<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cannot transfer the file to the ftp server which is behind ASA 5510 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649696#M1025013</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;configured ASA for allowing ftp requests to my ftp server residing behind the ASA,problem is when a internet client is doing ftp to the ftp server, he can able to connect, but he can't able to transfer the files after few seconds i get a message displaying "connection closed by remote host" how do i solve this? problem also happens when i issue DIR or LS command after logging in to the ftp server.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 09:38:00 GMT</pubDate>
    <dc:creator>Anand Narayana</dc:creator>
    <dc:date>2019-03-11T09:38:00Z</dc:date>
    <item>
      <title>Cannot transfer the file to the ftp server which is behind ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649696#M1025013</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;configured ASA for allowing ftp requests to my ftp server residing behind the ASA,problem is when a internet client is doing ftp to the ftp server, he can able to connect, but he can't able to transfer the files after few seconds i get a message displaying "connection closed by remote host" how do i solve this? problem also happens when i issue DIR or LS command after logging in to the ftp server.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:38:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649696#M1025013</guid>
      <dc:creator>Anand Narayana</dc:creator>
      <dc:date>2019-03-11T09:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot transfer the file to the ftp server which is behind A</title>
      <link>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649697#M1025015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems that you done have FTP inspection enabled on your ASA. Assuming that you are using default settings, please implement following commands on ASA-&lt;/P&gt;&lt;P&gt;(all commands are to be executed in config mode)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt; exit&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect ftp&lt;/P&gt;&lt;P&gt;  exit&lt;/P&gt;&lt;P&gt; exit&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now check if FTP works. If it does, save the configuration. If the issue remains, please provide the output for-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show service-policy&lt;/P&gt;&lt;P&gt;show run policy-map&lt;/P&gt;&lt;P&gt;If possible, syslogs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Feb 2007 12:13:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649697#M1025015</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-02-24T12:13:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot transfer the file to the ftp server which is behind A</title>
      <link>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649698#M1025016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;NO Use, it didn't work, still the same probs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Feb 2007 14:23:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649698#M1025016</guid>
      <dc:creator>Anand Narayana</dc:creator>
      <dc:date>2007-02-24T14:23:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot transfer the file to the ftp server which is behind A</title>
      <link>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649699#M1025017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take a look here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807ee585.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807ee585.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Feb 2007 15:14:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649699#M1025017</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2007-02-24T15:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot transfer the file to the ftp server which is behind A</title>
      <link>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649700#M1025018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Thanks for your response,&lt;/P&gt;&lt;P&gt;  actually i was trying from windows xp/2000 laptop, that is the reason i was facing this probs, when i tried in a BSd box it works fine being a "passive ftp" is enabled default. but still i couldn't understand why in windows xp/2000 i couldn't find the "passive" command. any idea? i was also informed by 1 of my friend that in windows box, if i issue "litral passive" he said that it would allow, but no use of that command, as it said it is invalid command.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Feb 2007 16:56:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649700#M1025018</guid>
      <dc:creator>Anand Narayana</dc:creator>
      <dc:date>2007-02-24T16:56:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot transfer the file to the ftp server which is behind A</title>
      <link>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649701#M1025019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In Unix/Linux, after ftp logging, you can issue&lt;/P&gt;&lt;P&gt;the command "passive" to either turn on or turn&lt;/P&gt;&lt;P&gt;off passive ftp as below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# cd /tmp&lt;/P&gt;&lt;P&gt;# ftp 192.168.15.10&lt;/P&gt;&lt;P&gt;Connected to 192.168.15.10.&lt;/P&gt;&lt;P&gt;220 (vsFTPd 1.2.0)&lt;/P&gt;&lt;P&gt;Name (192.168.15.10:root): anonymous&lt;/P&gt;&lt;P&gt;331 Please specify the password.&lt;/P&gt;&lt;P&gt;Password:&lt;/P&gt;&lt;P&gt;230 Login successful.&lt;/P&gt;&lt;P&gt;Remote system type is UNIX.&lt;/P&gt;&lt;P&gt;Using binary mode to transfer files.&lt;/P&gt;&lt;P&gt;ftp&amp;gt; bin&lt;/P&gt;&lt;P&gt;200 Switching to Binary mode.&lt;/P&gt;&lt;P&gt;ftp&amp;gt; prompt&lt;/P&gt;&lt;P&gt;Interactive mode off.&lt;/P&gt;&lt;P&gt;ftp&amp;gt; hash&lt;/P&gt;&lt;P&gt;Hash mark printing on (8192 bytes/hash mark).&lt;/P&gt;&lt;P&gt;ftp&amp;gt; passive&lt;/P&gt;&lt;P&gt;Passive mode on.&lt;/P&gt;&lt;P&gt;ftp&amp;gt; passive&lt;/P&gt;&lt;P&gt;Passive mode off.&lt;/P&gt;&lt;P&gt;ftp&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On Microsoft Windows, it works a differently.&lt;/P&gt;&lt;P&gt;After logging in, you can issue the command&lt;/P&gt;&lt;P&gt;"literal pasv".  That will take you to &lt;/P&gt;&lt;P&gt;passive mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\temp&amp;gt;ftp 192.168.15.10&lt;/P&gt;&lt;P&gt;Connected to 192.168.15.10.&lt;/P&gt;&lt;P&gt;220 (vsFTPd 1.2.0)&lt;/P&gt;&lt;P&gt;User (192.168.15.10:(none)): anonymous&lt;/P&gt;&lt;P&gt;331 Please specify the password.