FTP: Request to Connect to Illegal Port
This protocol anomaly triggers when it detects an FTP PORT command/response to a PASV command ("227...") that specifies a reserved port number. This can indicate an attempt to make IDP or firewall open reserved ports.
Extended Description
PASV commands specifying a reserved port may be the result of misconfigured, or badly implemented, FTP clients. It could also indicate that an attacker is attempting an FTP Bounce Attack, or similar.
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
7.5