<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA, Passive FTP (Explicit FTP with TLS) does not work. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-passive-ftp-explicit-ftp-with-tls-does-not-work/m-p/4090940#M1070457</link>
    <description>&lt;P&gt;passitve FTP with TLS you required 1 to 1023 ports - try that and let us know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;your ACL show&amp;nbsp; &amp;gt; 1000&lt;/P&gt;</description>
    <pubDate>Fri, 22 May 2020 20:09:08 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2020-05-22T20:09:08Z</dc:date>
    <item>
      <title>ASA, Passive FTP (Explicit FTP with TLS) does not work.</title>
      <link>https://community.cisco.com/t5/network-security/asa-passive-ftp-explicit-ftp-with-tls-does-not-work/m-p/4090571#M1070420</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am having issues to make work a passive FTP server with explicit TLS encryption because ASA is blocking the response on a random port, even when I have enabled this configuration:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;access-list ftp-list extended permit tcp any any gt 1000&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;class-map ftp-class&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;match access-list ftp-list&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;policy-map global_policy&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;class ftp-class&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;inspect ftp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Problem is that we are using explicit ftp with TLS encryption and this is probably the reason because the ASA is not able to inspect that traffic and block the connection. Do you know if there is a solution for this? Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 09:50:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-passive-ftp-explicit-ftp-with-tls-does-not-work/m-p/4090571#M1070420</guid>
      <dc:creator>morabusa</dc:creator>
      <dc:date>2020-05-22T09:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA, Passive FTP (Explicit FTP with TLS) does not work.</title>
      <link>https://community.cisco.com/t5/network-security/asa-passive-ftp-explicit-ftp-with-tls-does-not-work/m-p/4090940#M1070457</link>
      <description>&lt;P&gt;passitve FTP with TLS you required 1 to 1023 ports - try that and let us know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;your ACL show&amp;nbsp; &amp;gt; 1000&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 20:09:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-passive-ftp-explicit-ftp-with-tls-does-not-work/m-p/4090940#M1070457</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-05-22T20:09:08Z</dc:date>
    </item>
    <item>
      <title>Re: ASA, Passive FTP (Explicit FTP with TLS) does not work.</title>
      <link>https://community.cisco.com/t5/network-security/asa-passive-ftp-explicit-ftp-with-tls-does-not-work/m-p/4091570#M1070476</link>
      <description>&lt;P&gt;I am seeing connection attempts to the ports 40XXX-6XXXX. Anyway, if traffic is encrypted, how the ASA could inspect it? Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2020 08:16:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-passive-ftp-explicit-ftp-with-tls-does-not-work/m-p/4091570#M1070476</guid>
      <dc:creator>morabusa</dc:creator>
      <dc:date>2020-05-25T08:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA, Passive FTP (Explicit FTP with TLS) does not work.</title>
      <link>https://community.cisco.com/t5/network-security/asa-passive-ftp-explicit-ftp-with-tls-does-not-work/m-p/4094523#M1070576</link>
      <description>&lt;P&gt;You're right the encryption will stop the ASA from seeing the packet and therefore won't be able to dynamically open the ports.&amp;nbsp; The passive FTP port range is configured on the server so you could contact whoever manages that, otherwise they tend to be within 49152-65535.&amp;nbsp; FTP isn't a nice protocol for security.&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 17:06:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-passive-ftp-explicit-ftp-with-tls-does-not-work/m-p/4094523#M1070576</guid>
      <dc:creator>rmathieson7</dc:creator>
      <dc:date>2020-05-29T17:06:57Z</dc:date>
    </item>
  </channel>
</rss>

