<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Connection problem with firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194324#M840582</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're correct. Do you have any statics configured for this connection?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Jun 2009 15:40:54 GMT</pubDate>
    <dc:creator>John Blakley</dc:creator>
    <dc:date>2009-06-02T15:40:54Z</dc:date>
    <item>
      <title>Connection problem with firewall</title>
      <link>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194312#M840570</link>
      <description>&lt;P&gt;I am having problems with ftp to my server.&lt;/P&gt;&lt;P&gt;Client IP:10.0.1.2&lt;/P&gt;&lt;P&gt;Server IP : 10.35.20.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It says connection timeout &amp;amp; when telnet is done on 21,gives connect to port 21 failed. ftp seems to be open locally on server as when i try a ftp from another server locally, it prompts for login.&lt;/P&gt;&lt;P&gt;Below are logs on my firewall for this connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.0.1.2	1667	10.35.20.1	21	Teardown TCP connection 12379739847839711173 for AppZone:10.0.1.2	1667 to ftp_app:10.35.20.1/21 duration 0:00:20 bytes 66 SYN Timeout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest what could be the cause.Any issues with firewall?&lt;/P&gt;&lt;P&gt;Also how to determine from this output if this ftp is on passive or active mode?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:38:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194312#M840570</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2019-03-11T15:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Connection problem with firewall</title>
      <link>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194313#M840571</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you ftp'ing from the outside of your firewall, or are you trying to ftp from inside to outside? Can you post your config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 12:54:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194313#M840571</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2009-06-02T12:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: Connection problem with firewall</title>
      <link>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194314#M840572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These are on firewall module &amp;amp; ftp is tried from outside to inside,or to be clear server is on security level 0 &amp;amp; client is on 100.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list AppZone_list_in permit tcp host 10.0.1.2 host 10.35.20.1 eq 21&lt;/P&gt;&lt;P&gt;this is applied inbound on AppZone.&lt;/P&gt;&lt;P&gt;Counts on rule can be seen when this is tried.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 13:43:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194314#M840572</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2009-06-02T13:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: Connection problem with firewall</title>
      <link>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194315#M840573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SYN timeouts are usually related to routing problems. Make sure your firewall has a route to get to your network the clients are on.  Also make sure that your internal network has a route back to the firewall for that network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 13:49:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194315#M840573</guid>
      <dc:creator>jj27</dc:creator>
      <dc:date>2009-06-02T13:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: Connection problem with firewall</title>
      <link>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194316#M840574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Routing looks right for both ways.i can ping both server/client from the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 14:08:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194316#M840574</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2009-06-02T14:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: Connection problem with firewall</title>
      <link>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194317#M840575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, the firewall can ping the server and the client, that is fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can the SERVER get back to the CLIENT?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your firewall is incrementing the access list, so the connection is coming inbound, leaving the firewall then passing it in to your server.  What is happening is the firewall is never receiving a response from the server back to the client so you get the SYN timeout.  The problem is probably due to internal routing (from your server network to the client network of 10.0.1.0)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 14:33:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194317#M840575</guid>
      <dc:creator>jj27</dc:creator>
      <dc:date>2009-06-02T14:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: Connection problem with firewall</title>
      <link>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194318#M840576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mean  the server route table ?&lt;/P&gt;&lt;P&gt;if so, i am also suspecting this,but just needed some expert inputs or some other possible causes from gurus here.&lt;/P&gt;&lt;P&gt;Tks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 14:38:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194318#M840576</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2009-06-02T14:38:49Z</dc:date>
    </item>
    <item>
      <title>Re: Connection problem with firewall</title>
      <link>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194319#M840577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What kind of server is it? Is it a Windows box running FTP? Is it Linux based?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It could be an issue with the default gateway of the server or the routing table.  It could be an issue with the routing on your default gateway to know how to get to the external network of your client 10.1.0.0/?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 14:49:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194319#M840577</guid>
      <dc:creator>jj27</dc:creator>
      <dc:date>2009-06-02T14:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: Connection problem with firewall</title>
      <link>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194320#M840578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its a windows box.One query here, if the server doesnt find proper route path back to client, won't it take its default gateway and try reach the client &amp;amp; shouldn't this work for the connection to reach atleast firewall thus responding with syn-ack.&lt;/P&gt;&lt;P&gt;or is a more specific path required?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 14:53:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194320#M840578</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2009-06-02T14:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Connection problem with firewall</title>
