<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CBAC - FTP and PAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cbac-ftp-and-pat/m-p/2306152#M343512</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the information which you provided earlier, data connection from client to server is failing. And that is the reason I requested for above outputs, these can help us understand the point of failure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition, can you run wireshark on host and post the captures as well?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sourav Kakkar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 13 Sep 2013 14:27:05 GMT</pubDate>
    <dc:creator>sokakkar</dc:creator>
    <dc:date>2013-09-13T14:27:05Z</dc:date>
    <item>
      <title>CBAC - FTP and PAT</title>
      <link>https://community.cisco.com/t5/network-security/cbac-ftp-and-pat/m-p/2306149#M343507</link>
      <description>&lt;P&gt;We have an unclass setup where we are PAT'ing to the internet via a 2911 router.&amp;nbsp; We've found that passive FTP from internal (client) to public ftp server is not working and I've confirmed there is no ACL denying.&amp;nbsp; The initial connection (login) is fine but when trying to actually send data we see timeouts.&amp;nbsp; I'm thinking this is because I'm not doing this on a firewall with inspect ftp enabled. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;So I enabled the security feature so I could configure CBAC but that doesn't seem to correct my problem with FTP (active and/or passive).&amp;nbsp; G0/0 is my interface to the outside world and I'm applying the CBAC there.&amp;nbsp; Let me know what you think....I'm sure someone has ran into this before and I'm stumped here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;Below are snippits of my config...&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;OUTPUT and CONFIG snippets&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive-quote" style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff; margin: 0px 0px 0px 40px; border: none;"&gt;&lt;BLOCKQUOTE class="jive-quote" style="margin: 0px 0px 0px 40px; border: none;"&gt;ip inspect name firewall ftp&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE class="jive-quote" style="margin: 0px 0px 0px 40px; border: none;"&gt;ip inspect name firewall tcp&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE class="jive-quote" style="margin: 0px 0px 0px 40px; border: none;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;access-list 199 deny&amp;nbsp;&amp;nbsp; ip any any&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE class="jive-quote" style="margin: 0px 0px 0px 40px; border: none;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;interface GigabitEthernet0/0&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE class="jive-quote" style="margin: 0px 0px 0px 40px; border: none;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip address x.x.x.x x.x.x.x&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE class="jive-quote" style="margin: 0px 0px 0px 40px; border: none;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip access-group 199 in&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE class="jive-quote" style="margin: 0px 0px 0px 40px; border: none;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; no ip redirects&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE class="jive-quote" style="margin: 0px 0px 0px 40px; border: none;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip nat outside&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE class="jive-quote" style="margin: 0px 0px 0px 40px; border: none;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip inspect firewall out&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE class="jive-quote" style="margin: 0px 0px 0px 40px; border: none;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip virtual-reassembly in&lt;/BLOCKQUOTE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;"show inspect all" shows the following and indicates to me that it is applied correctly.&amp;nbsp; I even see the router tracking (inspecting sessions) via the "show inspect sessions" command.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;SPAN style="color: #333333; font-family: arial, helvetica, sans-serif; font-size: 10pt;"&gt;#sho ip inspect all&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Session audit trail is disabled&lt;/P&gt;&lt;P&gt;Session alert is enabled&lt;/P&gt;&lt;P&gt;one-minute (sampling period) thresholds are [unlimited : unlimited] connections&lt;/P&gt;&lt;P&gt;max-incomplete sessions thresholds are [unlimited : unlimited]&lt;/P&gt;&lt;P&gt;max-incomplete tcp connections per host is unlimited. Block-time 0 minute.&lt;/P&gt;&lt;P&gt;tcp synwait-time is 30 sec -- tcp finwait-time is 5 sec&lt;/P&gt;&lt;P&gt;tcp idle-time is 3600 sec -- udp idle-time is 30 sec&lt;/P&gt;&lt;P&gt;tcp reassembly queue length 16; timeout 5 sec; memory-limit 1024 kilo bytes&lt;/P&gt;&lt;P&gt;dns-timeout is 5 sec&lt;/P&gt;&lt;P&gt;Inspection Rule Configuration&lt;/P&gt;&lt;P&gt; Inspection name firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ftp alert is on audit-trail is off timeout 3600&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp alert is on audit-trail is off timeout 3600&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface Configuration&lt;/P&gt;&lt;P&gt; Interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;&amp;nbsp; Inbound inspection rule is not set&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;STRONG&gt;Outgoing inspection rule is firewall&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ftp alert is on audit-trail is off timeout 3600&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp alert is on audit-trail is off timeout 3600&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dns alert is on audit-trail is off timeout 30&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt; Inbound access list is 199&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Outgoing access list is not set&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ERROR WHEN TRYING FTP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;ftp&amp;gt; open&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;To &lt;A href="http://ftp.hp.com/" style="color: #1155cc;" target="_blank"&gt;ftp.hp.com&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;Connected to &lt;A href="http://ftp.hpgtm.nsatc.net/" style="color: #1155cc;" target="_blank"&gt;ftp.hpgtm.nsatc.net&lt;/A&gt;.