<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't access FTP server over Internet through ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184207#M875857</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With the ASA 5520, the fixup replaced with inspect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns maximum-length 512&lt;/P&gt;&lt;P&gt;  inspect ftp&lt;/P&gt;&lt;P&gt;  inspect h323 h225&lt;/P&gt;&lt;P&gt;  inspect h323 ras&lt;/P&gt;&lt;P&gt;  inspect rsh&lt;/P&gt;&lt;P&gt;  inspect rtsp&lt;/P&gt;&lt;P&gt;  inspect esmtp&lt;/P&gt;&lt;P&gt;  inspect sqlnet&lt;/P&gt;&lt;P&gt;  inspect skinny&lt;/P&gt;&lt;P&gt;  inspect sunrpc&lt;/P&gt;&lt;P&gt;  inspect xdmcp&lt;/P&gt;&lt;P&gt;  inspect sip&lt;/P&gt;&lt;P&gt;  inspect netbios&lt;/P&gt;&lt;P&gt;  inspect tftp&lt;/P&gt;&lt;P&gt;  inspect pptp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;this functionality allows active FTP to pass through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Feb 2009 20:57:01 GMT</pubDate>
    <dc:creator>Tshi M</dc:creator>
    <dc:date>2009-02-25T20:57:01Z</dc:date>
    <item>
      <title>Can't access FTP server over Internet through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184197#M875779</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This was all working so I'm not sure what has changed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a windows 2003 FTP server that we can access internally fine.  Usually we can access over the Internet using it's public IP, but it has stopped working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the following rules:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host *.*.*.72 eq ftp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host *.*.*.72 eq ftp-data &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (DMZ10_Web_Svrs,outside) *.*.*.72 192.168.15.4 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the Internet I get the logon page (when I go to &lt;A class="jive-link-custom" href="ftp://" target="_blank"&gt;ftp://&lt;/A&gt;*.*.*.72) and put my username and password in and I get accepted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get the message "getting contents of folder" in the left hand corner, but then get a "time out" error.  If I go to the FTP server then to and look at current connections I see that I am connected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have rebuilt the FTP server and get the same results, I have even installed FTP on another Windows server and get the same results, so it must be on the ASA5520.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I open up port 80 and installed a simple web page and that worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see my asa has poliy maps &amp;gt; inspect ftp could this be anything?  It's like it's an outbound issue back to the client as it works fine on the LAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:56:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184197#M875779</guid>
      <dc:creator>whiteford</dc:creator>
      <dc:date>2019-03-11T14:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access FTP server over Internet through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184198#M875785</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Based on what you describe here it seems it is the standard active FTP setup, but can you confirm? is this active or passive FTP? Can you enable logging on the ASA and check it when the connection times out?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Feb 2009 21:42:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184198#M875785</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-02-24T21:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access FTP server over Internet through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184199#M875798</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's a standard Windows 2003 FTP server in isolation mode (local user logins).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I tell if it is passove or active?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I can telnet to port 21 but not 20 even though I have this port open over the internet, should I be able to telnet to this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried installing FTP on another server and get the same results over the internet too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plus FTP works on these servers internally&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Feb 2009 22:10:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184199#M875798</guid>
      <dc:creator>whiteford</dc:creator>
      <dc:date>2009-02-24T22:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access FTP server over Internet through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184200#M875813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK well you would have to check your FTP server but I think it is active, now can you go ahead and enable logs on your ASA to level 5 and then try the ftp connection for example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging on&lt;/P&gt;&lt;P&gt;logging monitor 5&lt;/P&gt;&lt;P&gt;ter mon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then try your ftp connection and see if you got logs from the relevant connection. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Feb 2009 22:13:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184200#M875813</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-02-24T22:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access FTP server over Internet through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184201#M875820</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I doesn't show up anything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got rid of the rule and a deny came up, just to prove I did it right.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FTP works just fine internally.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Feb 2009 22:29:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184201#M875820</guid>
      <dc:creator>whiteford</dc:creator>
