<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTP and Port mapping in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445055#M8201</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;where is your firewall located ?&lt;/P&gt;&lt;P&gt;The CSS will indeed change the source port, but this is on the server side.&lt;/P&gt;&lt;P&gt;Is the problem with both active and passive FTP or just one of them ?&lt;/P&gt;&lt;P&gt;Do you have a sniffer trace showing the problem ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 Sep 2005 09:52:10 GMT</pubDate>
    <dc:creator>Gilles Dufour</dc:creator>
    <dc:date>2005-09-01T09:52:10Z</dc:date>
    <item>
      <title>FTP and Port mapping</title>
      <link>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445054#M8200</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;we get troubles with our FTP Server. The clients send a Syn with Src port 40000 then the Server replies with the the same dst port but i presume that the loadbalancer makes a port-mapping and translate the source Port to eg. 33000. Our firewall clearly drops the packet with the reason "Packet out of state". have you any idea ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here my config&lt;/P&gt;&lt;P&gt;service h01p6u_21 &lt;/P&gt;&lt;P&gt;  keepalive type tcp &lt;/P&gt;&lt;P&gt;  keepalive port 21 &lt;/P&gt;&lt;P&gt;  ip address x.x.158.129 &lt;/P&gt;&lt;P&gt;  protocol tcp &lt;/P&gt;&lt;P&gt;  redundant-index 11790 &lt;/P&gt;&lt;P&gt;  active &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service h01p6v_21 &lt;/P&gt;&lt;P&gt;  ip address x.x.158.130 &lt;/P&gt;&lt;P&gt;  keepalive type tcp &lt;/P&gt;&lt;P&gt;  keepalive port 21 &lt;/P&gt;&lt;P&gt;  protocol tcp &lt;/P&gt;&lt;P&gt;  redundant-index 11800 &lt;/P&gt;&lt;P&gt;  active &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  content c01sg5_21 &lt;/P&gt;&lt;P&gt;    vip address x.x.x.140 &lt;/P&gt;&lt;P&gt;    add service h01p6v_21 &lt;/P&gt;&lt;P&gt;    add service h01p6u_21 &lt;/P&gt;&lt;P&gt;    port 21 &lt;/P&gt;&lt;P&gt;    protocol tcp &lt;/P&gt;&lt;P&gt;    application ftp-control&lt;/P&gt;&lt;P&gt;    active &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!*************************** GROUP &lt;/P&gt;&lt;P&gt;group srg_c01sg5 &lt;/P&gt;&lt;P&gt;  vip address x.x.x.140 &lt;/P&gt;&lt;P&gt;  add service h01p6u_21 &lt;/P&gt;&lt;P&gt;  add service h01p6v_21 &lt;/P&gt;&lt;P&gt;  active &lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2005 14:27:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445054#M8200</guid>
      <dc:creator>casablancag</dc:creator>
      <dc:date>2005-08-31T14:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: FTP and Port mapping</title>
      <link>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445055#M8201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;where is your firewall located ?&lt;/P&gt;&lt;P&gt;The CSS will indeed change the source port, but this is on the server side.&lt;/P&gt;&lt;P&gt;Is the problem with both active and passive FTP or just one of them ?&lt;/P&gt;&lt;P&gt;Do you have a sniffer trace showing the problem ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Sep 2005 09:52:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445055#M8201</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2005-09-01T09:52:10Z</dc:date>
    </item>
    <item>
      <title>Re: FTP and Port mapping</title>
      <link>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445056#M8202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gilles&lt;/P&gt;&lt;P&gt;the Firewall is between Internet and Loadbalancer. On the Loadbalancer we habe configured two VLAN in the front and 2 VLAn in the back. We have 2 defualt route in the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;attached you will find the sniffer trace&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Sep 2005 10:43:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445056#M8202</guid>
      <dc:creator>casablancag</dc:creator>
      <dc:date>2005-09-01T10:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: FTP and Port mapping</title>
