<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to enable FTP in management port of an ASA 5525X? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-enable-ftp-in-management-port-of-an-asa-5525x/m-p/2749890#M916980</link>
    <description>&lt;P style="font-size: 14.4px; line-height: normal;"&gt;Hi all,&lt;BR /&gt;I can ping the management port of my ASA from my PC (remote VPN to the client), all other ports are in shutdown (pre-prod stage)&lt;BR /&gt;I can't ping however from ASA to my PC that is now a vpn client of the remote client I am working on.&lt;/P&gt;&lt;P style="font-size: 14.4px; line-height: normal;"&gt;Global policy below:&lt;/P&gt;&lt;P style="font-size: 14.4px; line-height: normal;"&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect ftp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect h323 h225&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect h323 ras&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect rsh&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect rtsp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect esmtp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sqlnet&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect skinny &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sunrpc&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect xdmcp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sip &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect netbios&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect tftp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect ip-options&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect icmp&amp;nbsp;&lt;BR /&gt;* As you can see icmp and ftp are allowed&lt;/P&gt;&lt;P style="font-size: 14.4px; line-height: normal;"&gt;Management has the same security level as the inside (100)&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P style="font-size: 14.4px; line-height: normal;"&gt;ip verify reverse-path interface management&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;What is missing in my config in order for ping to work from my ASA and as well make ftp work so I can transfer new packages from my PC to my ASA?&lt;BR /&gt;&lt;BR /&gt;Please let me know what else you need for me to capture....&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 13:35:05 GMT</pubDate>
    <dc:creator>blue phoenix</dc:creator>
    <dc:date>2020-02-21T13:35:05Z</dc:date>
    <item>
      <title>How to enable FTP in management port of an ASA 5525X?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-enable-ftp-in-management-port-of-an-asa-5525x/m-p/2749890#M916980</link>
      <description>&lt;P style="font-size: 14.4px; line-height: normal;"&gt;Hi all,&lt;BR /&gt;I can ping the management port of my ASA from my PC (remote VPN to the client), all other ports are in shutdown (pre-prod stage)&lt;BR /&gt;I can't ping however from ASA to my PC that is now a vpn client of the remote client I am working on.&lt;/P&gt;&lt;P style="font-size: 14.4px; line-height: normal;"&gt;Global policy below:&lt;/P&gt;&lt;P style="font-size: 14.4px; line-height: normal;"&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect ftp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect h323 h225&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect h323 ras&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect rsh&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect rtsp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect esmtp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sqlnet&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect skinny &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sunrpc&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect xdmcp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sip &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect netbios&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect tftp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect ip-options&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect icmp&amp;nbsp;&lt;BR /&gt;* As you can see icmp and ftp are allowed&lt;/P&gt;&lt;P style="font-size: 14.4px; line-height: normal;"&gt;Management has the same security level as the inside (100)&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P style="font-size: 14.4px; line-height: normal;"&gt;ip verify reverse-path interface management&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;What is missing in my config in order for ping to work from my ASA and as well make ftp work so I can transfer new packages from my PC to my ASA?&lt;BR /&gt;&lt;BR /&gt;Please let me know what else you need for me to capture....&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:35:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-enable-ftp-in-management-port-of-an-asa-5525x/m-p/2749890#M916980</guid>
      <dc:creator>blue phoenix</dc:creator>
      <dc:date>2020-02-21T13:35:05Z</dc:date>
    </item>
    <item>
      <title>Your inspection policies have</title>
      <link>https://community.cisco.com/t5/network-security/how-to-enable-ftp-in-management-port-of-an-asa-5525x/m-p/2749891#M916981</link>
      <description>&lt;P&gt;Your inspection policies have nothing to do with allowing or preventing access.&lt;/P&gt;&lt;P&gt;Traffic cannot flow through the ASA to the management port. That is prevented by design.&lt;/P&gt;&lt;P&gt;If all ports are shutdown except management then you should be able to access management directly from whatever network it is connected to. If you're on a remote network, you simply need to have a route defined and bound to management and allow the ssh or http from that network for cli and ASDM access respectively.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2015 13:44:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-enable-ftp-in-management-port-of-an-asa-5525x/m-p/2749891#M916981</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-09-11T13:44:57Z</dc:date>
    </item>
    <item>
      <title>Thanks,I have access to the</title>
      <link>https://community.cisco.com/t5/network-security/how-to-enable-ftp-in-management-port-of-an-asa-5525x/m-p/2749892#M916983</link>
      <description>&lt;P&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;I have access to the management port, the management port is routable in the network for Inside and vpn users. &amp;nbsp;The ASA I am configuring is in it's staging status and not yet in production.&lt;BR /&gt;&lt;BR /&gt;So I don't know if I am doing this right or wrong since by default if the IP is routable and reachable you can ftp into it right if in the global policy it is allowed?&lt;BR /&gt;&lt;BR /&gt;I tried to also configure an access-list permitting any any to the inbound of the management. &amp;nbsp;And binded that to an access-group in the management interface as well... No joy....&lt;BR /&gt;&lt;BR /&gt;So what you are saying is that by default and design, management port is just purely for management and can't be used for transferring files to and from?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2015 15:22:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-enable-ftp-in-management-port-of-an-asa-5525x/m-p/2749892#M916983</guid>
      <dc:creator>blue phoenix</dc:creator>
      <dc:date>2015-09-11T15:22:39Z</dc:date>
    </item>
    <item>
      <title>I noted that you cannot</title>
      <link>https://community.cisco.com/t5/network-security/how-to-enable-ftp-in-management-port-of-an-asa-5525x/m-p/2749893#M916984</link>
      <description>&lt;P&gt;I noted that you cannot access the management interface&amp;nbsp;THROUGH the ASA. If you're connecting directly TO&amp;nbsp;the management address, then it works fine.&lt;/P&gt;
&lt;P&gt;The global policy and inspect rules it references have nothing to do with management traffic, ftp or otherwise.&lt;/P&gt;
&lt;P&gt;To copy files onto the ASA you can use ftp (ASA is the ftp client so you need to initiate from the ASA - not "ftp into it"), scp, tftp or http. HTTP(s) is the method used when we transfer via ASDM.&lt;/P&gt;
&lt;P&gt;In any of those cases we need to allow ssh (for the cli-based methods) or http (for ASDM) from your client address or network in the ASA configuration. The commands look something like:&lt;/P&gt;

