ftps

  • From: "Amy Babinchak" <Amy@xxxxxxxxxxxxxxxxxxxxxxxxxx>
  • To: <isalist@xxxxxxxxxxxxx>
  • Date: Tue, 16 Sep 2003 14:26:45 -0400

Let me first say that I've read the article on the isaserver.org website
on the complexities of ftp and the portion near the bottom where it
gives the gloomy news about ftps, secureNat clients and ISA server. This
is exactly where I'm at. 

I have an AS400 that needs to transmit information to and from EDS and
another company using FTPS. The AS400 can't run the Firewall client so I
created a client address set for it and the appropriate protocol rule,
protocol definitions and matching packets filters for the required ports
(990, 2015, 1969 and 1970; all in and out) and I disabled the FTP
application filter and FTP packet filters that were in ISA by default so
that they wouldn't get in the way. Attempts by the as400 to connect
timeout. Not much is logged by the firewall - it shows 10.0.0.99
anonymous (this is the as400) connecting to the server in the log and
all else are dashes.

I went to all of this effort simply because in the article it isn't
clear to me why non-firewall client computer can't access ftps. Can
someone explain why not or give some advice on making it work? If I
can't come up with a workable solution with the ISA server then it is
going to be replaced by a Cisco Pix; this is the recommended hardware
from EDS. I'd hate to see that happen.

Amy
 




Other related posts: