<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: passive FTP doesn't work with CBAC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499157#M632400</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;KS, you da man!&amp;nbsp; Adding that line worked! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not a big deal if you don't &lt;SPAN style="background-color: #f8fafd;"&gt;know or don't have time but, why?&amp;nbsp; All the docs that I have read on CBAC show applying the inspect in one direction only. So why do I need to add it in the "in" direction?&amp;nbsp; Do I need the "out"?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Diego&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 07 Aug 2010 13:56:02 GMT</pubDate>
    <dc:creator>tato386</dc:creator>
    <dc:date>2010-08-07T13:56:02Z</dc:date>
    <item>
      <title>passive FTP doesn't work with CBAC</title>
      <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499137#M632372</link>
      <description>&lt;P&gt;I have setup an inbound ACL on the outside interface&amp;nbsp; of my router that allows TCP ports 20 and 21 in and I have a CBAC inspect map with FTP specified on the same interface in an outbound direction.&amp;nbsp; My understanding is that the inspect will check all outbound traffic and dynamically fix the inbound ACL for the client/serve negotiated ports.&amp;nbsp; I have active FTP clients like the command line Windows ftp work, but passive clients like a browser do not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I uncheck passive mode on my browser it works further confirming that active FTP works.&amp;nbsp; Ironically, the browser active/passive option says that passive mode is for firewall compatibility!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas on this?&amp;nbsp; I would really like both to work because I frequently use the command line ftp and most others prefer the browser.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Diego &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:21:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499137#M632372</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2019-03-11T18:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: passive FTP doesn't work with CBAC</title>
      <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499138#M632373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi diego&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where is the client and where is the server, i mean with respect to firewall which is on inside and which is on internet&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 13:29:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499138#M632373</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-08-05T13:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: passive FTP doesn't work with CBAC</title>
      <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499139#M632374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ftp server is behind the firewall on the private and protected network.&amp;nbsp; Clients are hitting the ftp server from the public Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Diego&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 14:34:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499139#M632374</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2010-08-05T14:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: passive FTP doesn't work with CBAC</title>
      <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499140#M632375</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if your active connection are working and passive are not working i can think of only one thing and that is inspect ftp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please make sure that inspect ftp is before inspect tcp other inspect ftp will never work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so this is how it should be&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip inspect name FW ftp&lt;/P&gt;&lt;P&gt;ip inspect name FW tcp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but not the other way&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 14:48:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499140#M632375</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-08-05T14:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: passive FTP doesn't work with CBAC</title>
      <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499141#M632377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately, I d&lt;SPAN style="background-color: #f8fafd;"&gt;o have the ftp inspect first.&amp;nbsp; Here is what I have:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip inspect name firewall dns&lt;BR /&gt;ip inspect name firewall ftp&lt;BR /&gt;ip inspect name firewall tftp&lt;BR /&gt;ip inspect name firewall https&lt;BR /&gt;ip inspect name firewall icmp&lt;BR /&gt;ip inspect name firewall imap&lt;BR /&gt;ip inspect name firewall pop3&lt;BR /&gt;ip inspect name firewall realaudio&lt;BR /&gt;ip inspect name firewall rtsp&lt;BR /&gt;ip inspect name firewall esmtp&lt;BR /&gt;ip inspect name firewall tcp&lt;BR /&gt;ip inspect name firewall udp&lt;BR /&gt;ip inspect name firewall skinny&lt;BR /&gt;ip inspect name firewall sip&lt;/P&gt;&lt;P&gt;I took some packet debugs and I can see where the packet is denied when the client begins sending to the negotiated high port.&amp;nbsp; In the debug when the client sends to the servers TCP port 16787 the packet is denied.&amp;nbsp; So it seems like CBAC is not dynamically openning the negotiated ports as it should.&amp;nbsp; I have attached the packet debug if you care to look at it.&amp;nbsp; Maybe I will open a case with the TAC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Diego&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 15:23:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499141#M632377</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2010-08-05T15:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: passive FTP doesn't work with CBAC</title>
      <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499142#M632379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;please put this command and see the logs and paste them here&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip inspect log drop-packet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also just to confirm taht it is the firewall remove the access-group from the outside interafce so taht you permit everything inside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 15:40:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499142#M632379</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-08-05T15:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: passive FTP doesn't work with CBAC</title>
      <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499143#M632381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ip inspect log drop-pkt does not show any packets being dropped. However wh&lt;SPAN style="background-color: #f8fafd;"&gt;en I removed the ACL it worked like a champ.&amp;nbsp; So we know it is the ACL but I don't think it is a good idea to open up all the high ports.&amp;nbsp; It just seems that CBAC is not opening up the ports as it should.&amp;nbsp; I would think maybe a bug but I am running a fairly up to date IOS of 12.4(20)T4.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Any ideas?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Diego&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 16:57:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499143#M632381</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2010-08-05T16:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: passive FTP doesn't work with CBAC</title>
      <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499144#M632382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you share with us your interfaces (inside/outside) config, also ACL and cbac config, if you agreed with this, please use examples IP address on your post.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 17:40:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499144#M632382</guid>
      <dc:creator>e.pedersen</dc:creator>
      <dc:date>2010-08-05T17:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: passive FTP doesn't work with CBAC</title>
      <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499145#M632384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the ACL and interface config.&amp;nbsp; Also the packet debug of the failure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;diego&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 18:32:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499145#M632384</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2010-08-05T18:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: passive FTP doesn't work with CBAC</title>
