<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to FTP image to ASA 5515-X in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354587#M1028300</link>
    <description>Yes seems it needs SFTP only. If its not listening locally it can't be ASA&lt;BR /&gt;problem&lt;BR /&gt;</description>
    <pubDate>Sun, 25 Mar 2018 10:16:39 GMT</pubDate>
    <dc:creator>Mohammed al Baqari</dc:creator>
    <dc:date>2018-03-25T10:16:39Z</dc:date>
    <item>
      <title>Unable to FTP image to ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354523#M1028297</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;i'm trying to FTP an image to a 5515-x but getting error 'no more process'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;per google, 'no more processes' is just saying 'file/directory not found'. but file is already on the linux server. the linux server is the only accessible remote server and i've used the same server for transfering license .lic files.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i tried playing around with the path file name but still getting the same error. can someone advise what can be wrong?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCtb65688/?rfs=iqvred" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCtb65688/?rfs=iqvred&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;5515-x# copy ftp://johnl:PW@10.1.1.14/home/johnl/asa917-20-smp-k8.bin disk0:&lt;/P&gt;
&lt;P&gt;Accessing ftp://johnl:PW@10.1.1.14/asa917-20-smp-k8.bin...&lt;BR /&gt;%Error reading ftp://johnl:PW@10.1.1.14/asa917-20-smp-k8.bin &lt;FONT color="#FF0000"&gt;(No more processes)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;5515-x# ping tcp 10.1.1.14 21&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;No source specified. Pinging from identity interface.&lt;BR /&gt;Sending 5 TCP SYN requests to 10.1.1.14 port 21&lt;BR /&gt;from 10.23.24.2, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 25/26/31 ms&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;[johnl@ ~]$ ls -lh&lt;BR /&gt;total 37M&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;-rw-------. 1 johnl johnl 37M Mar 24 22:24 asa917-20-smp-k8.bin&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;^C[johnl@~]$ ping 10.23.24.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt; ASA MGMT IP&lt;BR /&gt;PING 10.23.24.2 (10.23.24.2) 56(84) bytes of data.&lt;BR /&gt;64 bytes from 10.23.24.2: icmp_seq=1 ttl=251 time=24.3 ms&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:33:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354523#M1028297</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2020-02-21T15:33:31Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to FTP image to ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354538#M1028298</link>
      <description>Is FTP running on linux? From ASA try to ping tcp on FTP port and see if&lt;BR /&gt;its working&lt;BR /&gt;</description>
      <pubDate>Sun, 25 Mar 2018 05:35:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354538#M1028298</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2018-03-25T05:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to FTP image to ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354576#M1028299</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;i posted an ASA ping tcp 21 on my last post.&lt;/P&gt;
&lt;P&gt;here's the linux output. does it normal FTP?&lt;/P&gt;
&lt;P&gt;sorry i'm a linux noob.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[johnl@~]$ service vsftpd status &lt;BR /&gt;&lt;FONT color="#000000"&gt;vsftpd (pid 1592) is running...&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[johnl@ ~]$ rpm -qa | grep ftp&lt;BR /&gt;ftp-0.17-54.el6.x86_64&lt;BR /&gt;vsftpd-2.2.2-13.el6_6.1.x86_64&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[johnl@~]$ ftp localhost&lt;BR /&gt;Trying ::1...&lt;BR /&gt;ftp: connect to address ::1Connection refused&lt;BR /&gt;Trying 127.0.0.1...&lt;BR /&gt;Connected to localhost (127.0.0.1).&lt;BR /&gt;220 (vsFTPd 2.2.2)&lt;/P&gt;</description>
      <pubDate>Sun, 25 Mar 2018 09:34:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354576#M1028299</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2018-03-25T09:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to FTP image to ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354587#M1028300</link>
      <description>Yes seems it needs SFTP only. If its not listening locally it can't be ASA&lt;BR /&gt;problem&lt;BR /&gt;</description>
      <pubDate>Sun, 25 Mar 2018 10:16:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354587#M1028300</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2018-03-25T10:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to FTP image to ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354599#M1028518</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;what do u mean by SFTP only? does SFTP only runs on linux server per output given?&lt;/P&gt;
