<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTP connection problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftp-connection-problem/m-p/1668824#M556857</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of our companies customer has ran into problems with a software that transfers files with FTP. The situation is as follows&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The customers DSL connection was before the start of the week going trough very old firewall equipment (PIX525 running old software) and it was at the start of the week that we moved the connection behind a new ASA 5585-X (8.4(1)) firewall in multiple context mode. The actual DSL connection is a L2 connection straight to the Firewall inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After this the customer hasnt been able to use his software which automatically connects to different banks with FTP and transfers files. So this is not a normal FTP Client but a software that in itself uses FTP for the file transfers. It seems to use active FTP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured the "inspect ftp" to the customer context. I have also made sure all access-list permits all the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the customer uses the software and initiates the connection I can see the control port connection going up (Flags UOI) but I cant see the data connection forming. I can see the TCP/20 connection with "show conn" but it doesnt seem to be going UP. Also what confuses me is that I can see a TCP connection with the port TCP/0 on the firewall sometimes?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The customer has a private IP address range in the LAN and only PAT translation to outside IP for all users. NAT is configured as show below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network PAT-X-X-X-X&lt;BR /&gt; subnet x.x.x.x y.y.y.y&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ive though about testing the FTP connection by routing an additional IP towards the customers security context and assinging it to the users local IP and test the connection that way. Im not totally sure if it will help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see no form of logg messages for these FTP connections that would tell me what the actual problem is. Also its pretty confusing that the connection sometimes goes trough and sometimes just hangs. Im wondering if the problem is because of the actual software as its not just a standard FTP Client software only. Also im wondering what could be the difference in replacing the PIX with the ASA. The setup regaring firewall configurations was pretty much the same in the old PIX also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've already configured packet capture on the firewall context and waiting for them to test the actual connections at some point. Probably next week.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have any ideas why the FTP connections are failing at the moment after the firewall change?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feel free to ask if I missed some crucial information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:27:05 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2019-03-11T20:27:05Z</dc:date>
    <item>
      <title>FTP connection problem</title>
      <link>https://community.cisco.com/t5/network-security/ftp-connection-problem/m-p/1668824#M556857</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of our companies customer has ran into problems with a software that transfers files with FTP. The situation is as follows&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The customers DSL connection was before the start of the week going trough very old firewall equipment (PIX525 running old software) and it was at the start of the week that we moved the connection behind a new ASA 5585-X (8.4(1)) firewall in multiple context mode. The actual DSL connection is a L2 connection straight to the Firewall inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After this the customer hasnt been able to use his software which automatically connects to different banks with FTP and transfers files. So this is not a normal FTP Client but a software that in itself uses FTP for the file transfers. It seems to use active FTP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured the "inspect ftp" to the customer context. I have also made sure all access-list permits all the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the customer uses the software and initiates the connection I can see the control port connection going up (Flags UOI) but I cant see the data connection forming. I can see the TCP/20 connection with "show conn" but it doesnt seem to be going UP. Also what confuses me is that I can see a TCP connection with the port TCP/0 on the firewall sometimes?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The customer has a private IP address range in the LAN and only PAT translation to outside IP for all users. NAT is configured as show below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network PAT-X-X-X-X&lt;BR /&gt; subnet x.x.x.x y.y.y.y&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ive though about testing the FTP connection by routing an additional IP towards the customers security context and assinging it to the users local IP and test the connection that way. Im not totally sure if it will help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see no form of logg messages for these FTP connections that would tell me what the actual problem is. Also its pretty confusing that the connection sometimes goes trough and sometimes just hangs. Im wondering if the problem is because of the actual software as its not just a standard FTP Client software only. Also im wondering what could be the difference in replacing the PIX with the ASA. The setup regaring firewall configurations was pretty much the same in the old PIX also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've already configured packet capture on the firewall context and waiting for them to test the actual connections at some point. Probably next week.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have any ideas why the FTP connections are failing at the moment after the firewall change?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feel free to ask if I missed some crucial information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:27:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-connection-problem/m-p/1668824#M556857</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2019-03-11T20:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: FTP connection problem</title>
      <link>https://community.cisco.com/t5/network-security/ftp-connection-problem/m-p/1668825#M556859</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have done your homework. What we need at this point is that packet capture. What are the flags on the port 20 that you saw? It would be crucial to have that packet capture to see what is going on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike Rojas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Apr 2011 16:46:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-connection-problem/m-p/1668825#M556859</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-04-29T16:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: FTP connection problem</title>
      <link>https://community.cisco.com/t5/network-security/ftp-connection-problem/m-p/1668826#M556861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a known issue with 8.4.1 and the 5585 and 5580 platforms and ACTIVE FTP. The bug is CSCto09465 and it is first fixed in 8.4.1.8. Please open a TAC case to get this version of code published to you. &lt;/P&gt;&lt;P&gt;Posted from my mobile device.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 30 Apr 2011 22:38:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-connection-problem/m-p/1668826#M556861</guid>
      <dc:creator>Magnus Mortensen</dc:creator>
      <dc:date>2011-04-30T22:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: FTP connection problem</title>
      <link>https://community.cisco.com/t5/network-security/ftp-connection-problem/m-p/1668827#M556863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Big thank you for the response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will get in contact with our Cisco contacts at the start of the week to get the software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 May 2011 00:43:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-connection-problem/m-p/1668827#M556863</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2011-05-01T00:43:31Z</dc:date>
    </item>
  </channel>
</rss>

