<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTP not working thru PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftp-not-working-thru-pix/m-p/221641#M610254</link>
    <description>&lt;P&gt;Trying to FTP from inside to outside. It works with nat 0 but when I use a static mapping from a.b.c.148(inside address) to a.b.c.120(outside address) it will not work. They are in different subnets. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PIX seems to just ignore the packet. There is no error message or denies!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol ftp strict 21  (also tried with fixup protocol ftp 21)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 192.1.3.32 netmask 255.255.255.224&lt;/P&gt;&lt;P&gt;nat (inside) 0 192.1.3.128 255.255.255.224 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.1.3.117 Workstation1 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.1.3.118 Workstation2 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.1.3.119 Workstation3 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.1.3.120 Workstation4 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Connections to external ftp server (SYN timeout)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;106100: access-list from-noc-lan permitted tcp inside/192.1.3.148(1531) -&amp;gt; outsi&lt;/P&gt;&lt;P&gt;de/199.1.1.200(21) hit-cnt 1 (first hit)&lt;/P&gt;&lt;P&gt;302013: Built outbound TCP connection 7595411 for outside:199.1.1.200/21 (199.1.&lt;/P&gt;&lt;P&gt;1.200/21) to inside:192.1.3.148/1531 (192.1.3.120/1531)&lt;/P&gt;&lt;P&gt;710005: UDP request discarded from 192.1.3.135/138 to inside:192.1.3.159/netbios&lt;/P&gt;&lt;P&gt;-dgm&lt;/P&gt;&lt;P&gt;302014: Teardown TCP connection 7595409 for outside:199.1.1.200/21 to inside:192&lt;/P&gt;&lt;P&gt;.1.3.148/1530 duration 0:02:01 bytes 0 SYN Timeout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 07:09:40 GMT</pubDate>
    <dc:creator>jkampmeyer</dc:creator>
    <dc:date>2020-02-21T07:09:40Z</dc:date>
    <item>
      <title>FTP not working thru PIX</title>
      <link>https://community.cisco.com/t5/network-security/ftp-not-working-thru-pix/m-p/221641#M610254</link>
      <description>&lt;P&gt;Trying to FTP from inside to outside. It works with nat 0 but when I use a static mapping from a.b.c.148(inside address) to a.b.c.120(outside address) it will not work. They are in different subnets. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PIX seems to just ignore the packet. There is no error message or denies!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol ftp strict 21  (also tried with fixup protocol ftp 21)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 192.1.3.32 netmask 255.255.255.224&lt;/P&gt;&lt;P&gt;nat (inside) 0 192.1.3.128 255.255.255.224 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.1.3.117 Workstation1 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.1.3.118 Workstation2 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.1.3.119 Workstation3 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.1.3.120 Workstation4 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Connections to external ftp server (SYN timeout)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;106100: access-list from-noc-lan permitted tcp inside/192.1.3.148(1531) -&amp;gt; outsi&lt;/P&gt;&lt;P&gt;de/199.1.1.200(21) hit-cnt 1 (first hit)&lt;/P&gt;&lt;P&gt;302013: Built outbound TCP connection 7595411 for outside:199.1.1.200/21 (199.1.&lt;/P&gt;&lt;P&gt;1.200/21) to inside:192.1.3.148/1531 (192.1.3.120/1531)&lt;/P&gt;&lt;P&gt;710005: UDP request discarded from 192.1.3.135/138 to inside:192.1.3.159/netbios&lt;/P&gt;&lt;P&gt;-dgm&lt;/P&gt;&lt;P&gt;302014: Teardown TCP connection 7595409 for outside:199.1.1.200/21 to inside:192&lt;/P&gt;&lt;P&gt;.1.3.148/1530 duration 0:02:01 bytes 0 SYN Timeout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:09:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-not-working-thru-pix/m-p/221641#M610254</guid>
      <dc:creator>jkampmeyer</dc:creator>
      <dc:date>2020-02-21T07:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: FTP not working thru PIX</title>
      <link>https://community.cisco.com/t5/network-security/ftp-not-working-thru-pix/m-p/221642#M610255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do a "show xlate local ip-workstation". You might need to execute a clear xlate for your inside hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I'm missing the reason why you use a "global (outside) 1...". Do you also use have a "nat (inside) 1..." ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally, what was the log looked before you use a static maping?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Dec 2003 18:59:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-not-working-thru-pix/m-p/221642#M610255</guid>
      <dc:creator>mpalardy</dc:creator>
      <dc:date>2003-12-18T18:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: FTP not working thru PIX</title>
      <link>https://community.cisco.com/t5/network-security/ftp-not-working-thru-pix/m-p/221643#M610256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the same problem. I tried adding service resetinbound and established permitto 113 as cisco's docs suggested.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Dec 2003 20:32:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftp-not-working-thru-pix/m-p/221643#M610256</guid>
      <dc:creator>sbosen67</dc:creator>
      <dc:date>2003-12-29T20:32:54Z</dc:date>
    </item>
  </channel>
</rss>