&lt;P&gt;i'm not the admin of the said server. please advise what needs to be done in order for normal FTP to work.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Mar 2018 11:21:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354599#M1028518</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2018-03-25T11:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to FTP image to ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354610#M1028519</link>
      <description>-##You need to install ftp app&lt;BR /&gt;</description>
      <pubDate>Sun, 25 Mar 2018 12:26:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354610#M1028519</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2018-03-25T12:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to FTP image to ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354626#M1028520</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;but FTP is working. which output are you looking?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[johnl@svr01 ~]$ ftp svr01&lt;BR /&gt;Connected to svr01 (10.1.1.14).&lt;BR /&gt;220 (vsFTPd 2.2.2)&lt;BR /&gt;Name (svr01:john): john&lt;BR /&gt;331 Please specify the password.&lt;BR /&gt;Password:&lt;BR /&gt;230 Login successful.&lt;BR /&gt;Remote system type is UNIX.&lt;BR /&gt;Using binary mode to transfer files.&lt;BR /&gt;ftp&amp;gt; ls&lt;BR /&gt;227 Entering Passive Mode (10,111,0,14,90,196).&lt;BR /&gt;150 Here comes the directory listing.&lt;BR /&gt;-rw-------&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 558&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 558&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1155 Mar 25 05:15 FGL1.lic&lt;BR /&gt;-rw-------&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 558&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 558&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 38338560 Mar 25 03:24 asa917-20-smp-k8.bin&lt;BR /&gt;226 Directory send OK.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Mar 2018 12:50:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354626#M1028520</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2018-03-25T12:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to FTP image to ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354649#M1028521</link>
      <description>&lt;P&gt;What version of ASA software do you currently have? I ask because there was a change in the file structure as of 9.1(3). That change prevents you from successfully copying the new image (.bin file) - whether it is via sfp, scp, tftp, https (ASDM) or whatever method.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In order to upgrade from an older version to 9.1(3) or later (such as the 9.1(7) you are trying) you must first upgrade to an interim version as noted in the 9.1 release notes:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa91/release/notes/asarn91.html#pgfId-763574" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa91/release/notes/asarn91.html#pgfId-763574&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Mar 2018 13:32:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354649#M1028521</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-03-25T13:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to FTP image to ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354653#M1028522</link>
      <description>&lt;P&gt;hi marvin,&lt;/P&gt;
&lt;P&gt;thanks for jumping in! i'm beginning to suspect a bug code here.&lt;/P&gt;
&lt;P&gt;the 5515-x A/S pair currently runs on 9.1(7)4.&lt;/P&gt;
&lt;P&gt;i plan to upgrade the FW pair o &lt;STRONG&gt;9.1.7.20&lt;/STRONG&gt; to patch the recent SSL VPN vulnerability (CVE-2018-0101).&lt;/P&gt;
&lt;P&gt;does this mean i can only upgrade via USB method since FTP is not properly working due to the '(No more processes)'&lt;/P&gt;
&lt;P&gt;which specific bug did i run per the link you gave?&lt;/P&gt;</description>
      <pubDate>Sun, 25 Mar 2018 13:45:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354653#M1028522</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2018-03-25T13:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to FTP image to ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354655#M1028523</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326072"&gt;@johnlloyd_13&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's not a bug so much as it is a documented behavior. However since you are running 9.1(7)4 already it shouldn't affect you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you try copying any other file onto the ASA via ftp - like some random small text file just to verify ftp is working at all? That will rule out any intermediate device that is possibly breaking the ftp data channel. (The login and ls is ftp control channel.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the small file ftp works ok then maybe it is a bug that's not public-facing. I'd try perhaps one of the recommended code releases like the latest interim of 9.4, 9.6 or 9.8. Or if you really really want the latest 9.1.(7) interim then open a TAC case. (Though they may tell you to go with the recommended release as well.)&lt;/P&gt;</description>
