Define a Passive NAT Address for an FTP Reverse Proxy Adapter
About this task
When a PASV command is sent to Secure Proxy from an inbound FTP client, the host and port number to which the inbound FTP client needs to connect for the data channel is returned. When Secure Proxy is behind a firewall, the host address of Secure Proxy is not visible to the inbound FTP client. To ensure that the client can obtain this information, define the passive network address translation (NAT) address.
Define this value if the client cannot directly connect to the proxy, such as when using a static NAT.
If you are using a remote external perimeter server with the FTP reverse proxy adapter and the perimeter server is also behind a firewall using static network address translation, identify the name or IP address of the computer running the external perimeter server.
To define a passive NAT address:
Procedure
- From IBM Sterling Secure Proxy, select Configuration from the left hand-side navigation panel.
- Click Adapters, then in the FTP Reverse Proxy tile, click View Adapters to display the list of created FTP Reverse Proxy Adapters.
- Select the Adapter you want to edit, click icon.
- Click the Advanced tab.
- Type a value to use for the passive NAT address in the Passive NAT Address field.
- Click Save.