<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTP over TLS not working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftp-over-tls-not-working/m-p/2005658#M435208</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FTPS is not supported in the ASA.&lt;/P&gt;&lt;P&gt;Due to the problem of traffic beeing encrypted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However you can in some FTPS servers setup that you are only able to use some few ports.&lt;/P&gt;&lt;P&gt;Then you can open for all those ports that you have choosen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want a better alternative than FTPS use SFTP.&lt;/P&gt;&lt;P&gt;FTPS is firewall unfriendly&lt;/P&gt;&lt;P&gt;SFTP is firewall friendly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SFTP will work correctly all the time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Jun 2012 19:02:00 GMT</pubDate>
    <dc:creator>hobbe</dc:creator>
    <dc:date>2012-06-01T19:02:00Z</dc:date>
    <item>
      <title>FTP over TLS not working</title>
      <link>https://community.cisco.com/t5/network-security/ftp-over-tls-not-working/m-p/2005654#M435173</link>
      <description>&lt;P&gt;hi all, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i configured port redirection on ASA to allow external user access to Internal FTPS Server.&amp;nbsp; but it's not working&lt;/P&gt;&lt;P&gt; i use Filezilla client to access but i have this error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Statut :&amp;nbsp;&amp;nbsp;&amp;nbsp; Connexion à x.x.x.x:21...&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Statut :&amp;nbsp;&amp;nbsp;&amp;nbsp; Connexion établie, attente du message d'accueil...&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Réponse :&amp;nbsp;&amp;nbsp;&amp;nbsp; 220-Microsoft FTP Service&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Réponse :&amp;nbsp;&amp;nbsp;&amp;nbsp; 220 FTP-Server FTP&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Commande :&amp;nbsp;&amp;nbsp;&amp;nbsp; AUTH TLS&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Réponse :&amp;nbsp;&amp;nbsp;&amp;nbsp; 234 AUTH command ok. Expecting TLS Negotiation.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="color: #800000; "&gt;Statut :&amp;nbsp;&amp;nbsp;&amp;nbsp; Initialisation de TLS...&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="color: #800000; "&gt;Erreur :&amp;nbsp;&amp;nbsp;&amp;nbsp; Délai d'attente expiré&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="color: #800000; "&gt;Erreur :&amp;nbsp;&amp;nbsp;&amp;nbsp; Impossible d'établir une connexion au serveur&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please can somebody know what can cause this issue ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your help &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:14:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-over-tls-not-working/m-p/2005654#M435173</guid>
      <dc:creator>piatthi1983</dc:creator>
      <dc:date>2019-03-11T23:14:24Z</dc:date>
    </item>
    <item>
      <title>FTP over TLS not working</title>
      <link>https://community.cisco.com/t5/network-security/ftp-over-tls-not-working/m-p/2005655#M435183</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this FTPS server working on active mode?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you share the nat configuration for the server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 15:49:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-over-tls-not-working/m-p/2005655#M435183</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-06-01T15:49:08Z</dc:date>
    </item>
    <item>
      <title>FTP over TLS not working</title>
      <link>https://community.cisco.com/t5/network-security/ftp-over-tls-not-working/m-p/2005656#M435191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA is configured in Passive Mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is NAT configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (DMZ1,outside) tcp&amp;nbsp; interface&amp;nbsp; 20&amp;nbsp; 'ftps-server-private IP'&amp;nbsp; 20&lt;/P&gt;&lt;P&gt;static (DMZ1,outside) tcp&amp;nbsp; interface&amp;nbsp; 21&amp;nbsp; 'ftps-server-private IP'&amp;nbsp; 21&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in&amp;nbsp; extended permit tcp any host 'Outside_public_IP' eq 20&lt;/P&gt;&lt;P&gt;access-list outside_access_in&amp;nbsp; extended permit tcp any host 'Outside_public_IP' eq 21&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 15:55:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-over-tls-not-working/m-p/2005656#M435191</guid>
      <dc:creator>piatthi1983</dc:creator>
      <dc:date>2012-06-01T15:55:16Z</dc:date>
    </item>
    <item>
      <title>FTP over TLS not working</title>
      <link>https://community.cisco.com/t5/network-security/ftp-over-tls-not-working/m-p/2005657#M435200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a document that you will need to read &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-23206"&gt;https://supportforums.cisco.com/docs/DOC-23206&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see you will be using&amp;nbsp;&amp;nbsp; FTPS (FTP over SSL) that uses port 990 for the control channel (this information is encrypted) and the data channel goes on plain text.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way you can use a static one to one and then allow port 990 on the outside ACL?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 16:32:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-over-tls-not-working/m-p/2005657#M435200</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-06-01T16:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: FTP over TLS not working</title>
      <link>https://community.cisco.com/t5/network-security/ftp-over-tls-not-working/m-p/2005658#M435208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FTPS is not supported in the ASA.&lt;/P&gt;&lt;P&gt;Due to the problem of traffic beeing encrypted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However you can in some FTPS servers setup that you are only able to use some few ports.&lt;/P&gt;&lt;P&gt;Then you can open for all those ports that you have choosen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want a better alternative than FTPS use SFTP.&lt;/P&gt;&lt;P&gt;FTPS is firewall unfriendly&lt;/P&gt;&lt;P&gt;SFTP is firewall friendly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SFTP will work correctly all the time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 19:02:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-over-tls-not-working/m-p/2005658#M435208</guid>
      <dc:creator>hobbe</dc:creator>
      <dc:date>2012-06-01T19:02:00Z</dc:date>
    </item>
  </channel>
</rss>

