In transparent mode, the FTP proxy captures ftp traffic and A-V scans the traffic. If you change the mode to non-transparent, the proxy "listens" on port 2121 instead, so, if you didn't make that change to your client's configuration, the non-transparent proxy doesn't handle your FTP traffic.
Probably, in non-transparent mode, the traffic is passing because you have a packet filter rule like 'Internal (Network) -> Any -> Any : Allow'.
Try putting the proxy back into transparent mode and looking at the packet filter log. If there's no indication there, look at the IPS log. If you see nothing in either one, try creating an A-V exception for one of the sites with which you are having a problem.
When you discover the fix, please post it.
Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
|