<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Our ASA is blocking FileZilla. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/our-asa-is-blocking-filezilla/m-p/4633871#M1091026</link>
    <description>&lt;P&gt;There is a server on our environment that's running FileZilla and the way we have the rule set up using &lt;STRONG&gt;FMC&lt;/STRONG&gt; is&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Set up: &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Objects:&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Public IP, Private IP.&lt;/P&gt;&lt;P&gt;- Ports that were asked to be opened.&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT Rule: For the public IP to the Private IP&amp;nbsp;&lt;/P&gt;&lt;P&gt;Initial Access Control Policy:&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Zone: SC: Internet, Destination: Lan&lt;/P&gt;&lt;P&gt;Network:&amp;nbsp;&lt;/P&gt;&lt;P&gt;- SC: Any, Destination: Private IP&amp;nbsp;&lt;/P&gt;&lt;P&gt;VLAN Tags, Users, Applications: Set to any.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ports: SC: Any, Dest: the objects selected from when I created the ports.&amp;nbsp;&lt;/P&gt;&lt;P&gt;URLS and SGT/ISE: any.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Issue&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;When someone tries to connect to the server they can get to the port, but TLS connection cant be authenticated so it closes the connection. Not sure what's going on.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Attempts to resolve.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I tried to allow any port to go through, anyone in the internet can go through.&lt;/P&gt;&lt;P&gt;Device Firewall has inbound and outbound ports allowed access.&amp;nbsp;&lt;/P&gt;&lt;P&gt;in the Initial access control policy, I changed it from&lt;/P&gt;&lt;P&gt;SC: Any, Destination: Private IP&amp;nbsp; to&amp;nbsp; SC: Any, Destination: public IP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Temp solution:&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;What seems to work at the moment is when I set up the rule action from&amp;nbsp; Allowed to Trust it let the connection through and TLS authentication was a success, files can be transferred etc. Now if I understand correctly Trust doesn't monitor and basically allowed anything just to go through. Not sure if I want that.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know why it's having this issue? The ASA isn't super configured so it can be assumed that it's a brand new ASA with very little configuration.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jun 2022 16:07:32 GMT</pubDate>
    <dc:creator>JBrav0</dc:creator>
    <dc:date>2022-06-17T16:07:32Z</dc:date>
    <item>
      <title>Our ASA is blocking FileZilla.</title>
      <link>https://community.cisco.com/t5/network-security/our-asa-is-blocking-filezilla/m-p/4633871#M1091026</link>
      <description>&lt;P&gt;There is a server on our environment that's running FileZilla and the way we have the rule set up using &lt;STRONG&gt;FMC&lt;/STRONG&gt; is&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Set up: &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Objects:&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Public IP, Private IP.&lt;/P&gt;&lt;P&gt;- Ports that were asked to be opened.&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT Rule: For the public IP to the Private IP&amp;nbsp;&lt;/P&gt;&lt;P&gt;Initial Access Control Policy:&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Zone: SC: Internet, Destination: Lan&lt;/P&gt;&lt;P&gt;Network:&amp;nbsp;&lt;/P&gt;&lt;P&gt;- SC: Any, Destination: Private IP&amp;nbsp;&lt;/P&gt;&lt;P&gt;VLAN Tags, Users, Applications: Set to any.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ports: SC: Any, Dest: the objects selected from when I created the ports.&amp;nbsp;&lt;/P&gt;&lt;P&gt;URLS and SGT/ISE: any.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Issue&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;When someone tries to connect to the server they can get to the port, but TLS connection cant be authenticated so it closes the connection. Not sure what's going on.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Attempts to resolve.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I tried to allow any port to go through, anyone in the internet can go through.&lt;/P&gt;&lt;P&gt;Device Firewall has inbound and outbound ports allowed access.&amp;nbsp;&lt;/P&gt;&lt;P&gt;in the Initial access control policy, I changed it from&lt;/P&gt;&lt;P&gt;SC: Any, Destination: Private IP&amp;nbsp; to&amp;nbsp; SC: Any, Destination: public IP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Temp solution:&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;What seems to work at the moment is when I set up the rule action from&amp;nbsp; Allowed to Trust it let the connection through and TLS authentication was a success, files can be transferred etc. Now if I understand correctly Trust doesn't monitor and basically allowed anything just to go through. Not sure if I want that.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know why it's having this issue? The ASA isn't super configured so it can be assumed that it's a brand new ASA with very little configuration.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 16:07:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/our-asa-is-blocking-filezilla/m-p/4633871#M1091026</guid>
      <dc:creator>JBrav0</dc:creator>
      <dc:date>2022-06-17T16:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: Our ASA is blocking FileZilla.</title>
      <link>https://community.cisco.com/t5/network-security/our-asa-is-blocking-filezilla/m-p/4634540#M1091046</link>
      <description>&lt;P&gt;What are you using to transfer files? (FTP,SCP, sFTP, etc.)&lt;/P&gt;
&lt;P&gt;So, Trust means just that you will bypass the SNORT process so the rule only acts as a regular ASA access-list rule. However, if you do have something in the rule that requires SNORT to process it and make a verdict on it, then the packet will be sent to SNORT even though you have it configured as trust.&amp;nbsp; an example of this would be if you are using Application instead of, or as well as Port, then the packet will be sent to SNORT for processing Application.&amp;nbsp; If you also have IPS configured for that rule then IPS will also be processed.&amp;nbsp; The only way to truely circumvent SNORT is to either not configure anything that would require SNORT to process the packet or to configure the rule in pre-filter.&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jun 2022 21:37:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/our-asa-is-blocking-filezilla/m-p/4634540#M1091046</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-06-19T21:37:24Z</dc:date>
    </item>
  </channel>
</rss>

