<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active ftp, ASA 5510 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/active-ftp-asa-5510/m-p/1544311#M606409</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have an inside host trying to establish an FTP session to an outside server correct?&lt;/P&gt;&lt;P&gt;If so... the ACL applied to the inside interface should permit outgoing FTP traffic and the response should be allowed by the FTP inspection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If using Active FTP, the control channel is established from the client, but the data channel comes from the server (and this will be allowed by inspecting FTP).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;If using Passive FTP it works?&lt;/P&gt;&lt;P&gt;Can you PING or access the same server via another service (http, telnet, etc)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 Nov 2010 19:09:30 GMT</pubDate>
    <dc:creator>Federico Coto Fajardo</dc:creator>
    <dc:date>2010-11-18T19:09:30Z</dc:date>
    <item>
      <title>Active ftp, ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-asa-5510/m-p/1544310#M606404</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having some trouble setting up an active ftp session from inside to outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've read the other topics on the forums, but i can't figure it out myself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created some acl's and port forwards, i also configured the inspect FTP in the global policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've attached the running config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've someone has a solution, please inform me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bert&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:11:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-asa-5510/m-p/1544310#M606404</guid>
      <dc:creator>Bert Kelchtermans</dc:creator>
      <dc:date>2019-03-11T19:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: Active ftp, ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-asa-5510/m-p/1544311#M606409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have an inside host trying to establish an FTP session to an outside server correct?&lt;/P&gt;&lt;P&gt;If so... the ACL applied to the inside interface should permit outgoing FTP traffic and the response should be allowed by the FTP inspection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If using Active FTP, the control channel is established from the client, but the data channel comes from the server (and this will be allowed by inspecting FTP).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;If using Passive FTP it works?&lt;/P&gt;&lt;P&gt;Can you PING or access the same server via another service (http, telnet, etc)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Nov 2010 19:09:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-asa-5510/m-p/1544311#M606409</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-11-18T19:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: Active ftp, ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-asa-5510/m-p/1544312#M606413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Frederico&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, we can reach the ftp server via telnet, and passive ftp also works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is the data coming from the server to port 20.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I you have any iea please let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Nov 2010 08:09:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-asa-5510/m-p/1544312#M606413</guid>
      <dc:creator>Bert Kelchtermans</dc:creator>
      <dc:date>2010-11-19T08:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: Active ftp, ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-asa-5510/m-p/1544313#M606416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please post the output of "show service-policy". Also, when you try the acive FTP, what are the syslogs you notice on the ASA? Please post debugs in debugging level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Nov 2010 05:27:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-asa-5510/m-p/1544313#M606416</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-11-20T05:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Active ftp, ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-asa-5510/m-p/1544314#M606417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not sure what this below section is doing in the config.&amp;nbsp; I'd remove it.&lt;BR /&gt;&lt;SPAN style="color: #3366ff;"&gt; class class-default&lt;BR /&gt;&amp;nbsp; set connection advanced-options tcp-state-bypass&lt;BR /&gt;&amp;nbsp; inspect ftp &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt;class class-default&lt;BR /&gt; no&amp;nbsp; set connection advanced-options tcp-state-bypass&lt;BR /&gt;&amp;nbsp; no&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;no class class-default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try the flow again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Nov 2010 17:36:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-asa-5510/m-p/1544314#M606417</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-11-20T17:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: Active ftp, ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-asa-5510/m-p/1544315#M606418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the responses, I will try your suggestions in the comming week&lt;/P&gt;&lt;P&gt;and post the 'show service-policy" as soon as possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Nov 2010 17:41:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-asa-5510/m-p/1544315#M606418</guid>
      <dc:creator>Bert Kelchtermans</dc:creator>
      <dc:date>2010-11-20T17:41:18Z</dc:date>
    </item>
    <item>
      <title>Re: Active ftp, ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-asa-5510/m-p/1544316#M606420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bert,&lt;/P&gt;&lt;P&gt;client--ASA--internet--active ftp server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason why active ftp fails is because the data connection is initiated from source port 20 as a brand new connection from the server on the outside - which is on the lower security interface.&amp;nbsp; When the acl applied on the outside does not allow tcp port 20 from the server to your client this will fail because ftp inspection is supposed to open that tcp port 20 coming from the server.&lt;/P&gt;&lt;P&gt;In your case you have some tcp-state-bypass configured which means tcp flow will be like udp flow and not inspected for ftp.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason why passive ftp works is because the client on the higher security interface opens up a brand new connection to the server to get the data and by default connections going from high to low security is allowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;once you remove the tcp-state-bypass lines from the config. Issue a clear local for the client ip. Then try to get the output of this sh service-policy command below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;clear local x.x.x.x&lt;/P&gt;&lt;P&gt;sh service-policy flow tcp host x.x.x.x host y.y.y.y eq 21&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where x.x.x.x is the IP of the inside client and y.y.y.y is the IP address of the ftp server on the outside. Make sure the output shows that it will hit the ftp inspection.&amp;nbsp; Then try the flow again. It should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Nov 2010 17:54:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-asa-5510/m-p/1544316#M606420</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-11-20T17:54:33Z</dc:date>
    </item>
  </channel>
</rss>

