Great Circle Associates Firewalls
(August 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Firewall FTP Authentication w/ GUI Clients
From: sengle @ dhtinc . com (Steven W. Engle)
Date: Fri, 16 Aug 1996 16:34:18 -0500
To: firewalls @ GreatCircle . COM
Cc: sengle @ dhtinc . com

We are a user of a CyberGuard Corp (Harris) CyberGuard firewall.
The CyberGuard firewall has an FTP proxy to authenticate FTP sessions. It
operates essentially in two different modes when authenticating the user.

1       User FTPs to firewall and is authenticated (firewall user id and
password). During the authentication process the user specifies the target
host. On authentication success, the user is connected to the target host,
where he/she authenticates, and if successful, proceeds with file
transfers.

2       User FTPs directly to target host. The FTP proxy intercepts the
session, prompting for firewall user id and password. Once authenticated,
the FTP proxy establishes an ftp session with the desired target host. The
user authenticates, and if successful, proceeds with file transfers.

This process works fine for textual based user interfaces (such as the
plain old UNIX ftp client application), as the prompt / response process is
presented directly to the user. However, GUI based ftp clients, such as
Netscape Navigator, completely barf on this as the authentication process
at the firewall, with its prompting / command response sequence, is
completely foreign to them.

This is becoming a problem, all the GUI based FTP clients that we have
tested, including WS-FTP and Navigator, are not compatible with the
CyberGuard ftp proxy. We are looking for a solution.

We have raised this several times with Netscape - their response has been
"Navigator can not support this - it is not aware of firewall proxies." We
discussed this with CyberGuard Corp. They indicated no plans for a GUI
compatible ftp proxy.

Anyone who has thoughts on this, please email or post. Does Navigator have
this problem with other firewalls?

Thanx!

--
Steve Engle
DHT, Inc.
sengle @
 dhtinc .
 com




Follow-Ups:
Indexed By Date Previous: DNS Organization Quandry
From: Bob Gammage <rlgammag @ use . usit . net>
Next: Rule: Re: Firewalls-Digest V5 #466
From: Kenneth_J . _Chan @ siac . com
Indexed By Thread Previous: Re: DNS Organization Quandry
From: Todd Aven <Todd . Aven @ BankersTrust . Com>
Next: Re: Firewall FTP Authentication w/ GUI Clients
From: Brian Hatch <bri @ ifokr . org>

Google
 
Search Internet Search www.greatcircle.com