> Source: [sk112495](https://support.checkpoint.com/results/sk/sk112495)

# sk112495 - Active FTP PORT command is not translated

| Property | Value |
|----------|-------|
| Solution ID | sk112495 |
| Date Created | 2016-07-21 |
| Last Modified | 2017-12-18 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- Source IP address is translated properly to the NAT IP address but FTP PORT command is not translated to the NAT IP address in active FTP.

## Cause

'Match for Any' is disabled for the ftp service. Rule accepting the active FTP connection specifies 'Any' for the Service column.

## Solution

When 'Match for Any' is disabled for the FTP service and the rule accepting the active FTP connection specifies 'Any' for the Service column, the FTP PORT command is not translated to the NAT IP address due to the following functionality of enabling 'Match for Any' for the ftp service:

'Match for Any' indicates whether this service is used when 'Any' is set as the rule's service and there are several service objects with the same source port and protocol.  
When there is a rule whose Service cell contains Any, and a connections protocol and source port match more than one service object, then the service object with the selected 'Match for Any' option will be used and its properties will be taken for handling this connection

Apply the following procedures to address this situation:

In SmartDashboard

1. Select 'Manage \> Services'.
2. In the Services dialog box, select the ftp service.
3. Click 'Edit'.
4. In the TCP Services Properties - ftp dialog box, click 'Advanced'.
5. In the Advanced TCP Services Properties dialog box, enable the Match for 'Any' check box.
6. Click 'OK'.
7. Click 'OK' again.
8. Click 'Close'.
9. Install the security policy on the Security Gateway.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
