<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unblae to communicate on SFTP port (Port No 22) between different VLANs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006059#M938111</link>
    <description>&lt;P&gt;I am having following trouble..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source IP from where he is trying to SFTP: 10.254.227.* (DMZ VLAN)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Destination IP: 10.254.230.* where we need access(Also a VLAN)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a Checkpoint and PIX firewall on which access-lists are configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On checking logs on both firewalls the SFTP is permitted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We tested it many times from command prompt but connections fails saying 'Connection failed on port 22'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For eg: &amp;gt;telnet ip address 22&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tried to telnet from server (ip 10.254.227.*) to (10.254.230.*)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We tried telnetting on port 22 first and then 21 also but no joy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone give some ideas as what could be preventing the connection?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have checked logs on Checkpoint and it says request accepted when I am sending request from 10.254.227.x using FileZilla software to connect to another server which is in different VLAN (10.254.230.x). &lt;/P&gt;&lt;P&gt;I have found that on cisco PIX, traffic is getting accepted but its not going to the appropriate destination. &lt;/P&gt;&lt;P&gt;Pls check my following logs from CISCO PIX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For PIX firewall it seems like address translation issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have got log from PIX firewall as follows&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;****************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2008-05-07 21:31:29 Local6.Info 192.168.1.1 %ASA-6-106100: access-list Outside-inbound permitted tcp Outside/10.254.227.*(3882) -&amp;gt; OperWebMgmt/10.254.230.*(22) hit-cnt 1 first hit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2008-05-07 21:31:29 Local6.Error 192.168.1.1 %ASA-3-305005: No translation group found for tcp src Outside:10.254.227.*/3882 dst OperWebMgmt:10.254.230.*/22&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;***************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looks to us like PIX is allowing to make inbound connection but not able to make it out towards destination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a route between both VLAN's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Due to security reasons ping and tracert are disabled.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 12:41:36 GMT</pubDate>
    <dc:creator>pannu3679</dc:creator>
    <dc:date>2019-03-11T12:41:36Z</dc:date>
    <item>
      <title>Unblae to communicate on SFTP port (Port No 22) between different VLANs</title>
      <link>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006059#M938111</link>
      <description>&lt;P&gt;I am having following trouble..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source IP from where he is trying to SFTP: 10.254.227.* (DMZ VLAN)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Destination IP: 10.254.230.* where we need access(Also a VLAN)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a Checkpoint and PIX firewall on which access-lists are configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On checking logs on both firewalls the SFTP is permitted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We tested it many times from command prompt but connections fails saying 'Connection failed on port 22'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For eg: &amp;gt;telnet ip address 22&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tried to telnet from server (ip 10.254.227.*) to (10.254.230.*)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We tried telnetting on port 22 first and then 21 also but no joy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone give some ideas as what could be preventing the connection?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have checked logs on Checkpoint and it says request accepted when I am sending request from 10.254.227.x using FileZilla software to connect to another server which is in different VLAN (10.254.230.x). &lt;/P&gt;&lt;P&gt;I have found that on cisco PIX, traffic is getting accepted but its not going to the appropriate destination. &lt;/P&gt;&lt;P&gt;Pls check my following logs from CISCO PIX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For PIX firewall it seems like address translation issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have got log from PIX firewall as follows&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;****************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2008-05-07 21:31:29 Local6.Info 192.168.1.1 %ASA-6-106100: access-list Outside-inbound permitted tcp Outside/10.254.227.*(3882) -&amp;gt; OperWebMgmt/10.254.230.*(22) hit-cnt 1 first hit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2008-05-07 21:31:29 Local6.Error 192.168.1.1 %ASA-3-305005: No translation group found for tcp src Outside:10.254.227.*/3882 dst OperWebMgmt:10.254.230.*/22&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;***************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looks to us like PIX is allowing to make inbound connection but not able to make it out towards destination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a route between both VLAN's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Due to security reasons ping and tracert are disabled.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:41:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006059#M938111</guid>
      <dc:creator>pannu3679</dc:creator>
      <dc:date>2019-03-11T12:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: Unblae to communicate on SFTP port (Port No 22) between diff</title>