&lt;PRE&gt;
ssh 192.168.1.0 255.255.255.0 management

http 192.168.1.0 255.255.255.0 management&lt;/PRE&gt;

&lt;P&gt;( of course substituting your network and netmask)&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2015 21:34:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-enable-ftp-in-management-port-of-an-asa-5525x/m-p/2749893#M916984</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-09-11T21:34:46Z</dc:date>
    </item>
    <item>
      <title>@Marvin Rhoads,Hi, do you</title>
      <link>https://community.cisco.com/t5/network-security/how-to-enable-ftp-in-management-port-of-an-asa-5525x/m-p/2749894#M916985</link>
      <description>&lt;P&gt;@Marvin Rhoads,&lt;BR /&gt;&lt;BR /&gt;Hi, do you mean that I can transfer files from my PC (tftp/ftp server) to the ASA via the managament port or not?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2015 16:09:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-enable-ftp-in-management-port-of-an-asa-5525x/m-p/2749894#M916985</guid>
      <dc:creator>blue phoenix</dc:creator>
      <dc:date>2015-09-15T16:09:35Z</dc:date>
    </item>
    <item>
      <title>Yes you can. I do it all the</title>
      <link>https://community.cisco.com/t5/network-security/how-to-enable-ftp-in-management-port-of-an-asa-5525x/m-p/2749895#M916986</link>
      <description>&lt;P&gt;Yes you can. I do it all the time.&lt;/P&gt;
&lt;P&gt;You just need to run the&lt;/P&gt;

