sk183853 - FTP traffic does not pass through Security Gateway when using the FTP "Extended Passive Mode"
FTP traffic does not pass through Security Gateway when using the FTP "Extended Passive Mode"
Product
Security Gateways
Version
R81.10 (EOS), R81.20, R82, R82.10
OS
Gaia
Last Modified
2026-07-23
Symptoms
- FTP traffic does not pass through Security Gateway when using the FTP "Extended Passive Mode", although an explicit Access Control rule is configured.
- SmartConsole logs show that the Security Gateway drops this FTP traffic on a Clean Up rule.
- Kernel debug (
fw ctl debug -m fw + conn drop vm ftp) on the Security Gateway shows that it drops the FTP traffic because of an illegal format.
Example:
`;fw_post_vm_chain_handler: executing handler function ftp_pasv_code;
;fw_do_ftp6port: data = XXX Entering Extended Passive Mode (!!!XXX!).
;fw_do_ftp6port: XXX command;
;fw_do_ftp6port: illegal format.;`
Cause
In the FTP "EPSV" command, the FTP server uses a character that is not the pipeline character "|" (for example, and exclamation sign "!") as the delimiter (see RFC 2428).
Security Gateway supports only the pipeline character "|" as the delimiter in the FTP "EPSV" command.
Solution
We're here for you
Please log in / sign in to view solution
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: Advanced
Status: Approved by TAC
Date Created: 2025-09-02
Last Modified: 2026-07-23