Security Basics mailing list archives

RE: firewalls that can ssl ftp?


From: "Hagen, Eric" <ehagen () DenverNewspaperAgency com>
Date: Fri, 6 Feb 2004 14:01:47 -0700

There are plenty of SFTP packages out there.  Most *nix systems (including
Linux and BSD derivatives) ship with an SFTP daemon.  You can use a client
like Putty, or a variety of other freeware or inexpensive SFTP clients on
the desktops.

As for a "firewall with SSL" I think you've basically described a VPN.
Since the SSL has to be supported on both ends, you would need an SSL aware
FTP client (the aforementioned SFTP is a good standard to use) or you would
need to use a VPN client (or an SSH tunneling client) anyway in order to
make a "standard" FTP client work over and encrypted tunnel.  At that point
you may as well invest in a good VPN server and instruct your partners to
use that VPN for security reasons.

Eric


-----Original Message-----
From: Ken Dallarax [mailto:dallarax11 () techie com]
Sent: Monday, February 02, 2004 5:29 PM
To: security-basics () securityfocus com
Subject: firewalls that can ssl ftp?




Anyone have experience with good ways to do secure ftp (ftp over ssl) in an
enterprise setting? We use ftp for partner apps and want to encrypt
everything. Looked at secure ftp servers from Valicert, etc. but they seem
like overkill. Does anyone know of a firewall that does ssl that can also
encrypt ftp? 

---------------------------------------------------------------------------
Ethical Hacking at InfoSec Institute. Mention this ad and get $720 off any 
course! All of our class sizes are guaranteed to be 10 students or less. 
We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion Prevention, 
and many other technical hands on courses. 
Visit us at http://www.infosecinstitute.com/securityfocus to get $720 off 
any course!  
----------------------------------------------------------------------------

---------------------------------------------------------------------------
Ethical Hacking at InfoSec Institute. Mention this ad and get $720 off any 
course! All of our class sizes are guaranteed to be 10 students or less. 
We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion Prevention, 
and many other technical hands on courses. 
Visit us at http://www.infosecinstitute.com/securityfocus to get $720 off 
any course!  
----------------------------------------------------------------------------


Current thread: