<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/active-ftp-not-working-after-switch-from-asa-5510-to-asa-5515-x/m-p/2934206#M149274</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;From the ASA perspective, if i understand correctly, your FTP server is on inside and and client is on outside. Is that correct ?&lt;/P&gt;
&lt;P&gt;Please share the output of "show run policy-map" ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;-&lt;/P&gt;
&lt;P&gt;Pulkit&lt;/P&gt;</description>
    <pubDate>Thu, 13 Oct 2016 10:48:33 GMT</pubDate>
    <dc:creator>Pulkit Saxena</dc:creator>
    <dc:date>2016-10-13T10:48:33Z</dc:date>
    <item>
      <title>Active FTP not working after switch from ASA 5510 to Asa 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-not-working-after-switch-from-asa-5510-to-asa-5515-x/m-p/2934203#M149271</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We replaced an old asa 5510 with an Asa 5515-X.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have configured access-lists and NAT Rules (port 20 and 21)&lt;/P&gt;
&lt;P&gt;Passive FTP working&amp;nbsp;with and without TLS.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Active FTP logs in but timeout at directory listing.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;i can see the user loggin in at my FTP server.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;There is no Drops on the asa, used Packet-tracer/capturing along with wireshark.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The servers Syn simply does not reach my client ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any Ideas. it works perfect with my 5510&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;also got this from a ftp tester, confirming my thoughts about TLS being breaked. (see Attachment)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:23:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-not-working-after-switch-from-asa-5510-to-asa-5515-x/m-p/2934203#M149271</guid>
      <dc:creator>mn</dc:creator>
      <dc:date>2019-03-12T08:23:33Z</dc:date>
    </item>
    <item>
      <title>Issue seems to be with the</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-not-working-after-switch-from-asa-5510-to-asa-5515-x/m-p/2934204#M149272</link>
      <description>&lt;P&gt;Issue seems to be with the data channel, your server is on trusted network or you are accessing a server on internet.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We need to allow in access list traffic accordingly, to the real IP of nat and inspect ftp command is also required.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;-&lt;/P&gt;
&lt;P&gt;Pulkit&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2016 10:38:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-not-working-after-switch-from-asa-5510-to-asa-5515-x/m-p/2934204#M149272</guid>
      <dc:creator>Pulkit Saxena</dc:creator>
      <dc:date>2016-10-13T10:38:25Z</dc:date>
    </item>
    <item>
      <title>Hi Pulkit.</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-not-working-after-switch-from-asa-5510-to-asa-5515-x/m-p/2934205#M149273</link>
      <description>&lt;P&gt;Hi Pulkit.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The FTP server is in my datacenter (off location from office) and my client is on lan.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Ftp Srever is based on inside network of ASA and nattet to Public IP.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What inspect FTp Command are you refering to ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Public Ip of FTP is 81.27.214.127 and public ip of client is 81.27.211.178&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2016 10:41:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-not-working-after-switch-from-asa-5510-to-asa-5515-x/m-p/2934205#M149273</guid>
      <dc:creator>mn</dc:creator>
      <dc:date>2016-10-13T10:41:43Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-not-working-after-switch-from-asa-5510-to-asa-5515-x/m-p/2934206#M149274</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;From the ASA perspective, if i understand correctly, your FTP server is on inside and and client is on outside. Is that correct ?&lt;/P&gt;
&lt;P&gt;Please share the output of "show run policy-map" ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;-&lt;/P&gt;
&lt;P&gt;Pulkit&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2016 10:48:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-not-working-after-switch-from-asa-5510-to-asa-5515-x/m-p/2934206#M149274</guid>
      <dc:creator>Pulkit Saxena</dc:creator>
      <dc:date>2016-10-13T10:48:33Z</dc:date>
    </item>
    <item>
      <title>Exactly, It is all clients</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-not-working-after-switch-from-asa-5510-to-asa-5515-x/m-p/2934207#M149275</link>
