FTP dumps of Packet captures are not being sent to the FTP server (Packet Monitor Logging Tab)

Description

Even after configuring the Packet Monitor "Logging" tab to send FTP dumps of Packet captures to the FTP server, files are not being sent to the FTP server.  The FTP server opens the data channel, but then returns a 425 error a second later, stating that it can't open data connection for transfer of the file.
Image

Cause

When the message 150 occurs, stating that the data channel is open, this means the FTP server is expecting to see another FTP socket open and push the actual file via FTP.  However, in the screenshot above, the firewall never opened the second socket.  Instead the firewall fails to pass traffic to the destination for 10 seconds, then generates a RST/ACK packet to close the socket.   This can occur if FTP transformations are not enabled for the FTP ports, but for a custom port.
Image
(If FTP transformations do not use the default ports, this second socket from source port 49226 is not created.  Note this new source port 49226 is 2 port numbers higher than the original socket's source port of 49224.)

Resolution for SonicOS 7.X

This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.


  • Under NETWORK | Firewall | Advanced | Settings, Set the drop-down menu to use the object "FTP (All)".

 Image



Resolution for SonicOS 6.5

This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.


  • Under Manage | Firewall Settings | Advanced Settings, Set the drop-down menu to use the object "FTP (All)".


 Image

Related Articles

  • SonicOS 8.1.0 FAQ
    Read More
  • SonicWall GEN8 TZs and GEN8 NSas Settings Migration
    Read More
  • Getting started with SonicWall firewalls
    Read More
not finding your answers?