Nokia IP60 User Manual page 35

Security appliance
Hide thumbs Also See for IP60:
Table of Contents

Advertisement

FTP connections are unique, since they are established using two sessions or channels: one for command
(AKA control) and one for data. The following table describes the steps of establishing a Passive FTP
connection, where:
C is the client port used in the command session,
D is the client port used in the data session, and
P is the server port used in the data session.
Table 9: Establishment of Passive FTP Connection
Step
Channel
Description
Type
1
CMD
Client initiates a
PASV command to
the FTP server on
port 21
2
CMD
Server responds
with data port
information P >
1023
3
Data
Client initiates data
connection to
server on port P
4
Data
Server
acknowledges
data connection
The following diagram demonstrates the establishment of a Passive FTP connection through a firewall
protecting the FTP server.
Figure 6: Establishment of Passive FTP Connection
From the FTP server's perspective, the following connections are established:
Chapter 2: Security
Source
TCP
Destination
Source
Port
FTP
C >
FTP server
client
1023
FTP
21
FTP client
server
FTP
D >
FTP server
client
1023
FTP
P
FTP client
server
The Nokia IP60 Firewall
TCP
Destination
Port
21
C
P
D
35

Advertisement

Table of Contents
loading

Table of Contents