× The internal search function is temporarily non-functional. The current search engine is no longer viable and we are researching alternatives.
As a stop gap measure, we are using Google's custom search engine service.
If you know of an easy to use, open source, search engine ... please contact support@midrange.com.



Fortunately the PTF Groups are (or can be) normal FTP.

--
Jim Oberholtzer
Agile Technology Architects

-----Original Message-----
From: MIDRANGE-L <midrange-l-bounces@xxxxxxxxxxxxxxxxxx> On Behalf Of
Roberto José Etcheverry Romero
Sent: Thursday, June 4, 2020 7:35 AM
To: Midrange Systems Technical Discussion <midrange-l@xxxxxxxxxxxxxxxxxx>
Subject: Re: Script in PTF download rejected by Cisco Firepower Intrusion
Prevention System (IPS)

Rob,

Are you using encrypted FTP? I thought that IBM had moved all ftp downloads
to encrypted awhile ago. The more networking guys want to snoop the more I
tunnel and encrypt.
This is a perfect example of the false positives these DPI tools bring.
Check if you can enable sftp or ftps or ftpes (whatever the secured option
IBM might be using). If the native IBM i FTP client doesn't allow encrypted
connections, you might be able to use one that does in PASE...

Roberto

On Thu, Jun 4, 2020 at 8:23 AM Rob Berendt <rob@xxxxxxxxx> wrote:

Possible bad ptf?

Late last week I started a PTF download from IBM. This resulted in
these files The CUME_1.bin byte count is: 3815768064 The CUME_2.bin
byte count is: 3721482240 The CUME_3.bin byte count is: 3904059392 The
CUME_4.bin byte count is: 3807432704 The CUME_5.bin byte count is:
447019008.
When using FTP download from IBM i command line it would die on
CUME_3.bin. Well into it. Repeatable. Multiple lpars. I downloaded
them again and the byte counts were a little different but the same
situation.
Same file dies. I gave up and downloaded them to a PC and then
uploaded that to IBM i. This worked.

Got a reply from our network guy:
<snip>
Turns out that the Cisco Firepower Intrusion Prevention System (IPS)
was killing your FTP downloads, because the file contained a script
that IPS did not like.

This was discovered during our weekly Webex meeting dropped traffic
review. Don't know why the same transfer worked from the laptop, but
something must have been different - perhaps binary vs non-binary
transfer mode - I don't know for sure.

There is no good workaround other than what you have already done.
Whitelisting would be putting the systems at risk.
</snip>

So, might there be a bad PTF in there which may corrupt the system?
I have it set to apply on 15 lpars at their next IPL.

I had ordered these PTF's:
MF65856,MF66031,MF66337,MF66879,MF67062,MF67143,MF67216,MF67304,SF9965
2,SF99653,SF99659,SF99661,SF99662,SF99663,SF99664,SF99665,SF99666,SF99
667,SF99668,SF99675,SF99704,SF99736,SF99737,SF99738,SF99739,SF99740,SF
99741,SI69396,SI69632,SI69635,SI69892,SI69943,SI70236,SI70319,SI70368,
SI70542,SI70552,SI70572,SI70591,SI70626,SI70716,SI70749,SI71060,SI7139
6,SI71601,SI71638,SI71876,SI71972,SI71975,SI72020,SI72305,SI73026,SI73
201,SI73239,SI72590, SI71719, MF67191, MF65997, MF66894, MF67002,
MF67004


Rob Berendt
--
IBM Certified System Administrator - IBM i 6.1 Group Dekko Dept 1600
Mail to: 2505 Dekko Drive
Garrett, IN 46738
Ship to: Dock 108
6928N 400E
Kendallville, IN 46755
http://www.dekko.com

--
This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing
list To post a message email: MIDRANGE-L@xxxxxxxxxxxxxxxxxx To
subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/midrange-l
or email: MIDRANGE-L-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives at
https://archive.midrange.com/midrange-l.

Please contact support@xxxxxxxxxxxxxxxxxxxx for any subscription
related questions.

Help support midrange.com by shopping at amazon.com with our affiliate
link: https://amazon.midrange.com

--
This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing list
To post a message email: MIDRANGE-L@xxxxxxxxxxxxxxxxxx To subscribe,
unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/midrange-l
or email: MIDRANGE-L-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives at
https://archive.midrange.com/midrange-l.

Please contact support@xxxxxxxxxxxxxxxxxxxx for any subscription related
questions.

Help support midrange.com by shopping at amazon.com with our affiliate link:
https://amazon.midrange.com


As an Amazon Associate we earn from qualifying purchases.

This thread ...

Follow-Ups:
Replies:

Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.