ADTRAN AOS Version R10.1.0 Command Reference Manual page 1194

Adtran operating system (aos)
Table of Contents

Advertisement

Command Reference Guide
ipv6 firewall alg ftp
Use the ipv6 firewall alg ftp command to enable the Internet Protocol version 6 (IPv6) File Transfer
Protocol (FTP) application-level gateway (ALG). Use the no form of this command to disable the FTP
ALG. Variations of this command include:
ipv6 firewall alg ftp
ipv6 firewall alg ftp tcp
ipv6 firewall alg ftp tcp port <port>
ipv6 firewall vrf <name> alg ftp
ipv6 firewall vrf <name> alg ftp tcp
ipv6 firewall vrf <name> alg ftp tcp port <port>
Syntax Description
tcp
port <port>
vrf <name>
Default Values
By default, the IPv6 FTP ALG is enabled on all VRF instances on TCP port 21.
Command History
Release R10.1.0
Functional Notes
The IPv6 FTP ALG operates by parsing the Layer 5 contents of packets used for FTP, and when
necessary, opens pending policy sessions so that FTP data transfers are able to traverse the IPv6 firewall
without being dropped by configured access control policies (ACPs). In addition, the IPv6 FTP ALG has
the ability to perform FTP-specific attack checking.
During the process of an FTP flow, the IPv6 FTP ALG creates a pending policy session based on a
currently active policy session. This pending policy session listens for expected FTP data transfer traffic.
Any IPv6 firewall policy sessions created using a stateless ACP entry bypass all ALG processing, even if
the ALG is enabled for the ACP's destination port, allowing global ALG processing for specific ports, but
bypassing the global configuration under certain circumstances (such as, on a particular ACP or for
particular hosts or networks based on IPv6 ACLs).
The IPv6 FTP ALG cannot be enabled on a protocol and port that is the default protocol and port for any
other ALG, even if the other ALG is disabled. The IPv6 FTP ALG also cannot be enabled on a TCP port
whose default filtering behavior has been overridden.
60000CRG0-35E
Optional. Specifies that the port on which the IPv6 FTP ALG is enabled is a
Transmission Control Protocol (TCP) port.
Optional. Specifies a single port on which to enable the IPv6 FTP ALG. Valid
range is 0 to 65535.
Optional. Specifies a nondefault (named) Virtual Routing and Forwarding
(VRF) instance on which to enable the IPv6 FTP ALG.
Command was introduced.
Copyright © 2012 ADTRAN, Inc.
Global Configuration Mode Command Set
1194

Advertisement

Table of Contents
loading

Related Products for ADTRAN AOS Version R10.1.0

This manual is also suitable for:

Aos r10.1.0

Table of Contents