      <pubDate>Sun, 25 Mar 2018 14:03:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354655#M1028523</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-03-25T14:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to FTP image to ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354828#M1028524</link>
      <description>&lt;P&gt;hi marvin,&lt;/P&gt;
&lt;P&gt;i tried with a small txt file (11KB) but still getting the same FTP response/error.&lt;/P&gt;
&lt;P&gt;i raised a TAC case to see what they could find.&lt;/P&gt;
&lt;P&gt;i might ask a remote tech to plug a USB stick as last resort.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 02:13:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354828#M1028524</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2018-03-26T02:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to FTP image to ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354959#M1028525</link>
      <description>&lt;P&gt;It's just an educated guess but it sounds like something between your ftp server and the device is running an Application Layer Gateway (ALG = Juniper term as I have seen this issue on both ScreenOS and JunOS-based Juniper firewalls) that's preventing successful ftp data channel communications.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 08:30:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354959#M1028525</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-03-26T08:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to FTP image to ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354964#M1028526</link>
      <description>&lt;P&gt;hi marvin,&lt;/P&gt;
&lt;P&gt;just finished troubleshooting with TAC today and observe the same thing when we did some packet captures. notice it only uses dynamic port and FTP port 21. this is passive FTP correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;183: 22:19:45.681162       802.1Q vlan#1235 P0 10.23.24.2.17535 &amp;gt; 10.1.1.4.21: S 3620565586:3620565586(0) win 32768 &amp;lt;mss 1460,nop,nop,timestamp 4138936578 0&amp;gt; 
184: 22:19:45.705316       802.1Q vlan#1235 P0 10.1.1.4.35630 &amp;gt; 10.23.24.2.22: . ack 437914409 win 65535 
185: 22:19:45.706277       802.1Q vlan#1235 P0 10.1.1.4.35630 &amp;gt; 10.23.24.2.22: . ack 437914461 win 65535 
186: 22:19:45.706292       802.1Q vlan#1235 P0 10.1.1.4.21 &amp;gt; 10.23.24.2.17535: S 1557221194:1557221194(0) ack 3620565587 win 14480 &amp;lt;mss 1380,nop,nop,timestamp 4181033265 4138936578&amp;gt; 
187: 22:19:45.706308       802.1Q vlan#1235 P0 10.23.24.2.17535 &amp;gt; 10.1.1.4.21: . ack 1557221195 win 32768 &amp;lt;nop,nop,timestamp 4138936603 4181033265&amp;gt; 
188: 22:19:45.735283       802.1Q vlan#1235 P0 10.1.1.4.21 &amp;gt; 10.23.24.2.17535: P 1557221195:1557221215(20) ack 3620565587 win 14480 &amp;lt;nop,nop,timestamp 4181033293 4138936603&amp;gt; 
189: 22:19:45.735313       802.1Q vlan#1235 P0 10.23.24.2.17535 &amp;gt; 10.1.1.4.21: . ack 1557221215 win 32768 &amp;lt;nop,nop,timestamp 4138936632 4181033293&amp;gt; 
190: 22:19:45.735405       802.1Q vlan#1235 P0 10.23.24.2.17535 &amp;gt; 10.1.1.4.21: P 3620565587:3620565599(12) ack 1557221215 win 32768 &amp;lt;nop,nop,timestamp 4138936633 0&amp;gt; 
191: 22:19:45.760321       802.1Q vlan#1235 P0 10.1.1.4.21 &amp;gt; 10.23.24.2.17535: . ack 3620565599 win 14480 &amp;lt;nop,nop,timestamp 41810333
&lt;/PRE&gt;
&lt;P&gt;i only noticed our linux server is using ACTIVE FTP (passive mode off) after tshooting was already done. could this be the culprit? do you know if linux server can be tweaked to support PASSIVE FTP?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[john@~]$ ftp&lt;BR /&gt;ftp&amp;gt; passive&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Passive mode off.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 08:35:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3354964#M1028526</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2018-03-26T08:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to FTP image to ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3355105#M1028527</link>
      <description>&lt;P&gt;It could&amp;nbsp; be, I'm not sure about that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you just try an FTP server like filezilla (free) on your laptop? Or are you limited to using a Linux jump server for the remote environment?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 13:18:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3355105#M1028527</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-03-26T13:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to FTP image to ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3355471#M1028528</link>
      <description>&lt;P&gt;unfortunately i'm only limited to this linux server.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 22:01:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ftp-image-to-asa-5515-x/m-p/3355471#M1028528</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2018-03-26T22:01:31Z</dc:date>
    </item>
  </channel>
</rss>