      <link>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006060#M938112</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there any once who can help me please? I can give you PIX config. too  if required...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 May 2008 10:08:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006060#M938112</guid>
      <dc:creator>pannu3679</dc:creator>
      <dc:date>2008-05-08T10:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: Unblae to communicate on SFTP port (Port No 22) between diff</title>
      <link>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006061#M938113</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;post the config so that I can help you&lt;/P&gt;&lt;P&gt;troubleshoot it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 May 2008 10:26:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006061#M938113</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-05-08T10:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unblae to communicate on SFTP port (Port No 22) between diff</title>
      <link>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006062#M938114</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pls find the following config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below config. will give you an idea about my VLAN interface IP and the access list I have configured to pass traffic between them.  I have also mentioned NAT list with different VLAN from my network which will give you more idea about NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; nameif Outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; ip address 10.254.240.236 255.255.255.0 standby 10.254.240.235&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2.63&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; vlan 63&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; nameif OperWebMgmt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt; ip address 10.254.230.254 255.255.255.0 standby 10.254.230.253 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;==========================================&lt;/P&gt;&lt;P&gt;I have configured following 2 ACL&lt;/P&gt;&lt;P&gt;==========================================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list Outside-inbound extended permit tcp host 10.254.227.6 host 10.254.230.33 eq ssh &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list OperWeb-inbound extended permit tcp host 10.254.230.33 host 10.254.227.6 eq ssh &lt;/P&gt;&lt;P&gt;=========&lt;/P&gt;&lt;P&gt;NAT&lt;/P&gt;&lt;P&gt;=========&lt;/P&gt;&lt;P&gt;global (OperAppMgmt) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (InterFWInterconnect) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (Witness) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (Hmenus) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (App-ILO) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (OperWebMgmt) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (management) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (Operators) 1 10.254.231.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (Operators) 1 192.168.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (OperWebMgmt) 0 10.254.230.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (InterFWInterconnect,Outside) 10.254.224.0 10.254.224.0 netmask 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (OperWebMgmt,OperAppMgmt) 10.254.230.39 10.254.230.39 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (OperAppMgmt,OperWebMgmt) 10.254.253.62 10.254.253.62 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (OperAppMgmt,OperWebMgmt) 10.254.253.61 10.254.253.61 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (OperAppMgmt,OperWebMgmt) 10.254.253.75 10.254.253.75 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (OperWebMgmt,OperAppMgmt) 10.254.230.33 10.254.230.33 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (OperWebMgmt,OperAppMgmt) 10.254.230.31 10.254.230.31 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (OperWebMgmt,OperAppMgmt) 10.254.230.32 10.254.230.32 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;--- More ---&amp;gt;&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;static (OperWebMgmt,OperAppMgmt) 10.254.230.13 10.254.230.13 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (OperWebMgmt,OperAppMgmt) 10.254.230.14 10.254.230.14 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (OperWebMgmt,OperAppMgmt) 10.254.230.41 10.254.230.41 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (OperWebMgmt,OperAppMgmt) 10.254.230.40 10.254.230.40 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (OperWebMgmt,OperAppMgmt) 10.254.230.34 10.254.230.34 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls let me know if u need more info.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 May 2008 11:46:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006062#M938114</guid>
      <dc:creator>pannu3679</dc:creator>
      <dc:date>2008-05-08T11:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Unblae to communicate on SFTP port (Port No 22) between diff</title>
      <link>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006063#M938115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Someone can help me pls... It's quite urgent as my client wanted to fix this issue ASAP and I could not find out proper solution....&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 May 2008 21:15:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006063#M938115</guid>
      <dc:creator>pannu3679</dc:creator>
      <dc:date>2008-05-08T21:15:15Z</dc:date>
    </item>
    <item>
      <title>Re: Unblae to communicate on SFTP port (Port No 22) between diff</title>
      <link>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006064#M938116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;static (OperWebMgmt,Outside) 10.254.30.x 10.254.30.x netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do that and it will work&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 May 2008 00:19:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006064#M938116</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-05-09T00:19:58Z</dc:date>
