202
Defining your security environment
Controlling full application inspection of traffic
■
Allow data connections to all ports
Blocks data connections to ports < 1024 is the most restrictive setting and is checked by
default. Settings other than the default may allow attacks based on low reserved port
numbers.
4
Click
OK
.
5
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
Related information
None.
Allowing longer banner and greeting lengths
When you grant access to FTP clients to access and FTP server that the security gateway protects,
those clients must go through the security gateway to gain access. When the client first connects to the
security gateway, the FTP proxy presents the user with a short message called a banner. Once the
client has properly authenticated, the client is presented a short greeting message, and the connection
is allowed.
The standard length for both the banner and the greeting is 512 characters. In some cases, however,
you may want this length to be longer. This is most often the case when you want to present a small set
of directions or a security statement prior to granting access. You can increase the banner and greeting
sizes to 1024 characters by following the procedure listed in this section.
Prerequisites
Complete the following tasks before beginning this procedure:
“Configuring the security gateway to send and receive files”
To allow longer banner and greeting lengths
1
In the SGMI, in the left pane, under Assets, click
Protocols
.
2
In the right pane, on the Service Groups tab, select the service group in which you have added the
ftp protocol, and then click
Properties
.
3
In the Service Group Properties dialog box, on the Protocols tab, click
ftp
.
4
Click
Configure
.
5
In the Parameters for ftp dialog box, on the Additional Commands tab, in the Command text box,
type
ftp.longresponse
.
6
Click
Add
.
7
Click
OK
.
8
In the Service Group Properties dialog box, click
OK
.
9
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
Related information
None.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...