&lt;PRE&gt;
copy tftp://&amp;lt;your pc address&amp;gt;/&amp;lt;file name&amp;gt; disk0:/&lt;/PRE&gt;

&lt;P&gt;...&amp;nbsp;command (or with ftp and username / password for ftp) on the ASA.&lt;/P&gt;
&lt;P&gt;The feature has been available since the ASA was known as a Pix.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2015 16:13:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-enable-ftp-in-management-port-of-an-asa-5525x/m-p/2749895#M916986</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-09-15T16:13:47Z</dc:date>
    </item>
    <item>
      <title>Hi,That is what is bothering</title>
      <link>https://community.cisco.com/t5/network-security/how-to-enable-ftp-in-management-port-of-an-asa-5525x/m-p/2749896#M916987</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;That is what is bothering me... I tried the usual copy ftp: disk:0&lt;BR /&gt;Asked me of the remote IP:&lt;BR /&gt;Asked me of the name of the file:&lt;BR /&gt;Asked me of the name for the destination file:&lt;BR /&gt;&lt;BR /&gt;I tried this command as well:&lt;BR /&gt;&lt;BR /&gt;copy ftp://192.168.80.239/C:\Users\rbilan\Downloads\ASA disk0:&lt;/P&gt;&lt;P&gt;still permission denied, do I need the complete syntax to work as below?&lt;BR /&gt;&lt;BR /&gt;copy ftp://192.168.80.239/C:\Users\rbilan\Downloads\ASA disk0:/&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Also if the copying of files has been around since the PIX, could you point me to a link that explains the step by step procedure for this using the management port? &amp;nbsp; Sorry can't seem to find any link for 9.1.2&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2015 08:37:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-enable-ftp-in-management-port-of-an-asa-5525x/m-p/2749896#M916987</guid>
      <dc:creator>blue phoenix</dc:creator>
      <dc:date>2015-09-16T08:37:05Z</dc:date>
    </item>
    <item>
      <title>Your copy ftp syntax is</title>
      <link>https://community.cisco.com/t5/network-security/how-to-enable-ftp-in-management-port-of-an-asa-5525x/m-p/2749897#M916988</link>
      <description>&lt;P&gt;Your copy ftp syntax is incorrect.&lt;/P&gt;
&lt;P&gt;The ftp server software on your PC should have an option to set the home directory of the configured ftp username. For instance, set it to "&lt;SPAN style="font-size: 14.4px; line-height: normal;"&gt;C:\Users\rbilan\Downloads\ASA&lt;/SPAN&gt;" in the ftp server software configuration. Once that is done, any remote ftp operation uses that as the starting point to look for the remote file.&lt;/P&gt;
&lt;P&gt;So if you do that and want to copy the file "asa915-k8.bin" onto your ASA from that home directory, you would simply use:&lt;/P&gt;

&lt;PRE&gt;
&lt;SPAN style="font-size: 14.4px; line-height: normal;"&gt;copy ftp://192.168.80.239/&lt;/SPAN&gt;asa915-k8.bin&lt;SPAN style="font-size: 14.4px; line-height: normal;"&gt; disk0:&lt;/SPAN&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;SPAN style="font-size: 14.4px; line-height: normal;"&gt;You can optionally include the username and password in the copy command as follows (substituting your values):&lt;/SPAN&gt;&lt;/P&gt;

&lt;PRE&gt;
&lt;SPAN style="font-size: 14.4px; line-height: normal;"&gt;copy ftp://username:password@192.168.80.239/&lt;/SPAN&gt;asa915-k8.bin&lt;SPAN style="font-size: 14.4px; line-height: normal;"&gt; disk0:&lt;/SPAN&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;SPAN style="font-size: 14.4px; line-height: normal;"&gt;The copy command syntax is covered in the ASA command reference.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2015 13:42:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-enable-ftp-in-management-port-of-an-asa-5525x/m-p/2749897#M916988</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-09-16T13:42:48Z</dc:date>
    </item>
  </channel>
</rss>