&lt;/P&gt;&lt;P&gt;Password:&lt;/P&gt;&lt;P&gt;230 Login successful.&lt;/P&gt;&lt;P&gt;ftp&amp;gt; bin&lt;/P&gt;&lt;P&gt;200 Switching to Binary mode.&lt;/P&gt;&lt;P&gt;ftp&amp;gt; prompt&lt;/P&gt;&lt;P&gt;Interactive mode Off .&lt;/P&gt;&lt;P&gt;ftp&amp;gt; hash&lt;/P&gt;&lt;P&gt;Hash mark printing On  ftp: (2048 bytes/hash mark) .&lt;/P&gt;&lt;P&gt;ftp&amp;gt; literal pasv&lt;/P&gt;&lt;P&gt;227 Entering Passive Mode (192,168,15,10,4,253)&lt;/P&gt;&lt;P&gt;ftp&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;good luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;&lt;P&gt;CCIE Security&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Feb 2007 20:37:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649701#M1025019</guid>
      <dc:creator>daviddtran</dc:creator>
      <dc:date>2007-02-24T20:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot transfer the file to the ftp server which is behind A</title>
      <link>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649702#M1025020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi David,&lt;/P&gt;&lt;P&gt; thanks for your response, even i tried the same &amp;amp; the command also accepted, but still the same probz, but when i tried ina GUI ftp client it is working being an Passive FTP. but no idea still why it is not working.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Feb 2007 11:25:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649702#M1025020</guid>
      <dc:creator>Anand Narayana</dc:creator>
      <dc:date>2007-02-25T11:25:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot transfer the file to the ftp server which is behind A</title>
      <link>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649703#M1025021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi anandanarayana,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think it is a bug in windows ftp client itself.  When you think you set the windows&lt;/P&gt;&lt;P&gt;ftp client from the CLI to passive ftp, it is &lt;/P&gt;&lt;P&gt;still doing "Active" ftp.  Check out the&lt;/P&gt;&lt;P&gt;tcpdump below from Linux FTP server itself:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------&lt;/P&gt;&lt;P&gt;C:\temp&amp;gt;ftp 192.168.15.10&lt;/P&gt;&lt;P&gt;Connected to 192.168.15.10.&lt;/P&gt;&lt;P&gt;220 (vsFTPd 1.2.0)&lt;/P&gt;&lt;P&gt;User (192.168.15.10:(none)): anonymous&lt;/P&gt;&lt;P&gt;331 Please specify the password.&lt;/P&gt;&lt;P&gt;Password:&lt;/P&gt;&lt;P&gt;230 Login successful.&lt;/P&gt;&lt;P&gt;ftp&amp;gt; bin&lt;/P&gt;&lt;P&gt;200 Switching to Binary mode.&lt;/P&gt;&lt;P&gt;ftp&amp;gt; prompt&lt;/P&gt;&lt;P&gt;Interactive mode Off .&lt;/P&gt;&lt;P&gt;ftp&amp;gt; hash&lt;/P&gt;&lt;P&gt;Hash mark printing On  ftp: (2048 bytes/hash mark) .&lt;/P&gt;&lt;P&gt;ftp&amp;gt; literal pasv&lt;/P&gt;&lt;P&gt;227 Entering Passive Mode (192,168,15,10,5,50)&lt;/P&gt;&lt;P&gt;ftp&amp;gt; get Winkey.exe&lt;/P&gt;&lt;P&gt;200 PORT command successful. Consider using PASV.&lt;/P&gt;&lt;P&gt;150 Opening BINARY mode data connection for Winkey.exe (43520 bytes).&lt;/P&gt;&lt;P&gt;#####################&lt;/P&gt;&lt;P&gt;226 File send OK.&lt;/P&gt;&lt;P&gt;ftp: 43520 bytes received in 0.00Seconds 43520000.00Kbytes/sec.&lt;/P&gt;&lt;P&gt;ftp&amp;gt; quit&lt;/P&gt;&lt;P&gt;221 Goodbye.