<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot Download From FTP Site in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-download-from-ftp-site/m-p/1351264#M751273</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also check forthe following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Any filter rules configured on ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. If you have any SSM modules check for alerts (means AIP, CSC).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Fragmentation issue, check you have permitted ICMP unreachable message on ASA, otherwise it will casue PMTUD (path mtu discovery)process to fail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dileep&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 12 Jan 2010 04:56:11 GMT</pubDate>
    <dc:creator>Dileep Sivadas Padmini</dc:creator>
    <dc:date>2010-01-12T04:56:11Z</dc:date>
    <item>
      <title>Cannot Download From FTP Site</title>
      <link>https://community.cisco.com/t5/network-security/cannot-download-from-ftp-site/m-p/1351261#M751256</link>
      <description>&lt;P&gt;I can connect and browse the subfolders but when ever I try to download anything&lt;SPAN style="background-color: #f8fafd;"&gt; IE 7 just hangs. I am behind a ASA 5510. when I try to download the same file from my home PC it starts the download right away, which is why I think its my firewall. What do I need on the firewall to allow the download?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:55:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-download-from-ftp-site/m-p/1351261#M751256</guid>
      <dc:creator>kencranmer</dc:creator>
      <dc:date>2019-03-11T16:55:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Download From FTP Site</title>
      <link>https://community.cisco.com/t5/network-security/cannot-download-from-ftp-site/m-p/1351262#M751262</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to check your Inspect Policy on your ASA.&amp;nbsp; make sure that inspect ftp is in there.&amp;nbsp; I hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Russell&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jan 2010 22:26:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-download-from-ftp-site/m-p/1351262#M751262</guid>
      <dc:creator>rmanapat</dc:creator>
      <dc:date>2010-01-11T22:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Download From FTP Site</title>
      <link>https://community.cisco.com/t5/network-security/cannot-download-from-ftp-site/m-p/1351263#M751266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Few things we need to consider about SLOW downloads from your FTP server (which I ASSUME is out on the internet) for clients behind the firewall.&lt;/P&gt;&lt;P&gt;Was any s/w upgrade or h/w change done to the box when you noticed such a behavior ?&lt;/P&gt;&lt;P&gt;Since you are able to connect to the FTP site, most probably&amp;nbsp; it will have nothing to do with your inspect FTP command on the box.&lt;/P&gt;&lt;P&gt;What you need to do is to setup captures on the box for interesting traffic and then analyse it using wireshark network analyser, to check for :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Increased MSS sizes being used for TCP transmission across the ASA. By default ASA has MSS of 1380 bytes, so if any greater segment sizes are coming to the ASA, then it will have to break them up into several PDU's which would mean a lot of reassembling will be done. This could slow down downloads.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Increased TCP MSS segments can be allowed on ASA, using advaced TCP options in MPF.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the asp drop counters on firewall to check for o-o-o packets (out of order) and try to increase the queue-limit for allowing such kinds of packets and montior if that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bottom line, best way to troubleshoot latency issues for downloads are packet captures. Here is a&amp;nbsp; link to help you setup captures&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-1222"&gt;https://supportforums.cisco.com/docs/DOC-1222&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vijaya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jan 2010 04:32:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-download-from-ftp-site/m-p/1351263#M751266</guid>
      <dc:creator>vilaxmi</dc:creator>
      <dc:date>2010-01-12T04:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Download From FTP Site</title>
      <link>https://community.cisco.com/t5/network-security/cannot-download-from-ftp-site/m-p/1351264#M751273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also check forthe following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Any filter rules configured on ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. If you have any SSM modules check for alerts (means AIP, CSC).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Fragmentation issue, check you have permitted ICMP unreachable message on ASA, otherwise it will casue PMTUD (path mtu discovery)process to fail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dileep&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jan 2010 04:56:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-download-from-ftp-site/m-p/1351264#M751273</guid>
      <dc:creator>Dileep Sivadas Padmini</dc:creator>
      <dc:date>2010-01-12T04:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Download From FTP Site</title>
      <link>https://community.cisco.com/t5/network-security/cannot-download-from-ftp-site/m-p/1351265#M751294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Turns out to be a problem with CSC. Waiting for a tech specialized in this area to look into&lt;/P&gt;&lt;P&gt;it for me. Thanks for the advice!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jan 2010 15:48:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-download-from-ftp-site/m-p/1351265#M751294</guid>
      <dc:creator>kencranmer</dc:creator>
      <dc:date>2010-01-12T15:48:34Z</dc:date>
    </item>
  </channel>
</rss>