&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;220 &lt;A href="http://g6u0651.atlanta.hp.com/" style="color: #1155cc;" target="_blank"&gt;g6u0651.atlanta.hp.com&lt;/A&gt; FTP server (&lt;A href="http://hp.com/" style="color: #1155cc;" target="_blank"&gt;hp.com&lt;/A&gt; version whp02s_p1) ready.&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;User (ftp.hpgtm.nsatc.net:(none)): anonymous&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;331 Guest login ok, send your complete e-mail address as password.&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;Password:&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;230 Guest login ok, access restrictions apply.&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;ftp&amp;gt; quote PASV&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;227 Entering Passive Mode (15,193,112,141,160,114)&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;ftp&amp;gt; dir&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;STRONG&gt;200 PORT command successful.&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;STRONG&gt;425 Can't build data connection: Connection timed out.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A few other questions.&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; I see that Cisco says they don't support third party FTP.&amp;nbsp; What exactly does that mean?&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; They also say that the data connection will not open if the session is not authenticated.&amp;nbsp; Does anonymous count as being authenticated?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for any ideas!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:34:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-ftp-and-pat/m-p/2306149#M343507</guid>
      <dc:creator>ppalmerjr</dc:creator>
      <dc:date>2019-03-12T02:34:06Z</dc:date>
    </item>
    <item>
      <title>CBAC - FTP and PAT</title>
      <link>https://community.cisco.com/t5/network-security/cbac-ftp-and-pat/m-p/2306150#M343508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To check if CBAC is dropping it. Enable logs on router:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ip inspect log drop-pkt&lt;/P&gt;&lt;P&gt;logg buffered 7&lt;/P&gt;&lt;P&gt;logg enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try FTP and get 'show logg' from CLI and paste it here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, please paste 'show run int xx', where xx is the hardware id for internal interface where client is connected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sourav Kakkar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Sep 2013 18:01:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-ftp-and-pat/m-p/2306150#M343508</guid>
      <dc:creator>sokakkar</dc:creator>
      <dc:date>2013-09-11T18:01:36Z</dc:date>
    </item>
    <item>
      <title>CBAC - FTP and PAT</title>
      <link>https://community.cisco.com/t5/network-security/cbac-ftp-and-pat/m-p/2306151#M343509</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply but I have since learned that I should not neet CBAC for passive FTP connections.&amp;nbsp; I have also learned that through windows ftp.exe you cannot do passive FTP, even though the quote PASV seems to put it in that mode.&amp;nbsp; Evidently, it only tells the server to go passive but windows doesn't support PASV....interesting!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did end up downloading a FTP client that does support PASV mode but am still unable to get it to work through my PAT router.&amp;nbsp; I think the key here is it's a PAT router and not a firewall/ASA.&amp;nbsp; I've tested PAT through a stateful firewall and it works fine....no issue at all.&amp;nbsp; Very interesting stuff here and it is fustrating the heck out of me as to why I can't get this to work!!!&amp;nbsp; Any help appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Sep 2013 13:04:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-ftp-and-pat/m-p/2306151#M343509</guid>
      <dc:creator>ppalmerjr</dc:creator>
      <dc:date>2013-09-13T13:04:07Z</dc:date>
    </item>
    <item>
      <title>CBAC - FTP and PAT</title>
      <link>https://community.cisco.com/t5/network-security/cbac-ftp-and-pat/m-p/2306152#M343512</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the information which you provided earlier, data connection from client to server is failing. And that is the reason I requested for above outputs, these can help us understand the point of failure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition, can you run wireshark on host and post the captures as well?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sourav Kakkar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Sep 2013 14:27:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-ftp-and-pat/m-p/2306152#M343512</guid>
      <dc:creator>sokakkar</dc:creator>
      <dc:date>2013-09-13T14:27:05Z</dc:date>
    </item>
    <item>
      <title>CBAC - FTP and PAT</title>
      <link>https://community.cisco.com/t5/network-security/cbac-ftp-and-pat/m-p/2306153#M343513</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I attached a capture from the client perspective.&amp;nbsp; Please let me know what you think but fromm what I can tell is that I'm not getting a response from the server for some reason....I don't think this really indicates what is the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/2/2/3/158322-FTP.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Sep 2013 18:02:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-ftp-and-pat/m-p/2306153#M343513</guid>
      <dc:creator>ppalmerjr</dc:creator>
      <dc:date>2013-09-26T18:02:32Z</dc:date>
    </item>
  </channel>
</rss>

