<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active FTP failing on ACE module in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/active-ftp-failing-on-ace-module/m-p/1416879#M29460</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It sounds like you probably didn't configure FTP INSPECT rule for this VIP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_appliances/vA1_7_/configuration/security/guide/appinsp.html#wp1310518"&gt;http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_appliances/vA1_7_/configuration/security/guide/appinsp.html#wp1310518&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pB1_Body1"&gt;The ACE performs the FTP command inspection process as follows:&lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;A name="wp1245951"&gt;&lt;/A&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Prepares a dynamic secondary data connection. The channels are allocated in response to a file upload, a file download, or a directory listing event and must be prenegotiated. The port is negotiated through the PORT or PASV commands.&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;Thanks&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;Eric Rose&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 18 Dec 2009 18:57:30 GMT</pubDate>
    <dc:creator>Eric Rose</dc:creator>
    <dc:date>2009-12-18T18:57:30Z</dc:date>
    <item>
      <title>Active FTP failing on ACE module</title>
      <link>https://community.cisco.com/t5/application-networking/active-ftp-failing-on-ace-module/m-p/1416878#M29459</link>
      <description>&lt;P&gt;I've setup FTP as show in the configuration examples.&amp;nbsp; Passive FTP works fine but for some reason active FTP breaks.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The client reported that he can authenticate to the FTP server with no problem.&amp;nbsp; However when he issues a FTP command such as LIST the connection just hangs.&amp;nbsp; Eventually he has to abort the connection.&amp;nbsp; 10.24.32.75 is my source NAT address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PORT 10,24,32,75,239,165&lt;/P&gt;&lt;P&gt;200 PORT command successful.&lt;/P&gt;&lt;P&gt;LIST&lt;/P&gt;&lt;P&gt;150 Opening ASCII mode data connection for /bin/ls.&lt;/P&gt;&lt;P&gt;425 Can't open data connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I look at the sniff trace between the NAT and server I see the ftp server initiate the ftp-data connection on port 20.&amp;nbsp; But then the ACE receives it and sends a reset back to the ftp server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone know of commands that can be executed that can show details as to why the connection gets reset by the ACE?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a TAC case opened but still waiting for an engineer to respond.&amp;nbsp; Just thought I'd post to see if anyone else has experienced this.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2009 17:17:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/active-ftp-failing-on-ace-module/m-p/1416878#M29459</guid>
      <dc:creator>JeramyKoval</dc:creator>
      <dc:date>2009-12-18T17:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: Active FTP failing on ACE module</title>
      <link>https://community.cisco.com/t5/application-networking/active-ftp-failing-on-ace-module/m-p/1416879#M29460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It sounds like you probably didn't configure FTP INSPECT rule for this VIP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_appliances/vA1_7_/configuration/security/guide/appinsp.html#wp1310518"&gt;http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_appliances/vA1_7_/configuration/security/guide/appinsp.html#wp1310518&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pB1_Body1"&gt;The ACE performs the FTP command inspection process as follows:&lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;A name="wp1245951"&gt;&lt;/A&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Prepares a dynamic secondary data connection. The channels are allocated in response to a file upload, a file download, or a directory listing event and must be prenegotiated. The port is negotiated through the PORT or PASV commands.&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;Thanks&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;Eric Rose&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Dec 2009 18:57:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/active-ftp-failing-on-ace-module/m-p/1416879#M29460</guid>
      <dc:creator>Eric Rose</dc:creator>
      <dc:date>2009-12-18T18:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: Active FTP failing on ACE module</title>
      <link>https://community.cisco.com/t5/application-networking/active-ftp-failing-on-ace-module/m-p/1416880#M29461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I triple checked that part of our configuration and made sure the inspect-ftp command was configured.&lt;SPAN style="background-color: #f8fafd;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Dec 2009 19:58:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/active-ftp-failing-on-ace-module/m-p/1416880#M29461</guid>
      <dc:creator>JeramyKoval</dc:creator>
      <dc:date>2009-12-18T19:58:58Z</dc:date>
    </item>
    <item>
      <title>Re: Active FTP failing on ACE module</title>
      <link>https://community.cisco.com/t5/application-networking/active-ftp-failing-on-ace-module/m-p/1416881#M29462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We'll need to see your config and the sniffer trace.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;G.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Dec 2009 19:42:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/active-ftp-failing-on-ace-module/m-p/1416881#M29462</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2009-12-21T19:42:38Z</dc:date>
    </item>
  </channel>
</rss>

