<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix Firewall and passive FTP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-firewall-and-passive-ftp/m-p/92325#M623899</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, I haven't tried the range of ports.  Just 21.  I'll do that and see what happens.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have found out some other information.  In going through my logs I have this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;8:08:02am  %PIX-6-302001:  Built outbound TCP connection xxxxxx for faddr a.b.c.d/80 gaddr &lt;EXTERNAL static="" ip="" of="" system="" in="" question=""&gt;&lt;/EXTERNAL&gt;&lt;/P&gt;&lt;P&gt;8:08:02am  %PIX-5-304001:  &lt;INSIDE ip="" address=""&gt; Accessed URL a.b.c.d:/filename.cab&lt;/INSIDE&gt;&lt;/P&gt;&lt;P&gt;8:08:02am  %PIX-6-302002: Teardown TCP connection xxxxx faddr a.b.c.d/80 gaddr &lt;EXTERNAL statc="" ip="" of="" system="" in="" question=""&gt;&lt;/EXTERNAL&gt;&lt;/P&gt;&lt;P&gt;8:08:02am  %PIX-5-106015:  Deny TCP (no connection) from a.b.c.d/80 to &lt;INSIDE ip="" address=""&gt; flags PSH ACK&lt;/INSIDE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like the PIX tears down the connection before I'm finished.  Any reason why?  Is there a timeout issue going on?  This has been working for a few months now.  I had to turn off our PIX's to move them to a new location, and then brought them back up.  The contents of the memory were saved.  I'm having the hardest time trying to figure this out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Sep 2002 19:30:09 GMT</pubDate>
    <dc:creator>apaxson</dc:creator>
    <dc:date>2002-09-06T19:30:09Z</dc:date>
    <item>
      <title>Pix Firewall and passive FTP</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-and-passive-ftp/m-p/92322#M623896</link>
      <description>&lt;P&gt;How can I use passive FTP through the Pix Firewall??  I've tried everything to get this to work.  I've tried using established commands.  I've tried using conduit commands enabling all the high ports back to the originating host (1024-65535).  Nothing is working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, once I do "no fixup protocol ftp" it works just fine.  However, our other FTP operations fail when I do this.  Is there any way I can get these two functions to work through our PIX?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Huge thanks in advance.  My company is very dependant on these services.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Aaron Paxson&lt;/P&gt;&lt;P&gt;IT Systems Analyst &lt;/P&gt;&lt;P&gt;Decorative Concepts&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:13:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-and-passive-ftp/m-p/92322#M623896</guid>
      <dc:creator>apaxson</dc:creator>
      <dc:date>2020-02-21T06:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: Pix Firewall and passive FTP</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-and-passive-ftp/m-p/92323#M623897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyone have any ideas??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Sep 2002 15:28:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-and-passive-ftp/m-p/92323#M623897</guid>
      <dc:creator>apaxson</dc:creator>
      <dc:date>2002-09-06T15:28:17Z</dc:date>
    </item>
    <item>
      <title>Re: Pix Firewall and passive FTP</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-and-passive-ftp/m-p/92324#M623898</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, have you tried a range of ports for fixup to inspect?  Something like......&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21-65535&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure if this will inspect all traffic leaving on those ports though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone else?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Sep 2002 17:47:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-and-passive-ftp/m-p/92324#M623898</guid>
      <dc:creator>mike-greene</dc:creator>
      <dc:date>2002-09-06T17:47:16Z</dc:date>
    </item>
    <item>
      <title>Re: Pix Firewall and passive FTP</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-and-passive-ftp/m-p/92325#M623899</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, I haven't tried the range of ports.  Just 21.  I'll do that and see what happens.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have found out some other information.  In going through my logs I have this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;8:08:02am  %PIX-6-302001:  Built outbound TCP connection xxxxxx for faddr a.b.c.d/80 gaddr &lt;EXTERNAL static="" ip="" of="" system="" in="" question=""&gt;&lt;/EXTERNAL&gt;&lt;/P&gt;&lt;P&gt;8:08:02am  %PIX-5-304001:  &lt;INSIDE ip="" address=""&gt; Accessed URL a.b.c.d:/filename.cab&lt;/INSIDE&gt;&lt;/P&gt;&lt;P&gt;8:08:02am  %PIX-6-302002: Teardown TCP connection xxxxx faddr a.b.c.d/80 gaddr &lt;EXTERNAL statc="" ip="" of="" system="" in="" question=""&gt;&lt;/EXTERNAL&gt;&lt;/P&gt;&lt;P&gt;8:08:02am  %PIX-5-106015:  Deny TCP (no connection) from a.b.c.d/80 to &lt;INSIDE ip="" address=""&gt; flags PSH ACK&lt;/INSIDE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like the PIX tears down the connection before I'm finished.  Any reason why?  Is there a timeout issue going on?  This has been working for a few months now.  I had to turn off our PIX's to move them to a new location, and then brought them back up.  The contents of the memory were saved.  I'm having the hardest time trying to figure this out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Sep 2002 19:30:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-and-passive-ftp/m-p/92325#M623899</guid>
      <dc:creator>apaxson</dc:creator>
      <dc:date>2002-09-06T19:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: Pix Firewall and passive FTP</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-and-passive-ftp/m-p/92326#M623900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you do  the no ftp fixup ptotocol, you are disabling the ftp server to open the ftp data connection to the client to establish the data connections. If you want both port mode and passive mode to work at the same time. add an access list that specifically allow the ftp servers to open data connection from port 21 to the clients, good luck.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Sep 2002 06:07:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-and-passive-ftp/m-p/92326#M623900</guid>
      <dc:creator>6a.araishy</dc:creator>
      <dc:date>2002-09-08T06:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: Pix Firewall and passive FTP</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-and-passive-ftp/m-p/92327#M623901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much for your response!  That makes alot of sense.  Would I also use a conduit command opening up the port back through the firewall, or would I just need an access-list?  I have one access-list applied to my inside interface, and use conduit commands to come back through the firewall into my private network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the response!&lt;/P&gt;&lt;P&gt;Aaron&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Sep 2002 16:30:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-and-passive-ftp/m-p/92327#M623901</guid>
      <dc:creator>apaxson</dc:creator>
      <dc:date>2002-09-09T16:30:40Z</dc:date>
    </item>
  </channel>
</rss>

