<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Secure FTP through PIX and VPN L2L in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/secure-ftp-through-pix-and-vpn-l2l/m-p/1729044#M537037</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jose, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Over the tunnel I dont think there is any problem, you see, the issue comes when opening the data channel in order to pass the file, since the inpsection on the ASA (That works looking at the payload on port 21)&amp;nbsp; does not see what port is going to be used nor the IPs involed, he wont open the data channel. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But on a VPN tunnel (under normal circunstances) you have permit ip any any for the interesting traffic, meaning all IP traffic is going to pass across it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I am trying to say is that, for traffic flowing from inside to outside with no VPN on it, it should failed (as documented), over the tunnel, I dont see why would it failed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am starting thinking that the problem can be related to the interesting traffic define on the Tunnel itself. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 Jun 2011 17:12:35 GMT</pubDate>
    <dc:creator>Maykol Rojas</dc:creator>
    <dc:date>2011-06-28T17:12:35Z</dc:date>
    <item>
      <title>Secure FTP through PIX and VPN L2L</title>
      <link>https://community.cisco.com/t5/network-security/secure-ftp-through-pix-and-vpn-l2l/m-p/1729043#M537036</link>
      <description>&lt;P&gt;Hi everybody,&amp;nbsp; I have this need from a customer. They have multiple VPN L2L connections with multiple offices (the configuration is a mess) but the issue is:&amp;nbsp; One of the Sites needs to use SFTP to transfer file from that branch office to the main office. They use a software like FileZilla acting like the SFTP.&amp;nbsp; When they transfer the files using FTP the tunnel goes up and the transfer is successfull. But when they try to use SFTP not even the authentication happens, and the VPN tunnel does not go up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been reading the post about SFTP and some say it works some other said it does not. I read at Cisco documentation and they say it is not possible becasuse the SSH encryption. Please somebody clarify if the use of SFTP is possible through a PIX firewall or an ASA firewall and what consideration should I have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jose&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:52:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/secure-ftp-through-pix-and-vpn-l2l/m-p/1729043#M537036</guid>
      <dc:creator>jose cortes</dc:creator>
      <dc:date>2019-03-11T20:52:12Z</dc:date>
    </item>
    <item>
      <title>Secure FTP through PIX and VPN L2L</title>
      <link>https://community.cisco.com/t5/network-security/secure-ftp-through-pix-and-vpn-l2l/m-p/1729044#M537037</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jose, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Over the tunnel I dont think there is any problem, you see, the issue comes when opening the data channel in order to pass the file, since the inpsection on the ASA (That works looking at the payload on port 21)&amp;nbsp; does not see what port is going to be used nor the IPs involed, he wont open the data channel. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But on a VPN tunnel (under normal circunstances) you have permit ip any any for the interesting traffic, meaning all IP traffic is going to pass across it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I am trying to say is that, for traffic flowing from inside to outside with no VPN on it, it should failed (as documented), over the tunnel, I dont see why would it failed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am starting thinking that the problem can be related to the interesting traffic define on the Tunnel itself. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2011 17:12:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/secure-ftp-through-pix-and-vpn-l2l/m-p/1729044#M537037</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-06-28T17:12:35Z</dc:date>
    </item>
    <item>
      <title>Secure FTP through PIX and VPN L2L</title>
      <link>https://community.cisco.com/t5/network-security/secure-ftp-through-pix-and-vpn-l2l/m-p/1729045#M537038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mykol,&amp;nbsp; But, when I try to do a FTP transfer the tunnel works... that's why I though the problem is the SSH encryption. As you said the interesting traffic is allowed by a "permit any" rule. So I cannot figure out what else could be failing but the 'S' at SFTP.&amp;nbsp; Regards,&amp;nbsp; Jose&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2011 17:28:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/secure-ftp-through-pix-and-vpn-l2l/m-p/1729045#M537038</guid>
      <dc:creator>jose cortes</dc:creator>
      <dc:date>2011-06-28T17:28:34Z</dc:date>
    </item>
    <item>
      <title>Secure FTP through PIX and VPN L2L</title>
      <link>https://community.cisco.com/t5/network-security/secure-ftp-through-pix-and-vpn-l2l/m-p/1729046#M537039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the pix, would you please do the following? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input inside tcp &lt;INSIDE_HOST_IP&gt; 1025 &lt;SFTP_SERVER&gt; 22 &lt;/SFTP_SERVER&gt;&lt;/INSIDE_HOST_IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2011 17:38:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/secure-ftp-through-pix-and-vpn-l2l/m-p/1729046#M537039</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-06-28T17:38:23Z</dc:date>
    </item>
  </channel>
</rss>