      <link>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445057#M8203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we only see SYN and SYN/ACK.&lt;/P&gt;&lt;P&gt;Is the control connection not even establishing ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CSS is spoofing the connection, so it will respond to the SYN on behalf of the server [at this time the server has not yet received any packet].&lt;/P&gt;&lt;P&gt;So the firewall should allow the SYN/ACK from the CSS.&lt;/P&gt;&lt;P&gt;There is no port mapping there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Sep 2005 11:59:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445057#M8203</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2005-09-01T11:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: FTP and Port mapping</title>
      <link>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445058#M8204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gilles&lt;/P&gt;&lt;P&gt;the problem that I have now is with ACTIVE FTP. I made PBR on the Loadbalancer. Passive FTP works either from the internet and from our internal network while Active FTP works only from the internet and doesn't work from our internal network. What we see is that the Loadbalancer sends the ftp-data packet out to the InternetVLAN (eg. VLAN 3605) and not to the VLAN 3603. I guess the problem is in my access-list. have you any Idea ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My configuration &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!*************************** GROUP ***************************&lt;/P&gt;&lt;P&gt;group srg_c01sg5 &lt;/P&gt;&lt;P&gt;  vip address x.x.152.140 &lt;/P&gt;&lt;P&gt;  add service h01p6v_21 &lt;/P&gt;&lt;P&gt;  add service h01p6u_21 &lt;/P&gt;&lt;P&gt;  active &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!**************************** ACL ****************************&lt;/P&gt;&lt;P&gt;acl 1 &lt;/P&gt;&lt;P&gt;  clause 10 permit any x.x.172.0 255.255.255.0 destination any prefer FW_VLAN3605 &lt;/P&gt;&lt;P&gt;  clause 99 permit any any destination any &lt;/P&gt;&lt;P&gt;  apply circuit-(VLAN3607) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;acl 2 &lt;/P&gt;&lt;P&gt;  clause 10 permit any x.x.158.0 255.255.255.0 destination any prefer FW_VLAN3603 &lt;/P&gt;&lt;P&gt;  clause 99 permit any any destination any &lt;/P&gt;&lt;P&gt;  apply circuit-(VLAN3610) &lt;/P&gt;&lt;P&gt;  clause 15 permit any x.x.158.0 255.255.255.0 destination 10.0.0.0 255.0.0.0 prefer FW_VLAN3603 &lt;/P&gt;&lt;P&gt;  clause 20 permit any x.x.158.0 255.255.255.0 destination 138.191.0.0 255.255.0.0 prefer FW_VLAN3603 &lt;/P&gt;&lt;P&gt;  clause 25 permit any x.x.158.0 255.255.255.0 destination 192.168.251.0 255.255.255.0 prefer FW_VLAN3603 &lt;/P&gt;&lt;P&gt;  clause 30 permit any x.x.158.0 255.255.255.0 destination 192.168.250.0 255.255.255.0 prefer FW_VLAN3603 &lt;/P&gt;&lt;P&gt;  clause 35 permit any x.x.158.0 255.255.255.0 destination 192.168.0.0 255.255.0.0 prefer FW_VLAN3603 &lt;/P&gt;&lt;P&gt;  clause 40 permit any x.x.158.0 255.255.255.0 destination 172.16.0.0 255.240.0.0 prefer FW_VLAN3603 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;acl 10 &lt;/P&gt;&lt;P&gt;  clause 99 permit any any destination any &lt;/P&gt;&lt;P&gt;  apply circuit-(VLAN3605) &lt;/P&gt;&lt;P&gt;  apply circuit-(VLAN3603) &lt;/P&gt;&lt;P&gt;  apply circuit-(VLAN2421) &lt;/P&gt;&lt;P&gt;  apply circuit-(VLAN1) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Sep 2005 09:01:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445058#M8204</guid>
      <dc:creator>casablancag</dc:creator>
      <dc:date>2005-09-02T09:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: FTP and Port mapping</title>
      <link>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445059#M8205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can't you use more specific static routes to direct your internal traffic to the correct vlan instead of the acl ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe the acl won't work because of bug CSCej01719.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Sep 2005 09:33:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445059#M8205</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2005-09-02T09:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: FTP and Port mapping</title>
