> Source: [sk39793](https://support.checkpoint.com/results/sk/sk39793)

# sk39793 - FTP over SSL traffic does not pass through Security Gateway

| Property | Value |
|----------|-------|
| Solution ID | sk39793 |
| Date Created | 2009-04-14 |
| Last Modified | 2016-04-19 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- FTP over SSL traffic does not pass through Security Gateway.

## Solution

FTP over SSL is not supported.

Since FTP over SSL is encrypted, there is no way to inspect the port command to decide what port to open and therefore the traffic is blocked.

There are certain configurations option that can allow FTP over SSL through the Security Gateway.  
Security Gateway insists on a 'newline' character in certain places (after the PORT command). Gateway expects each FTP header coming from the server to end with **\\r\\n** . Refer to [sk39516](http://supportcontent.checkpoint.com/solutions?id=sk39516).

Some variants of FTP over SSL operate over different ports (port 990 for Control, 989 for Data). In this case, you simply need to create the following TCP services:

* ftp-ssl-control: port 990

* ftp-ssl-data: port \>1023, source port 989

<br />

The rulebase to permit access would look like:

|------------|-------------|-----------------|--------|
| Source     | Destination | Service         | Action |
| ftp-client | ftp-server  | ftp-ssl-control | accept |
| ftp-server | ftp-client  | ftp-ssl-data    | accept |

If you still cannot get this traffic through the gateway, there are several ways to disable FTP enforcement. Usually this is done through SmartDefense/IPS, by disabling the FTP Bounce attack protection.  
**Note:** This is NOT recommended.

Notes:

* FTP over SSL is specified in [RFC 2228](https://www.rfc-editor.org/info/rfc2228).
* For FTP over SSL over port 21, refer to [sk102528 - How to pass FTPS traffic through Security Gateway without inspection](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk102528)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
