sk181165 - FTP connection fails in Port Mode with NAT and Specific FTP clients

FTP connection fails in Port Mode with NAT and Specific FTP clients

Product: Security Gateways
Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20
Last Modified: 2025-01-20

Symptoms

FTP command sequence
  ---------------------------------------
220 Welcome to blah FTP service.
USER root
331 Please specify the password.
PASS asgent1
230 Login successful.
TYPE I
200 Switching to Binary mode.
PORT 10,10,198,200,148,247       <-- dropped by firewall
  ---------------------------------------
  ---------------------------------------
@;63553938;19May2023 15:06:07.557825;[cpu_2];[fw4_1];fw_xlate_anticipate_cookie: dir = 0, host = 100.100.100.100, port = 94f7, case = 1, is_cmi_fw_handler_streaming = 0;
@;63553938;19May2023 15:06:07.557832;[cpu_2];[fw4_1];fw_xlate_scan_ftp_cmd: :
    PORT 10,10,198,200,148,247;
@;63553938;19May2023 15:06:07.557833;[cpu_2];[fw4_1];fw_xlate_scan_ftp_cmd: PORT command;
@;63553938;19May2023 15:06:07.557834;[cpu_2];[fw4_1];fw_xlate_scan_ftp_cmd: bad termination format ('(');
@;63553938;19May2023 15:06:07.557835;[cpu_2];[fw4_1];fw_xlate_anticipate_cookie: fw_xlate_scan_ftp_cmd failed;
@;63553938;19May2023 15:06:07.557836;[cpu_2];[fw4_1];fw_post_vm_chain_handler: handler function returned action DROP;
@;63553938;19May2023 15:06:07.557841;[cpu_2];[fw4_1];fw_log_drop_ex: Packet proto=6 10.10.198.200:47492 -> 192.168.198.200:8021 dropped by fw_post_vm_chain_handler Reason: Handler 'ftp_code' drop;
@;63553938;19May2023 15:06:07.557846;[cpu_2];[fw4_1];After POST VM:  192.168.198.200:8021 IPP 6> (len=78) TCP flags=0x18 (PUSH-ACK), seq=885278701, ack=2403950228, data end=885278727 ;
@;63553938;19May2023 15:06:07.557847;[cpu_2];[fw4_1];POST VM Final action=DROP;
  ---------------------------------------

Cause

Some FTP clients send the command string fragmented: the first packet has the string of PORT command, and the next packet has (Carriage Return, Line Feed : "\r\n")

Security Gateway expects to receive (\r\n) at the end of every string. Therefore, the packet without the (\r\n) is considered as of incorrect format and dropped.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2023-07-23
Last Modified: 2025-01-20

Was this page helpful? Yes/No