      <description>&lt;P&gt;Exactly, It is all clients from all over that hangs on showing directory list.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;sh run policy-map&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt; message-length maximum client auto&lt;BR /&gt; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt; inspect dns preset_dns_map&lt;BR /&gt; inspect rsh&lt;BR /&gt; inspect rtsp&lt;BR /&gt; inspect sqlnet&lt;BR /&gt; inspect skinny&lt;BR /&gt; inspect sunrpc&lt;BR /&gt; inspect xdmcp&lt;BR /&gt; inspect sip&lt;BR /&gt; inspect netbios&lt;BR /&gt; inspect ip-options&lt;BR /&gt; inspect icmp&lt;BR /&gt; inspect icmp error&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2016 10:50:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-not-working-after-switch-from-asa-5510-to-asa-5515-x/m-p/2934207#M149275</guid>
      <dc:creator>mn</dc:creator>
      <dc:date>2016-10-13T10:50:36Z</dc:date>
    </item>
    <item>
      <title>Please answer the below :</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-not-working-after-switch-from-asa-5510-to-asa-5515-x/m-p/2934208#M149276</link>
      <description>&lt;P&gt;Please answer the below :&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;a) You have static NAT or static PAT ?&lt;/P&gt;
&lt;P&gt;b) In access list on outside interface, you have allowed traffic for the complete IP or only port ?&lt;/P&gt;
&lt;P&gt;c) Do you have any access list on inside interface also, since data channel will be initiated by the server.&lt;/P&gt;
&lt;P&gt;d) Please configure "ftp inspection" by the following :&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;policy-map global_policy&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;class inspection_default&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;inspect ftp&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;exit&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;exit&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Test and let me know.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;-&lt;/P&gt;
&lt;P&gt;Pulkit&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2016 10:55:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-not-working-after-switch-from-asa-5510-to-asa-5515-x/m-p/2934208#M149276</guid>
      <dc:creator>Pulkit Saxena</dc:creator>
      <dc:date>2016-10-13T10:55:03Z</dc:date>
    </item>
    <item>
      <title>I Use static NAT:</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-not-working-after-switch-from-asa-5510-to-asa-5515-x/m-p/2934209#M149279</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;I Use static NAT:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;3 (outside) to (inside) source static any any&amp;nbsp; destination static Pub-DK-Sync-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;Priv-DK-Sync-1 service FTP FTP no-proxy-arp&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;4 (outside) to (inside) source static any any&amp;nbsp; destination static Pub-DK-Sync-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Priv-DK-Sync-1 service FTP20 FTP20 no-proxy-arp&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;Acces_list&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;access-list outside_access_in line 3 extended permit tcp any host 81.27.214.178 eq ftp log informational interval 300 (hitcnt=0) 0x8665beac&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;&amp;nbsp; access-list outside_access_in line 3 extended permit tcp any host 81.27.214.178 eq ftp-data log informational interval 300 (hitcnt=0) 0xcf5d8e2e&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;No ACL on inside-&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;I’ve tested the FTP Inspection but no luck&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2016 11:01:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-not-working-after-switch-from-asa-5510-to-asa-5515-x/m-p/2934209#M149279</guid>
      <dc:creator>mn</dc:creator>
      <dc:date>2016-10-13T11:01:08Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-not-working-after-switch-from-asa-5510-to-asa-5515-x/m-p/2934210#M149281</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Issue is with the NAT, when data channel is initiated, it will not work.&lt;/P&gt;
&lt;P&gt;Apply the following NAT :&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;nat (outside,inside) 1 source static any any destination static&amp;nbsp;&lt;SPAN&gt;Pub-DK-Sync-1&amp;nbsp;Priv-DK-Sync-1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On the new codes, you need to allow the real IP in the access list, so the access list will be :&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;access-list outside_access_in line 1 permit ip any &amp;lt;real ip of server&amp;gt; eq 21&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;Do keep the inspect ftp.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am pretty sure this should help resolve the issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Pulkit&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2016 11:07:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-not-working-after-switch-from-asa-5510-to-asa-5515-x/m-p/2934210#M149281</guid>
      <dc:creator>Pulkit Saxena</dc:creator>
      <dc:date>2016-10-13T11:07:22Z</dc:date>
    </item>
  </channel>
</rss>