      <link>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194321#M840579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;I&gt;access-list AppZone_list_in permit tcp host 10.0.1.2 host 10.35.20.1 eq 21&lt;/I&gt;&lt;/P&gt;&lt;P&gt;this is applied inbound on AppZone. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this applied on the outside interface or the inside interface (0 or 100). If it's applied on the inside interface, do you have an acl that's applied to the outside interface? If you have an acl on the outside interface, try adding port 20 to that acl. Active FTP connections make a connection to port 21, but the server tries to connect back to the client on port 20, and this could be the cause of your timeouts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 14:57:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194321#M840579</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2009-06-02T14:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: Connection problem with firewall</title>
      <link>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194322#M840580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh, another thing, I've never worked with the FWSM, but in PIX/ASA you can use fixup commands to fix things like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This could solve all of your problems instead of going through everything else you've done. &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 14:59:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194322#M840580</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2009-06-02T14:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: Connection problem with firewall</title>
      <link>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194323#M840581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its applied on outside(level 0).Anyway to know from this output if its active or passive? &lt;/P&gt;&lt;P&gt;for active as i know, server would give port 20 to client &amp;amp; try connecting back to random port &amp;gt;1023 which client had given during the second phase.&lt;/P&gt;&lt;P&gt;I may be wrong,please correct if so.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 15:05:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194323#M840581</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2009-06-02T15:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: Connection problem with firewall</title>
      <link>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194324#M840582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're correct. Do you have any statics configured for this connection?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 15:40:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194324#M840582</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2009-06-02T15:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: Connection problem with firewall</title>
      <link>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194325#M840583</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No statics for this connection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 23:33:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194325#M840583</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2009-06-02T23:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: Connection problem with firewall</title>
      <link>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194326#M840584</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;10.0.1.2 1667 10.35.20.1 21 Teardown TCP connection 12379739847839711173 for AppZone:10.0.1.2 1667 to ftp_app:10.35.20.1/21 duration 0:00:20 bytes 66 SYN Timeout &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This means that the server on the outside did not respond to they SYNs sent from the client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;jjohnston1127  asked the right question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the client have a route to the server network? I think it does or we wouldn't see the syn arrive on the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the server have a route back to the client network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just because the FWSM can ping both the client and the server, it doesn't mean server and the client can get to each other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure the server and the client can ping each other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What code is the FWSM running? &lt;/P&gt;&lt;P&gt;If it is 2.x then you should have &lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;If it is 3.x and above you should have &lt;/P&gt;&lt;P&gt;inspect ftp configured under policy-map&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It doesn't look like that is the problem. It looks like the server does not have a route back to the client's IP. Pls. check the gateway that the server is pointing to and make sure it has a route back to the client network&lt;/P&gt;&lt;P&gt;otherwise, just add a static route on the windows server such that it will reach the FWSM ftp_app interface in order to get to 10.0.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route add 10.0.1.2 &lt;FWSM-FTP_APP_IP&gt;&lt;/FWSM-FTP_APP_IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and give that a shot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wireshark capture on the server may be a good idea to see where it is sending the syn ack (as to which mac address)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know how that goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2009 00:41:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194326#M840584</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-06-03T00:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: Connection problem with firewall</title>
      <link>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194327#M840585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks to all, problem was with server ip configuration.&lt;/P&gt;&lt;P&gt;Btw, a question since we were talking of sniffing traffic, is there any link or guide to get know how about the different&lt;/P&gt;&lt;P&gt;outputs given by different sniffers or the common ones like wireshark.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jun 2009 02:16:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194327#M840585</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2009-06-04T02:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: Connection problem with firewall</title>
      <link>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194328#M840586</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very glad to hear that the problem was on the server end just as we suspected...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://wiki.wireshark.org/SampleCaptures" target="_blank"&gt;http://wiki.wireshark.org/SampleCaptures&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope the above link will help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jun 2009 02:28:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-problem-with-firewall/m-p/1194328#M840586</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-06-04T02:28:23Z</dc:date>
    </item>
  </channel>
</rss>

