<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ftp mode passive in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftp-mode-passive/m-p/2216944#M350019</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration should only be related to the firewall device itself and not the connections going through it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest first monitoring the problematic connections through the logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or possible configuring traffic capture on the firewall device to see if there is any return traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other than that should naturally confirm that no NAT configuration or their order isnt causing problems OR that there is no problem with routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why are you moving to the FWSM by the way? Its a product on its way out of the market and is replaced by the ASASM which again supports software levels past 8.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Naturally if we are talking about existing equipment then its understandable, but otherwise ASASM or a separate new ASA would be a better choice for example because of the software levels supported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 13 May 2013 12:27:40 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-05-13T12:27:40Z</dc:date>
    <item>
      <title>ftp mode passive</title>
      <link>https://community.cisco.com/t5/network-security/ftp-mode-passive/m-p/2216943#M350018</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I have one issue. I have to migrate some customers from ASA 5510 /8.2(5)26 to FWSM /4.1(9) &amp;lt;context&amp;gt;. Passive mode is not working on FWSM.&lt;/P&gt;&lt;P&gt;Config is same on both devices, NAT,ACL,inspection,routing..everything except one command ftp mode passive. &lt;/P&gt;&lt;P&gt;Can command ftp mode passive cause the issue? Or this command is used for passive FTP from FW not thru FW?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:42:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-mode-passive/m-p/2216943#M350018</guid>
      <dc:creator>Michal Valach</dc:creator>
      <dc:date>2019-03-12T01:42:24Z</dc:date>
    </item>
    <item>
      <title>ftp mode passive</title>
      <link>https://community.cisco.com/t5/network-security/ftp-mode-passive/m-p/2216944#M350019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration should only be related to the firewall device itself and not the connections going through it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest first monitoring the problematic connections through the logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or possible configuring traffic capture on the firewall device to see if there is any return traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other than that should naturally confirm that no NAT configuration or their order isnt causing problems OR that there is no problem with routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why are you moving to the FWSM by the way? Its a product on its way out of the market and is replaced by the ASASM which again supports software levels past 8.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Naturally if we are talking about existing equipment then its understandable, but otherwise ASASM or a separate new ASA would be a better choice for example because of the software levels supported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 May 2013 12:27:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-mode-passive/m-p/2216944#M350019</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-05-13T12:27:40Z</dc:date>
    </item>
    <item>
      <title>ftp mode passive</title>
      <link>https://community.cisco.com/t5/network-security/ftp-mode-passive/m-p/2216945#M350020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Their routing/NAT is also ok, because he is getting login prompt, but once moving to passive mode (PASV message) he is getting disconnecting. I think we will ask them to move to active mode on capture data.&lt;/P&gt;&lt;P&gt;I do not know why FWSM, but I think is temporary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 May 2013 13:30:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-mode-passive/m-p/2216945#M350020</guid>
      <dc:creator>Michal Valach</dc:creator>
      <dc:date>2013-05-13T13:30:42Z</dc:date>
    </item>
    <item>
      <title>ftp mode passive</title>
      <link>https://community.cisco.com/t5/network-security/ftp-mode-passive/m-p/2216946#M350021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post the 'show run' for review and also captures once you've those?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;Sourav&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 May 2013 15:27:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-mode-passive/m-p/2216946#M350021</guid>
      <dc:creator>sokakkar</dc:creator>
      <dc:date>2013-05-13T15:27:54Z</dc:date>
    </item>
    <item>
      <title>ftp mode passive</title>
      <link>https://community.cisco.com/t5/network-security/ftp-mode-passive/m-p/2216947#M350022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi I am sorry but I cannot paste whole config here. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But as I said, ACL is correct, NAT is there, routing, FTP inspection....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 May 2013 09:53:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-mode-passive/m-p/2216947#M350022</guid>
      <dc:creator>Michal Valach</dc:creator>
      <dc:date>2013-05-14T09:53:51Z</dc:date>
    </item>
  </channel>
</rss>

