> Source: [sk109574](https://support.checkpoint.com/results/sk/sk109574)

# sk109574 - FTP connection using Filezilla client through Security Gateway fails when DLP is enabled

| Property | Value |
|----------|-------|
| Solution ID | sk109574 |
| Date Created | 2016-01-11 |
| Last Modified | 2016-10-11 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- After enabling DLP blade with FTP inspection - FTP connection with Filezilla client to an FTP server behind the Security Gateway fails and not established.

## Cause

Filezilla client is set by default to use FTPS to communicate with FTP server.

When FTPS is not supported by the FTP server, a message is sent back to the client notifying FTPS not allowed (message 502). At this point the client will fallback to direct FTP method and connection should be established successfully.

When DLP is enabled, the same method applies and the client first tries to establish connection via FTPS.   
If the server does not support FTPS, the FW returns message 550 which means the server didn't understand the request, instead of message 502.  
Due to the wrong message, the client does not perform the failback to direct causing the connection establishment failure.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