      <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499146#M632386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i know you have already done this and some of my below steps might sound very stupid... but try them they have worked for me&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;try one more small thing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;open only port 20 with your access-list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this should allow passive ftp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if this works then it is the inspection thats not working&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;trying removing inspection ftp and reapplying&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 18:34:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499146#M632386</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-08-05T18:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: passive FTP doesn't work with CBAC</title>
      <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499147#M632388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure I follow you here.&amp;nbsp; I have currently have both 20 and 21 open.&amp;nbsp; &lt;SPAN style="background-color: #f8fafd;"&gt;Active is working and passive is not.&amp;nbsp; So you want me to remove 21 and recheck passive?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I will also try removing and reapplyting the inspect command.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Diego&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 18:39:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499147#M632388</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2010-08-05T18:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: passive FTP doesn't work with CBAC</title>
      <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499148#M632389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just for testing pursoses. Have you tried to open all IP traffic for that server. Just do it, try it and then close all IP. If it works then we know the problem is with the FTP Inspection. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 21:26:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499148#M632389</guid>
      <dc:creator>Diego Armando Cambronero Arias</dc:creator>
      <dc:date>2010-08-05T21:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: passive FTP doesn't work with CBAC</title>
      <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499149#M632390</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Diego,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have tried that and it works OK.&amp;nbsp; At this point I am well satisfied that it is the inspection.&amp;nbsp; Now I need to find out if I am doing something wrong, or maybe missing something or maybe just a bug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your input.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Diego&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 21:39:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499149#M632390</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2010-08-05T21:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: passive FTP doesn't work with CBAC</title>
      <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499150#M632392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Diego,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All CBAC is a Bug. Change to ZOne-Based that is easier to manage and do a better work&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 21:56:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499150#M632392</guid>
      <dc:creator>Diego Armando Cambronero Arias</dc:creator>
      <dc:date>2010-08-05T21:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: passive FTP doesn't work with CBAC</title>
      <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499151#M632394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Never heard of zone-based.&amp;nbsp; Is that available on IOS routers?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;diego&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Aug 2010 03:31:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499151#M632394</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2010-08-06T03:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: passive FTP doesn't work with CBAC</title>
      <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499152#M632395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it is supported on IOS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;well it is recommended u go thr only if you see that cbac is unable to achieve what you want&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it provides more flexibility&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in any case, for your query we seem to have isolated the issue that inspect ftp is broken, i have seen a lot of bugs related to broken inspect for L7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can go to zone-based-firewall but let me advise you that it is also unpredictable at times as far as features are concerned. when it works it works like magic but when something is boken it get really tough to isolate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to resolve your issue, i think its worth a try to go to 15.0 code which is latest, i would suggest even if you go to zone-based firewall use this code&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Aug 2010 05:18:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499152#M632395</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-08-06T05:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: passive FTP doesn't work with CBAC</title>
      <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499153#M632396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Diego,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I looked at your config, and it seems to be fine. Also I tried something similiar in a lab enviroment and it worked.&lt;/P&gt;&lt;P&gt;If you want to know more about zone based firewall, here is a link whit the configuration guide:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/ios/sec_data_plane/configuration/guide/sec_zone_polcy_firew_ps6441_TSD_Products_Configuration_Guide_Chapter.html"&gt;http://www.cisco.com/en/US/docs/ios/sec_data_plane/configuration/guide/sec_zone_polcy_firew_ps6441_TSD_Products_Configuration_Guide_Chapter.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Aug 2010 07:50:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499153#M632396</guid>
      <dc:creator>e.pedersen</dc:creator>
      <dc:date>2010-08-06T07:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: passive FTP doesn't work with CBAC</title>
      <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499154#M632397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One more question before I try the zone bases approach.&amp;nbsp; What type of ftp server did you test with?&amp;nbsp; I d&lt;SPAN style="background-color: #f8fafd;"&gt;id a test with a 2nd router runing a slightly older IOS and got the same results.&amp;nbsp; In both my cases the ftp server being protected was a Windows server.&amp;nbsp; Maybe CBAC and Windows ftp don't get along?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Diego&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Aug 2010 11:30:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499154#M632397</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2010-08-06T11:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: passive FTP doesn't work with CBAC</title>
      <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499155#M632398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please read your PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Aug 2010 15:43:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499155#M632398</guid>
      <dc:creator>e.pedersen</dc:creator>
      <dc:date>2010-08-06T15:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: passive FTP doesn't work with CBAC</title>
      <link>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499156#M632399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is this issue resolved?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0&lt;BR /&gt; description public IP&lt;BR /&gt; ip address 72.17.151.190 255.255.255.224&lt;BR /&gt; ip access-group 101 in&lt;BR /&gt; ip nat outside&lt;BR /&gt; ip inspect firewall out&lt;/P&gt;&lt;P&gt;ip inspect firewall in ------------------------&amp;gt; Pls. add this line as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for ftp traffic the user id and password goes over the control channel using tcp 21.You need to allow this via ACL. Inspection will take care of opening the data channel.&lt;/P&gt;&lt;P&gt;For active ftp the server sends the data using the source port tcp 20. Client sends the port command.&lt;/P&gt;&lt;P&gt;In case of passive ftp the server sends the port command and the client connects back to the high port &amp;gt;1024 to receive data.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://slacksite.com/other/ftp.html#actexample"&gt;http://slacksite.com/other/ftp.html#actexample&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Aug 2010 02:34:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passive-ftp-doesn-t-work-with-cbac/m-p/1499156#M632399</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-08-07T02:34:07Z</dc:date>
    </item>
  </channel>
</rss>