      <dc:date>2009-02-24T22:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access FTP server over Internet through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184202#M875829</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you done packet captures? if so get captures on both inside and outside from the server to the client and viceversa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Feb 2009 22:32:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184202#M875829</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-02-24T22:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access FTP server over Internet through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184203#M875836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your ACL is not correct.  You need to understand how Active and Passive FTP works:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Active FTP:  client connects to server on port 21.  Server uses port 20 to transfer data back to client.  In the 2nd phase, the FTP server is the client and the FTP client is the server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Passive FTP:  client connects to server on port 21.  Server tells the client a port &amp;gt; 1024 to use for the data transfer.  Client then makes a 2nd connection from its &amp;gt;1024 ports to the server &amp;gt; 1024 ports.  In this scenario, the client does all the work, server does nothing.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Therefore, the second-line ACL ftp-data is not needed at all.  You will never see a match in this ACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your scenario, since you're doing NAT, you must enable "fixup protocol ftp 21" or your FTP will fail&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you bypass the ASA, does FTP still work?  If that works, it is probably a bug in the ASA code, just guessing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Feb 2009 22:49:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184203#M875836</guid>
      <dc:creator>daviddtran</dc:creator>
      <dc:date>2009-02-24T22:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access FTP server over Internet through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184204#M875843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do I just need to add "fixup protocol ftp 21" to the cli?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will try to bypass the ASA too.  Thing is it's all been working fine for years.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is active ftp, do I need an outbound rule?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Feb 2009 23:03:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184204#M875843</guid>
      <dc:creator>whiteford</dc:creator>
      <dc:date>2009-02-24T23:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access FTP server over Internet through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184205#M875851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"fixup protocol ftp 21" did it!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A big thanks, what does this do?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, could this be a bug?  I'm on 8.0(3).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Feb 2009 23:17:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184205#M875851</guid>
      <dc:creator>whiteford</dc:creator>
      <dc:date>2009-02-24T23:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access FTP server over Internet through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184206#M875855</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "fixup protocol ftp 21" doesn't appear in the CLI or ASDM, where does it go once I've added it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does the Fixup actually do?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Feb 2009 20:16:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184206#M875855</guid>
      <dc:creator>whiteford</dc:creator>
      <dc:date>2009-02-25T20:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access FTP server over Internet through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184207#M875857</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With the ASA 5520, the fixup replaced with inspect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns maximum-length 512&lt;/P&gt;&lt;P&gt;  inspect ftp&lt;/P&gt;&lt;P&gt;  inspect h323 h225&lt;/P&gt;&lt;P&gt;  inspect h323 ras&lt;/P&gt;&lt;P&gt;  inspect rsh&lt;/P&gt;&lt;P&gt;  inspect rtsp&lt;/P&gt;&lt;P&gt;  inspect esmtp&lt;/P&gt;&lt;P&gt;  inspect sqlnet&lt;/P&gt;&lt;P&gt;  inspect skinny&lt;/P&gt;&lt;P&gt;  inspect sunrpc&lt;/P&gt;&lt;P&gt;  inspect xdmcp&lt;/P&gt;&lt;P&gt;  inspect sip&lt;/P&gt;&lt;P&gt;  inspect netbios&lt;/P&gt;&lt;P&gt;  inspect tftp&lt;/P&gt;&lt;P&gt;  inspect pptp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;this functionality allows active FTP to pass through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Feb 2009 20:57:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184207#M875857</guid>
      <dc:creator>Tshi M</dc:creator>
      <dc:date>2009-02-25T20:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access FTP server over Internet through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184208#M875859</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's not correct.  "fixup protocol ftp 21" allows both Active and Passive FTP to pass through.  Without this command, you will have to use allow &amp;gt;1024 ports to enter the firewall for passive ftp and that, if you have ACL on the inside interface, you have to allow ftp-data port from the server back out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One more thing, without "fixup protocol ftp 21", FTP will not work at all, if you have NAT.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Feb 2009 22:09:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-ftp-server-over-internet-through-asa/m-p/1184208#M875859</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2009-02-25T22:09:09Z</dc:date>
    </item>
  </channel>
</rss>