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\temp&amp;gt;&lt;/P&gt;&lt;P&gt;--------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[root@dca2-LinuxES ftp]# tcpdump -i eth0 -n host 129.174.1.13&lt;/P&gt;&lt;P&gt;tcpdump: listening on eth0&lt;/P&gt;&lt;P&gt;10:26:58.104416 129.174.1.13.2668 &amp;gt; 192.168.15.10.ftp: S 1268059330:1268059330(0) win 64512 &lt;MSS 1460=""&gt; (DF)&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;10:26:58.104540 192.168.15.10.ftp &amp;gt; 129.174.1.13.2668: S 2901538155:2901538155(0) ack 1268059331 win 5840 &lt;MSS 1460=""&gt; (DF)&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;10:26:58.105335 129.174.1.13.2668 &amp;gt; 192.168.15.10.ftp: . ack 1 win 64512 (DF)&lt;/P&gt;&lt;P&gt;10:26:58.109962 192.168.15.10.ftp &amp;gt; 129.174.1.13.2668: P 1:21(20) ack 1 win 5840 (DF)&lt;/P&gt;&lt;P&gt;10:27:09.185283 129.174.1.13.2668 &amp;gt; 192.168.15.10.ftp: P 65:82(17) ack 208 win 64305 (DF)&lt;/P&gt;&lt;P&gt;10:27:09.185748 192.168.15.10.ftp-data &amp;gt; 129.174.1.13.2670: S 2914151128:2914151128(0) win 5840 &lt;MSS 1460=""&gt; (DF)&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;10:27:09.186629 129.174.1.13.2670 &amp;gt; 192.168.15.10.ftp-data: S 3044473740:3044473740(0) ack 2914151129 win 64512 &lt;MSS 1460=""&gt; (DF)&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;10:27:09.186702 192.168.15.10.ftp-data &amp;gt; 129.174.1.13.2670: . ack 1 win 5840 &lt;NOP&gt; (DF)&lt;/NOP&gt;&lt;/P&gt;&lt;P&gt;10:27:09.186928 192.168.15.10.ftp &amp;gt; 129.174.1.13.2668: P 208:279(71) ack 82 win 5840 (DF)&lt;/P&gt;&lt;P&gt;10:27:09.187040 192.168.15.10.ftp-data &amp;gt; 129.174.1.13.2670: . 1:1449(1448) ack 1 win 5840 &lt;NOP&gt; (DF) [tos 0x8]&lt;/NOP&gt;&lt;/P&gt;&lt;P&gt;10:27:09.187072 192.168.15.10.ftp-data &amp;gt; 129.174.1.13.2670: . 1449:2897(1448) ack 1 win 5840 &lt;NOP&gt; (DF) [tos 0x8]&lt;/NOP&gt;&lt;/P&gt;&lt;P&gt;10:27:09.187124 192.168.15.10.ftp-data &amp;gt; 129.174.1.13.2670: . 2897:4345(1448) ack 1 win 5840 &lt;NOP&gt; (DF) [tos 0x8]&lt;/NOP&gt;&lt;/P&gt;&lt;P&gt;10:27:09.187931 129.174.1.13.2670 &amp;gt; 192.168.15.10.ftp-data: . ack 2897 win 64512 &lt;NOP&gt; (DF)&lt;/NOP&gt;&lt;/P&gt;&lt;P&gt;10:27:09.187965 192.168.15.10.ftp-data &amp;gt; 129.174.1.13.2670: . 4345:5793(1448) ack 1 win 5840 &lt;NOP&gt; (DF) [tos 0x8]&lt;/NOP&gt;&lt;/P&gt;&lt;P&gt;10:27:09.187974 192.168.15.10.ftp-data &amp;gt; 129.174.1.13.2670: . 5793:7241(1448) ack 1 win 5840 &lt;NOP&gt; (DF) [tos 0x8]&lt;/NOP&gt;&lt;/P&gt;&lt;P&gt;10:27:09.187987 192.168.15.10.ftp-data &amp;gt; 129.174.1.13.2670: . 7241:8689(1448) ack 1 win 5840 &lt;NOP&gt; (DF) [tos 0x8]&lt;/NOP&gt;&lt;/P&gt;&lt;P&gt;10:27:09.188568 129.174.1.13.2670 &amp;gt; 192.168.15.10.ftp-data: . ack 5793 win 6451&lt;/P&gt;&lt;P&gt;10:27:11.555300 129.174.1.13.2668 &amp;gt; 192.168.15.10.ftp: P 82:88(6) ack 298 win 64215 (DF)&lt;/P&gt;&lt;P&gt;10:27:11.555817 192.168.15.10.ftp &amp;gt; 129.174.1.13.2668: P 298:312(14) ack 88 win 5840 (DF)&lt;/P&gt;&lt;P&gt;10:27:11.556957 129.174.1.13.2668 &amp;gt; 192.168.15.10.ftp: F 88:88(0) ack 312 win 64201 (DF)&lt;/P&gt;&lt;P&gt;10:27:11.557242 192.168.15.10.ftp &amp;gt; 129.174.1.13.2668: F 312:312(0) ack 89 win 5840 (DF)&lt;/P&gt;&lt;P&gt;10:27:11.557718 129.174.1.13.2668 &amp;gt; 192.168.15.10.ftp: . ack 313 win 64201 (DF)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;82 packets received by filter&lt;/P&gt;&lt;P&gt;0 packets dropped by kernel&lt;/P&gt;&lt;P&gt;[root@dca2-LinuxES ftp]#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Feb 2007 14:31:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649703#M1025021</guid>
