<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTP inspection on FTD? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/4194115#M1076456</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/132383"&gt;@dejan_jov1&lt;/a&gt;&amp;nbsp; , &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/266761"&gt;@socratesp1980&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I have exactly the same problem. &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;But I don´t want the traffic goes through FTD without inspection.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What is your idea in this regard.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Thanks in advance.&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 06 Dec 2020 11:25:05 GMT</pubDate>
    <dc:creator>Shervin SoAb</dc:creator>
    <dc:date>2020-12-06T11:25:05Z</dc:date>
    <item>
      <title>FTP inspection on FTD?</title>
      <link>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/3810620#M17686</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what is the correct way to configure the FTD 21XX so that the internal clients can use FTP on external ftp servers.&lt;/P&gt;
&lt;P&gt;I know that on ASAs we had ftp inspection that worked but i have hard time to find out how to configure the Firepower.&lt;/P&gt;
&lt;P&gt;I see that clients can connect to servers on dest port 21 but they are blocked as soon as the server tries to make new connection to clients on source port 21 and then on high numbered ports.&lt;/P&gt;
&lt;P&gt;I tried to configure access rules with ports and with applications but with same results.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Output from FTD cli:&lt;/P&gt;
&lt;P&gt;&amp;gt; show running-config | include ftp&lt;BR /&gt;ftp mode passive&lt;/P&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;P&gt;inspect ftp&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:52:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/3810620#M17686</guid>
      <dc:creator>dejan_jov1</dc:creator>
      <dc:date>2020-02-21T16:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: FTP inspection on FTD?</title>
      <link>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/3810647#M17689</link>
      <description>&lt;P&gt;Hello dejan_jov1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This may can be done using the flexconfig&lt;/P&gt;
&lt;P&gt;Objects --&amp;gt; Object Management --&amp;gt; FlexConfig --&amp;gt; FlexConfig Object&lt;/P&gt;
&lt;P&gt;Find the "Default_Inspection_protocol_disable edit it&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and on the "variables place write the value ftp&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then on devices Flexconfig create&amp;nbsp;a new policy on your ftd and add the&amp;nbsp;Default_Inspection_protocol_disable&lt;/P&gt;
&lt;P&gt;Save and apply&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that works&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 08:58:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/3810647#M17689</guid>
      <dc:creator>socratesp1980</dc:creator>
      <dc:date>2019-02-27T08:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: FTP inspection on FTD?</title>
      <link>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/3810677#M17690</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your reply!&lt;/P&gt;
&lt;P&gt;Do I understand this correctly: I need to disable "inspect ftp" over Flexconfig so that my internal users can use active and passive ftp?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 09:37:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/3810677#M17690</guid>
      <dc:creator>dejan_jov1</dc:creator>
      <dc:date>2019-02-27T09:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: FTP inspection on FTD?</title>
      <link>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/3810684#M17691</link>
      <description>Actually yes,

This will remove the ftp protocol from your inspection policies.  If you do a configuration preview Under flex config policy you will the correct configuration command that will be applied</description>
      <pubDate>Wed, 27 Feb 2019 09:42:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/3810684#M17691</guid>
      <dc:creator>socratesp1980</dc:creator>
      <dc:date>2019-02-27T09:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: FTP inspection on FTD?</title>
      <link>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/3810710#M17692</link>
      <description>&lt;P&gt;I configured the "no inspect ftp" on FTD trough CLI I see that it is turned off in global_policy map, but unfortunatelly it is still not working. Maybe I haven't corectly explained it but this ist the problem that I have:&lt;/P&gt;
&lt;P&gt;In event logs I see this Block action that is causing the problems:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Event log.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/31035i3AA6FA4C94F22281/image-size/large?v=v2&amp;amp;px=999" role="button" title="Event log.jpg" alt="Event log.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my Access policies I allowed that my internal Users can reach external FTP servers and here I even allowed that the exernal servers can reach my internal users with TCP source port 21.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 10:16:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/3810710#M17692</guid>
      <dc:creator>dejan_jov1</dc:creator>
      <dc:date>2019-02-27T10:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: FTP inspection on FTD?</title>
      <link>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/3810735#M17693</link>
      <description>It looks your access lists are working fine. Though your ftp application I using other non-standard ports (63103,63102,63106 etc). I think it is something you need to sort it with your application. Maybe it needs a certain number of tcp ports to work and you should add them to an object.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 27 Feb 2019 10:47:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/3810735#M17693</guid>
      <dc:creator>socratesp1980</dc:creator>
      <dc:date>2019-02-27T10:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: FTP inspection on FTD?</title>
      <link>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/3810794#M17694</link>
      <description>&lt;P&gt;I can't open all the ports that the ftp is using, it's simply to many of them. This is normal behavior of FTP that the server is trying to open a second channel to client but I don't want to open the whole range of ports for FTP to work...&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 11:57:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/3810794#M17694</guid>
      <dc:creator>dejan_jov1</dc:creator>
      <dc:date>2019-02-27T11:57:08Z</dc:date>
    </item>
    <item>
      <title>Re: FTP inspection on FTD?</title>
      <link>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/3818135#M17695</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a Workaround I configured an Prefilter Policy with Fastpath Action for TCP 21 port and it works this way.&lt;/P&gt;
&lt;P&gt;But this is also only an temporary solution because this way we have no advanced features for this traffic.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 14:39:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/3818135#M17695</guid>
      <dc:creator>dejan_jov1</dc:creator>
      <dc:date>2019-03-12T14:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: FTP inspection on FTD?</title>
      <link>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/4194115#M1076456</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/132383"&gt;@dejan_jov1&lt;/a&gt;&amp;nbsp; , &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/266761"&gt;@socratesp1980&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I have exactly the same problem. &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;But I don´t want the traffic goes through FTD without inspection.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What is your idea in this regard.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Thanks in advance.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Dec 2020 11:25:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/4194115#M1076456</guid>
      <dc:creator>Shervin SoAb</dc:creator>
      <dc:date>2020-12-06T11:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: FTP inspection on FTD?</title>
      <link>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/4195014#M1076501</link>
      <description>&lt;P&gt;Even if you fastpath through FTD using a prefilter rule, the flow should still hit any configured ALG (Application Layer Gateway = service policy-based inspection) that's configured in the LINA code.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 08:34:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-inspection-on-ftd/m-p/4195014#M1076501</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-12-08T08:34:26Z</dc:date>
    </item>
  </channel>
</rss>

