<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTP issue through Firewall(2) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftp-issue-through-firewall-2/m-p/1785387#M533850</link>
    <description>&lt;P&gt;***This is the 2nd instance of this post.&amp;nbsp; I had to post it again, as I had inadvertently hit "ANSWERED" on the original post.&amp;nbsp; The question is still "NOT ANSWERED".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the original post...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a very interesting problem at a client site this morning.&amp;nbsp; Here is a summary of the problem in a nutshell.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This specific client has set up FTP to an FTP server in a DMZ at their Headquarters building.&amp;nbsp; They have two Production servers that send FTP data to the box in the DMZ.&amp;nbsp; The 1st of the two servers sending FTP data is located on the inside network (they use an ASA with a inside, outside, DMZ, WAN) and sends the FTP data into the box on the DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 2nd of the two production servers is located across the WAN interface of the ASA.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue is as follows:&amp;nbsp; Server 1 can perform all of its ftp commands correctly once it has connected to the FTP server in the DMZ.&amp;nbsp; Server 2 can log into the FTP server and authenticate successfully, but when a "ls" command or and "dir" command is issued, there is no response (the contents of the root folder are not listed as they are when the same command is issued on the 1st server).&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been running sniffer on the FTP server in the DMZ, but cannot tell from the traces what is wrong.&amp;nbsp; I have a hard time beleiving that this may be an ACL issue, as if FTP was not allowed coming in from the WAN interface, then they would not have the ability to authenticate.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am wondering if anyone has seen behavior like this before...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help or insight.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kevin&amp;nbsp; &lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 21:09:59 GMT</pubDate>
    <dc:creator>Kevin Melton</dc:creator>
    <dc:date>2019-03-11T21:09:59Z</dc:date>
    <item>
      <title>FTP issue through Firewall(2)</title>
      <link>https://community.cisco.com/t5/network-security/ftp-issue-through-firewall-2/m-p/1785387#M533850</link>
      <description>&lt;P&gt;***This is the 2nd instance of this post.&amp;nbsp; I had to post it again, as I had inadvertently hit "ANSWERED" on the original post.&amp;nbsp; The question is still "NOT ANSWERED".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the original post...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a very interesting problem at a client site this morning.&amp;nbsp; Here is a summary of the problem in a nutshell.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This specific client has set up FTP to an FTP server in a DMZ at their Headquarters building.&amp;nbsp; They have two Production servers that send FTP data to the box in the DMZ.&amp;nbsp; The 1st of the two servers sending FTP data is located on the inside network (they use an ASA with a inside, outside, DMZ, WAN) and sends the FTP data into the box on the DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 2nd of the two production servers is located across the WAN interface of the ASA.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue is as follows:&amp;nbsp; Server 1 can perform all of its ftp commands correctly once it has connected to the FTP server in the DMZ.&amp;nbsp; Server 2 can log into the FTP server and authenticate successfully, but when a "ls" command or and "dir" command is issued, there is no response (the contents of the root folder are not listed as they are when the same command is issued on the 1st server).&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been running sniffer on the FTP server in the DMZ, but cannot tell from the traces what is wrong.&amp;nbsp; I have a hard time beleiving that this may be an ACL issue, as if FTP was not allowed coming in from the WAN interface, then they would not have the ability to authenticate.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am wondering if anyone has seen behavior like this before...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help or insight.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kevin&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:09:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-issue-through-firewall-2/m-p/1785387#M533850</guid>
      <dc:creator>Kevin Melton</dc:creator>
      <dc:date>2019-03-11T21:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: FTP issue through Firewall(2)</title>
      <link>https://community.cisco.com/t5/network-security/ftp-issue-through-firewall-2/m-p/1785388#M533852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is FTP inpsection enabled? If so, you might try turning that off.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is ftp mode passive enabled? If so, you might try changing that to ftp mode active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just a couple of quick and easy ideas to try. Hope it helps. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Aug 2011 18:43:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-issue-through-firewall-2/m-p/1785388#M533852</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2011-08-10T18:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: FTP issue through Firewall(2)</title>
      <link>https://community.cisco.com/t5/network-security/ftp-issue-through-firewall-2/m-p/1785389#M533854</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;conversely, if you don't have FTP Inspection enabled, turn it on and see what happens.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Aug 2011 18:46:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-issue-through-firewall-2/m-p/1785389#M533854</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2011-08-10T18:46:25Z</dc:date>
    </item>
    <item>
      <title>FTP issue through Firewall(2)</title>
      <link>https://community.cisco.com/t5/network-security/ftp-issue-through-firewall-2/m-p/1785390#M533856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Well I was able to take the inspect FTP out of the policy map global.&amp;nbsp; Unfortunantly this had no bearing on resolving the issue.&amp;nbsp;&amp;nbsp; We are still able to log into the ftp server from the Production Server on the other side of the WAN interface, but cannot do an ls or a dir command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the response anyhow.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Aug 2011 20:05:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-issue-through-firewall-2/m-p/1785390#M533856</guid>
      <dc:creator>Kevin Melton</dc:creator>
      <dc:date>2011-08-10T20:05:56Z</dc:date>
    </item>
    <item>
      <title>FTP issue through Firewall(2)</title>
      <link>https://community.cisco.com/t5/network-security/ftp-issue-through-firewall-2/m-p/1785391#M533857</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Seems to be a active/passive FTP mode issue change the mode and try.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;ajay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Aug 2011 13:05:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-issue-through-firewall-2/m-p/1785391#M533857</guid>
      <dc:creator>ajay chauhan</dc:creator>
      <dc:date>2011-08-11T13:05:15Z</dc:date>
    </item>
    <item>
      <title>FTP issue through Firewall(2)</title>
      <link>https://community.cisco.com/t5/network-security/ftp-issue-through-firewall-2/m-p/1785392#M533858</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Actually it did seem to be the differnece betweent the two. I found an article and ended up opening ephemeral ports and that allowed the connection to occur.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Aug 2011 18:42:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-issue-through-firewall-2/m-p/1785392#M533858</guid>
      <dc:creator>Kevin Melton</dc:creator>
      <dc:date>2011-08-11T18:42:08Z</dc:date>
    </item>
    <item>
      <title>FTP issue through Firewall(2)</title>
      <link>https://community.cisco.com/t5/network-security/ftp-issue-through-firewall-2/m-p/1785393#M533859</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to allow all port between WAN to DMZ FTP server IP address...in acl..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Aug 2011 02:35:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-issue-through-firewall-2/m-p/1785393#M533859</guid>
      <dc:creator>NAGISWAREN2</dc:creator>
      <dc:date>2011-08-12T02:35:05Z</dc:date>
    </item>
  </channel>
</rss>