      <dc:creator>daviddtran</dc:creator>
      <dc:date>2007-02-25T14:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot transfer the file to the ftp server which is behind A</title>
      <link>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649704#M1025022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi David,&lt;/P&gt;&lt;P&gt; as u said it should be a bug in windows CUI ftp client, so i tried installing a 3rd party FTP client it works. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Feb 2007 14:40:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649704#M1025022</guid>
      <dc:creator>Anand Narayana</dc:creator>
      <dc:date>2007-02-25T14:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot transfer the file to the ftp server which is behind A</title>
      <link>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649705#M1025038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes, third party clients such as WinSCP and &lt;/P&gt;&lt;P&gt;SecureFX works with passive ftp.  It is just&lt;/P&gt;&lt;P&gt;Windows ftp client CLI that does not.  As you can see, the client is transferring file with &lt;/P&gt;&lt;P&gt;the server with the server high-ports.  No &lt;/P&gt;&lt;P&gt;port 20 is taken place anywhere.  Therefore, &lt;/P&gt;&lt;P&gt;I think it is a bug in the microsoft ftp &lt;/P&gt;&lt;P&gt;client CLI itself.  See below when I initiate&lt;/P&gt;&lt;P&gt;ftp client from a third party ftp client such&lt;/P&gt;&lt;P&gt;as SecureFX:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[root@dca2-LinuxES root]# tcpdump -i eth0 -n host 129.174.1.13&lt;/P&gt;&lt;P&gt;tcpdump: listening on eth0&lt;/P&gt;&lt;P&gt;10:48:53.228633 129.174.1.13.35375 &amp;gt; 192.168.15.10.ftp: S 538184680:538184680(0) win 49640 &lt;MSS 1460=""&gt; (DF)&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;10:48:53.228753 192.168.15.10.ftp &amp;gt; 129.174.1.13.35375: S 4261832214:4261832214(0) ack 538184681 win 5840 &lt;MSS 1460=""&gt; (DF)&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;10:48:53.229620 129.174.1.13.35375 &amp;gt; 192.168.15.10.ftp: . ack 1 win 49640 (DF)&lt;/P&gt;&lt;P&gt;10:48:53.234096 192.168.15.10.ftp &amp;gt; 129.174.1.13.35375: P 1:21(20) ack 1 win 5840 (DF)&lt;/P&gt;&lt;P&gt;10:48:53.234565 129.174.1.13.35375 &amp;gt; 192.168.15.10.ftp: . ack 21 win 49640 (DF)&lt;/P&gt;&lt;P&gt;10:48:53.255148 192.168.15.10.34391 &amp;gt; 129.174.1.13.domain:  64769+ PTR? 2.12.147.198.in-addr.arpa. (43) (DF)&lt;/P&gt;&lt;P&gt;10:48:53.256379 129.174.1.13.domain &amp;gt; 192.168.15.10.34391:  64769 1/4/2 (202) (DF)&lt;/P&gt;&lt;P&gt;10:48:56.791231 129.174.1.13.35375 &amp;gt; 192.168.15.10.ftp: P 1:17(16) ack 21 win 49640 (DF)&lt;/P&gt;&lt;P&gt;10:48:56.791310 192.168.15.10.ftp &amp;gt; 129.174.1.13.35375: . ack 17 win 5840 (DF)&lt;/P&gt;&lt;P&gt;10:48:56.791885 192.168.15.10.ftp &amp;gt; 129.174.1.13.35375: P 21:55(34) ack 17 win 5840 (DF)&lt;/P&gt;&lt;P&gt;10:48:57.030438 129.174.1.13.35375 &amp;gt; 192.168.15.10.ftp: . ack 128 win 49640 (DF)&lt;/P&gt;&lt;P&gt;10:48:57.389484 129.174.1.13.35375 &amp;gt; 192.168.15.10.ftp: P 38:46(8) ack 128 win 49640 (DF)&lt;/P&gt;&lt;P&gt;10:48:57.389553 192.168.15.10.ftp &amp;gt; 129.174.1.13.35375: P 128:159(31) ack 46 win 5840 (DF)&lt;/P&gt;&lt;P&gt;10:48:57.480433 129.174.1.13.35375 &amp;gt; 192.168.15.10.ftp: . ack 159 win 49640 (DF)&lt;/P&gt;&lt;P&gt;10:48:58.586925 192.168.15.10.34391 &amp;gt; 129.174.1.13.domain:  64770+ PTR? 2.12.147.198.in-addr.arpa. (43) (DF)&lt;/P&gt;&lt;P&gt;10:48:58.588275 129.174.1.13.domain &amp;gt; 192.168.15.10.34391:  64770 1/4/2 (202) (DF)&lt;/P&gt;&lt;P&gt;10:49:00.638756 192.168.15.10.34391 &amp;gt; 129.174.1.13.domain:  64771+ PTR? 2.12.147.198.in-addr.arpa. (43) (DF)&lt;/P&gt;&lt;P&gt;10:49:00.639900 129.174.1.13.domain &amp;gt; 192.168.15.10.34391:  64771 1/4/2 (202) (DF)&lt;/P&gt;&lt;P&gt;10:49:08.028007 129.174.1.13.35375 &amp;gt; 192.168.15.10.ftp: P 46:52(6) ack 159 win 49640 (DF)&lt;/P&gt;&lt;P&gt;10:49:08.028710 192.168.15.10.ftp &amp;gt; 129.174.1.13.35375: P 159:207(48) ack 52 win 5840 (DF)&lt;/P&gt;&lt;P&gt;10:49:08.029984 129.174.1.13.35376 &amp;gt; 192.168.15.10.1037: S 541876187:541876187(0) win 49640 &lt;MSS 1460=""&gt; (DF)&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;10:49:08.030061 192.168.15.10.1037 &amp;gt; 129.174.1.13.35376: S 4267281440:4267281440(0) ack 541876188 win 5840 &lt;MSS 1460=""&gt; (DF)&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;10:49:08.030793 129.174.1.13.35376 &amp;gt; 192.168.15.10.1037: . ack 1 win 49640 (DF)&lt;/P&gt;&lt;P&gt;10:49:08.030932 129.174.1.13.35375 &amp;gt; 192.168.15.10.ftp: P 52:69(17) ack 207 win 49640 (DF)&lt;/P&gt;&lt;P&gt;10:49:08.031158 192.168.15.10.ftp &amp;gt; 129.174.1.13.35375: P 207:278(71) ack 69 win 5840 (DF)&lt;/P&gt;&lt;P&gt;10:49:08.031255 192.168.15.10.1037 &amp;gt; 129.174.1.13.35376: . 1:1461(1460) ack 1 win 5840 (DF) [tos 0x8]&lt;/P&gt;&lt;P&gt;10:49:08.031314 192.168.15.10.1037 &amp;gt; 129.174.1.13.35376: . 1461:2921(1460) ack 1 win 5840 (DF) [tos 0x8]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10:49:08.038016 129.174.1.13.35376 &amp;gt; 192.168.15.10.1037: F 1:1(0) ack 43522 win 49640 (DF)&lt;/P&gt;&lt;P&gt;10:49:08.038070 192.168.15.10.1037 &amp;gt; 129.174.1.13.35376: . ack 2 win 5840 (DF)&lt;/P&gt;&lt;P&gt;10:49:10.012613 129.174.1.13.35375 &amp;gt; 192.168.15.10.ftp: P 69:75(6) ack 297 win 49569 (DF)&lt;/P&gt;&lt;P&gt;10:49:10.012836 192.168.15.10.ftp &amp;gt; 129.174.1.13.35375: P 297:311(14) ack 75 win 5840 (DF)&lt;/P&gt;&lt;P&gt;10:49:10.013471 129.174.1.13.35375 &amp;gt; 192.168.15.10.ftp: F 75:75(0) ack 311 win 49569 (DF)&lt;/P&gt;&lt;P&gt;10:49:10.014115 192.168.15.10.ftp &amp;gt; 129.174.1.13.35375: F 311:311(0) ack 76 win 5840 (DF)&lt;/P&gt;&lt;P&gt;10:49:10.014590 129.174.1.13.35375 &amp;gt; 192.168.15.10.ftp: . ack 312 win 49569 (DF)&lt;/P&gt;&lt;P&gt;10:49:10.578376 192.168.15.10.34391 &amp;gt; 129.174.1.13.domain:  64772+ PTR? 2.12.147.198.in-addr.arpa. (43) (DF)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;101 packets received by filter&lt;/P&gt;&lt;P&gt;0 packets dropped by kernel&lt;/P&gt;&lt;P&gt;[root@dca2-LinuxES root]#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Feb 2007 14:51:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-transfer-the-file-to-the-ftp-server-which-is-behind-asa/m-p/649705#M1025038</guid>
      <dc:creator>daviddtran</dc:creator>
      <dc:date>2007-02-25T14:51:43Z</dc:date>
    </item>
  </channel>
</rss>

