<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Active FTP NOT WORKING in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/active-ftp-not-working/m-p/1568487#M612069</link>
    <description>&lt;P&gt;Hello experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a 5520 and PASV FTP is working fine but ACTIVE FTP is not. I have enabled ftp inspection and I am actually seeing resets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt; Service-policy: global_policy&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: ESMTP-POLICY&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: esmtp _default_esmtp_map, packet 0, drop 0, reset-drop 0&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: inspection_default&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: dns preset_dns_map, packet 1307204594, drop 5704127, reset-drop 0&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: ftp, packet 4004288, drop 0, reset-drop 45&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;In the capture that I did in the OUTSIDE interface&amp;nbsp; I am seeing NO &lt;/STRONG&gt;&lt;STRONG&gt;problems with control channel however with the data channel Iam seeing problems. The Server tries to connect using port 20 to the client however in the next packet there is a reset from the ASA to the ftp server.&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;In the inside capture the packet from the server on port 20 to the client is never seeing so it's the ASA.&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;I have a ZBF in the inside however like I said the request from the server on port 20 to the client on port X&amp;nbsp; is never seeing in the capture.&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;Why whould the FTP INSPECTION reset the connection?&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;Im not using any regex to reset connections or something similar that could be causing this behavior.&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;Please help.&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 18:37:17 GMT</pubDate>
    <dc:creator>Diego Armando Cambronero Arias</dc:creator>
    <dc:date>2019-03-11T18:37:17Z</dc:date>
    <item>
      <title>Active FTP NOT WORKING</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-not-working/m-p/1568487#M612069</link>
      <description>&lt;P&gt;Hello experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a 5520 and PASV FTP is working fine but ACTIVE FTP is not. I have enabled ftp inspection and I am actually seeing resets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt; Service-policy: global_policy&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: ESMTP-POLICY&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: esmtp _default_esmtp_map, packet 0, drop 0, reset-drop 0&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: inspection_default&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: dns preset_dns_map, packet 1307204594, drop 5704127, reset-drop 0&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: ftp, packet 4004288, drop 0, reset-drop 45&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;In the capture that I did in the OUTSIDE interface&amp;nbsp; I am seeing NO &lt;/STRONG&gt;&lt;STRONG&gt;problems with control channel however with the data channel Iam seeing problems. The Server tries to connect using port 20 to the client however in the next packet there is a reset from the ASA to the ftp server.&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;In the inside capture the packet from the server on port 20 to the client is never seeing so it's the ASA.&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;I have a ZBF in the inside however like I said the request from the server on port 20 to the client on port X&amp;nbsp; is never seeing in the capture.&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;Why whould the FTP INSPECTION reset the connection?&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;Im not using any regex to reset connections or something similar that could be causing this behavior.&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;/P&gt;&lt;P class="ecxMsoNormal"&gt;&lt;STRONG&gt;Please help.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:37:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-not-working/m-p/1568487#M612069</guid>
      <dc:creator>Diego Armando Cambronero Arias</dc:creator>
      <dc:date>2019-03-11T18:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: Active FTP NOT WORKING</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-not-working/m-p/1568488#M612070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Diego,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you get simultaneous captures on either side of the ASA for a full FTP session? Also, you'll want to gather syslogs at the debug level during the FTP session.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Sep 2010 20:51:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-not-working/m-p/1568488#M612070</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2010-09-08T20:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: Active FTP NOT WORKING</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-not-working/m-p/1568489#M612071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok I will get the logs I will keep you posted.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Sep 2010 20:59:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-not-working/m-p/1568489#M612071</guid>
      <dc:creator>Diego Armando Cambronero Arias</dc:creator>
      <dc:date>2010-09-08T20:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: Active FTP NOT WORKING</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-not-working/m-p/1568490#M612072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What code are you running mate?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You might want to enable debugging for ftp inspection - I *think* that this is debug ftp? (sorry I don't have a unit to hand), then check the logs, the ftp client might not be conforming to the RFC.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;BTW - this is a total stab in the dark! And I've just seen that I pretty much written what Mike said above. Give that man some points &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Sep 2010 22:11:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-not-working/m-p/1568490#M612072</guid>
      <dc:creator>golly_wog</dc:creator>
      <dc:date>2010-09-08T22:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: Active FTP NOT WORKING</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-not-working/m-p/1568491#M612073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From your description, it seems like the server is on the outside and the&lt;/P&gt;&lt;P&gt;client is on the inside. Do you have one-to-one NAT mapping for the client?&lt;/P&gt;&lt;P&gt;If it is not there, can you configure one-to-one static (IP-to-IP) and see&lt;/P&gt;&lt;P&gt;if the active FTP works? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Sep 2010 23:04:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-not-working/m-p/1568491#M612073</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-09-08T23:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: Active FTP NOT WORKING</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-not-working/m-p/1568492#M612074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok I will try with a one2one static to see wath happens.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Sep 2010 15:55:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-not-working/m-p/1568492#M612074</guid>
      <dc:creator>Diego Armando Cambronero Arias</dc:creator>
      <dc:date>2010-09-09T15:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: Active FTP NOT WORKING</title>
      <link>https://community.cisco.com/t5/network-security/active-ftp-not-working/m-p/1568493#M612075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;tomorrow I will be able to do more troubleshooting thank u.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Sep 2010 15:57:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-ftp-not-working/m-p/1568493#M612075</guid>
      <dc:creator>Diego Armando Cambronero Arias</dc:creator>
      <dc:date>2010-09-09T15:57:32Z</dc:date>
    </item>
  </channel>
</rss>