      <link>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445060#M8206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gilles&lt;/P&gt;&lt;P&gt;I already have more specific Routes but it doesn't work.Is there a way to not use the source group for active ftp but to make nat at the ACL ? &lt;/P&gt;&lt;P&gt;*********************************&lt;/P&gt;&lt;P&gt;below the routing table&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; ip route 0.0.0.0 0.0.0.0 194.41.160.254 1 &lt;/P&gt;&lt;P&gt;  ip route 172.16.0.0 255.240.0.0 194.41.160.1 1 &lt;/P&gt;&lt;P&gt;  ip route 10.0.0.0 255.0.0.0 194.41.160.1 1 &lt;/P&gt;&lt;P&gt;  ip route 138.191.0.0 255.255.0.0 194.41.160.1 1 &lt;/P&gt;&lt;P&gt;  ip route 194.41.128.119 255.255.255.255 194.41.160.248 1 &lt;/P&gt;&lt;P&gt;  ip route 172.28.0.0 255.255.0.0 172.27.3.254 1 &lt;/P&gt;&lt;P&gt;  ip route 172.27.0.0 255.255.0.0 172.27.3.254 1 &lt;/P&gt;&lt;P&gt;  ip route 192.168.250.0 255.255.255.0 194.41.160.1 1 &lt;/P&gt;&lt;P&gt;  ip route 192.168.251.0 255.255.255.0 194.41.160.1 1 &lt;/P&gt;&lt;P&gt;  ip route 138.189.96.0 255.255.255.224 194.41.160.1 1 &lt;/P&gt;&lt;P&gt;  ip route 172.29.128.0 255.255.192.0 194.41.160.248 1 &lt;/P&gt;&lt;P&gt;  ip route 0.0.0.0 0.0.0.0 194.41.152.254 1 &lt;/P&gt;&lt;P&gt;  ip route 10.0.0.0 255.0.0.0 194.41.152.129 1 &lt;/P&gt;&lt;P&gt;  ip route 138.191.0.0 255.255.0.0 194.41.152.129 1 &lt;/P&gt;&lt;P&gt;  ip route 192.168.251.0 255.255.255.0 194.41.152.129 1 &lt;/P&gt;&lt;P&gt;  ip route 192.168.250.0 255.255.255.0 194.41.152.129 1 &lt;/P&gt;&lt;P&gt;  ip route 192.168.0.0 255.255.0.0 194.41.160.1 1 &lt;/P&gt;&lt;P&gt;  ip route 192.168.0.0 255.255.0.0 194.41.152.129 1 &lt;/P&gt;&lt;P&gt;  ip route 172.16.0.0 255.240.0.0 194.41.152.129 1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Sep 2005 14:32:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445060#M8206</guid>
      <dc:creator>casablancag</dc:creator>
      <dc:date>2005-09-02T14:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: FTP and Port mapping</title>
      <link>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445061#M8207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't understand the need for your acl 1 ??&lt;/P&gt;&lt;P&gt;Why is it required ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think that's the one forwarding all your traffic to the Internet.&lt;/P&gt;&lt;P&gt;Why don't you simply let the CSS route based on the routing table ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Sep 2005 14:43:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445061#M8207</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2005-09-02T14:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: FTP and Port mapping</title>
      <link>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445062#M8208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Because we have internal server that have the need to open a connetion to the internet. Without acl 1 we had the situation that one server in the private lan could connect to the internet and one server in the same lan couldn't. The sniffer trace tells us that the packets for the server were routet to the wrong interface. We have two default route in the internet and the firewall with the anti spoofing rule blocks the traffic.&lt;/P&gt;&lt;P&gt;Any idea concerning the active ftp issue ??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Sep 2005 18:22:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445062#M8208</guid>
      <dc:creator>casablancag</dc:creator>
      <dc:date>2005-09-02T18:22:38Z</dc:date>
    </item>
    <item>
      <title>Re: FTP and Port mapping</title>
      <link>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445063#M8209</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you're active ftp issue is related to your acl.&lt;/P&gt;&lt;P&gt;You need to modify the acl so it does not forward your FTP traffic to the Internet when it's not needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create a new clause that will match your active ftp traffic and just permit without using the prefer option.&lt;/P&gt;&lt;P&gt;You could setup your ftp server to always use the data port 20 to make it easier to identify the FTP data traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Sep 2005 06:32:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ftp-and-port-mapping/m-p/445063#M8209</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2005-09-03T06:32:04Z</dc:date>
    </item>
  </channel>
</rss>

