<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SFTP through Cisco ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sftp-through-cisco-asa/m-p/2100546#M392448</link>
    <description>&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;We are trying to get SFTP working from a server (x.x.128.13) within our network to another companies server (x.x.114.132) which we connect to via the Internet.&amp;nbsp; From our server the connection hits our ASA Firewall where we have rules in place to allow the connection on a customised port of 29052. The firewall then NAT's the Source IP of our server to a Public IP (x.x.36.60), thus making it routable on the Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;We have done some packet captures on our ingress (inside) interface and egress (internet) interface and we can see that the 3 way TCP handshake is successful between the two servers but then all further communication fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;We see no further packets on our ingress interface but we do see further packets on the egress side.&amp;nbsp; What we see is a "RST+ACK" from the destination server but this is never passed on to the server within our network.&amp;nbsp; We also see our ack packet from the 3 way handshake being sent back to the destination server but again this only appears for the egress capture, and is not being sent by the server.&amp;nbsp; Both of these packets repeat about 6 times and then we see nothing further.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached the packet capture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the far end the 3rd party don't see any of our repeated ACK's and when the connection works normally through a different infrastructure/firewall we see the 4th packet as a normal packet.&amp;nbsp; The initial payload of this RST+ACK is the same payload we see in the 4th packet when the connection works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Any help with this would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Stuart&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:50:14 GMT</pubDate>
    <dc:creator>soliver2005</dc:creator>
    <dc:date>2019-03-12T00:50:14Z</dc:date>
    <item>
      <title>SFTP through Cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/sftp-through-cisco-asa/m-p/2100546#M392448</link>
      <description>&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;We are trying to get SFTP working from a server (x.x.128.13) within our network to another companies server (x.x.114.132) which we connect to via the Internet.&amp;nbsp; From our server the connection hits our ASA Firewall where we have rules in place to allow the connection on a customised port of 29052. The firewall then NAT's the Source IP of our server to a Public IP (x.x.36.60), thus making it routable on the Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;We have done some packet captures on our ingress (inside) interface and egress (internet) interface and we can see that the 3 way TCP handshake is successful between the two servers but then all further communication fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;We see no further packets on our ingress interface but we do see further packets on the egress side.&amp;nbsp; What we see is a "RST+ACK" from the destination server but this is never passed on to the server within our network.&amp;nbsp; We also see our ack packet from the 3 way handshake being sent back to the destination server but again this only appears for the egress capture, and is not being sent by the server.&amp;nbsp; Both of these packets repeat about 6 times and then we see nothing further.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached the packet capture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the far end the 3rd party don't see any of our repeated ACK's and when the connection works normally through a different infrastructure/firewall we see the 4th packet as a normal packet.&amp;nbsp; The initial payload of this RST+ACK is the same payload we see in the 4th packet when the connection works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Any help with this would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Stuart&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:50:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sftp-through-cisco-asa/m-p/2100546#M392448</guid>
      <dc:creator>soliver2005</dc:creator>
      <dc:date>2019-03-12T00:50:14Z</dc:date>
    </item>
    <item>
      <title>SFTP through Cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/sftp-through-cisco-asa/m-p/2100547#M392449</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Soliver,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So basically you are using a customized program that will allow you to run SFTP over port &lt;SPAN style="font-size: 10pt;"&gt;29052? Right?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Either way it's just a single channel so it should not be any problem regarding the firewall not being able to identify the data channel ( as there is only one for both the control/data communication)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way you could share those captures on wireshark.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also do the following capture&lt;/P&gt;&lt;P&gt;cap asp type asp-drop all circular-buffer&lt;/P&gt;&lt;P&gt;Then try to connect and share&lt;/P&gt;&lt;P&gt;show cap asp | include &lt;SPAN style="font-size: 10pt;"&gt;x.x.114.132&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;This will show us if the firewall is dropping some traffic based on it's code ( Acellerated Security Path algorithm)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Julio Carvajal &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jan 2013 18:40:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sftp-through-cisco-asa/m-p/2100547#M392449</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-01-21T18:40:25Z</dc:date>
    </item>
  </channel>
</rss>

