<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX fixup direction in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-fixup-direction/m-p/420546#M533896</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does PIX "fixup protocol" command work in both directions? By directions, I mean, from inside to outside and from outside to inside. I know it works for inside to outside, but not sure if it works for outside to inside traffic as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be more specific; if I have an FTP server on the inside and the client on the outside, will my "fixup protocol ftp 21" work when I try to connect from the outside client to the inside server? Will the PIX open up necessary ports for me to have a successful ftp connection?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Mo&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 08:21:04 GMT</pubDate>
    <dc:creator>m.mohanasundaram</dc:creator>
    <dc:date>2020-02-21T08:21:04Z</dc:date>
    <item>
      <title>PIX fixup direction</title>
      <link>https://community.cisco.com/t5/network-security/pix-fixup-direction/m-p/420546#M533896</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does PIX "fixup protocol" command work in both directions? By directions, I mean, from inside to outside and from outside to inside. I know it works for inside to outside, but not sure if it works for outside to inside traffic as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be more specific; if I have an FTP server on the inside and the client on the outside, will my "fixup protocol ftp 21" work when I try to connect from the outside client to the inside server? Will the PIX open up necessary ports for me to have a successful ftp connection?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Mo&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:21:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-fixup-direction/m-p/420546#M533896</guid>
      <dc:creator>m.mohanasundaram</dc:creator>
      <dc:date>2020-02-21T08:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: PIX fixup direction</title>
      <link>https://community.cisco.com/t5/network-security/pix-fixup-direction/m-p/420547#M533898</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes, please see its manner in two scenarios for inbound traffic when a client wants to initiate ftp connection (passive/active) to a server from outside to inside:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Standard FTP&lt;/P&gt;&lt;P&gt;1. if a access-list/conduit exists to allow ftp traffic from outbound to inbound (ftp server) and if outbound traffic explicitly allowed , there isn't any handeling because the data channel is open from server to client.&lt;/P&gt;&lt;P&gt;2. if a access-list/conduit exists to allow ftp traffic from outbound to inbound (ftp server) and if outbound traffic isn't explicitly allowed , then the PIX opens access to outbound temporary and it will closed after the ftp data is sent from server to client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Passive FTP&lt;/P&gt;&lt;P&gt;if a access-list/conduit exists allowing inbound FTP control connections to a Passive FTP server and the PIX opens a temporary inbound acl for the data channel initiated by the client. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in fact if ftp fixup is disabled then &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Inbound standard FTP will work properly if a access-list/conduit to the inside server exists.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Inbound passive FTP will not work properly because the client should be initiate to server on a port that server specified for data channel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mehrdad Arshad Rad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Aug 2005 04:28:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-fixup-direction/m-p/420547#M533898</guid>
      <dc:creator>mehrdad</dc:creator>
      <dc:date>2005-08-25T04:28:09Z</dc:date>
    </item>
  </channel>
</rss>