    </item>
    <item>
      <title>Re: Unblae to communicate on SFTP port (Port No 22) between diff</title>
      <link>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006065#M938117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have tried this but same result... but this time, I can't see NAT log error message.....any idea?&lt;/P&gt;&lt;P&gt;Now I can see following logs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;05-09-2008	12:00:54	Local6.Info	192.168.1.1	%ASA-6-106100: access-list Outside-inbound permitted tcp Outside/10.254.227.6(2710) -&amp;gt; OperWebMgmt/10.254.230.33(22) hit-cnt 1 first hit&lt;/P&gt;&lt;P&gt;=============================================&lt;/P&gt;&lt;P&gt;05-09-2008	12:04:40	Local6.Info	192.168.1.1	%ASA-6-106015: Deny TCP (no connection) from 10.254.227.6/2897 to 10.254.230.33/22 flags RST  on interface Outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for quick response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 May 2008 00:54:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006065#M938117</guid>
      <dc:creator>pannu3679</dc:creator>
      <dc:date>2008-05-09T00:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Unblae to communicate on SFTP port (Port No 22) between diff</title>
      <link>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006066#M938118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any time if you see this message - No translation group found, means you are missing NAT or incorrect NATing. PIX will not work without NATing though access list is allowing the traffic. It needs some kind of NAT - NAT 0 (no NAT), static or dymanic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2008-05-07 21:31:29 Local6.Error 192.168.1.1 %ASA-3-305005: No translation group found for tcp src Outside:10.254.227.*/3882 dst OperWebMgmt:10.254.230.*/22 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are not able to connect though you have Proper NAT and access list, means mostly your return traffic is taking different path. Packet flowing in both directions should go through same firewalls. The error Deny TCP (no connection) means return traffic came to PIX but PIX has no entry of connection initiation. &lt;/P&gt;&lt;P&gt;Connection initiated packet took one path but return traffic is comming through some other path, Check you routing on both end systems like default GW or host/network routes, also on firewall and any middle devices. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate me if this helps&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Kapish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 May 2008 01:53:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006066#M938118</guid>
      <dc:creator>kapish.mohole</dc:creator>
      <dc:date>2008-05-09T01:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: Unblae to communicate on SFTP port (Port No 22) between diff</title>
      <link>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006067#M938120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Mate,&lt;/P&gt;&lt;P&gt;I have configured static NAT but still same thing... pls check my last post and if it makes any sense to you...&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 May 2008 02:07:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006067#M938120</guid>
      <dc:creator>pannu3679</dc:creator>
      <dc:date>2008-05-09T02:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: Unblae to communicate on SFTP port (Port No 22) between diff</title>
      <link>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006068#M938124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have modified my post please see it again. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Kapish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 May 2008 02:09:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006068#M938124</guid>
      <dc:creator>kapish.mohole</dc:creator>
      <dc:date>2008-05-09T02:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: Unblae to communicate on SFTP port (Port No 22) between diff</title>
      <link>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006069#M938127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post PIX full configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 May 2008 03:35:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006069#M938127</guid>
      <dc:creator>CiscogeekIND</dc:creator>
      <dc:date>2008-05-09T03:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Unblae to communicate on SFTP port (Port No 22) between diff</title>
      <link>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006070#M938129</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, were you able to solve it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Kapish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 May 2008 21:50:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006070#M938129</guid>
      <dc:creator>kapish.mohole</dc:creator>
      <dc:date>2008-05-09T21:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: Unblae to communicate on SFTP port (Port No 22) between diff</title>
      <link>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006071#M938132</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have not allowed any ftp traffic between the two hosts.  Put this in your config :&lt;/P&gt;&lt;P&gt;access-list Outside-inbound extended permit tcp host 10.254.227.6 host 10.254.230.33 eq ftp &lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 May 2008 00:38:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006071#M938132</guid>
      <dc:creator>rkalia1</dc:creator>
      <dc:date>2008-05-10T00:38:26Z</dc:date>
    </item>
    <item>
      <title>Re: Unblae to communicate on SFTP port (Port No 22) between diff</title>
      <link>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006072#M938133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sorry use eq 22 as you are using sftp.  You need to check that you have "ip inspect sftp" or "fixup protocol sftp" command also on the PIX depending upon your version release.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 May 2008 00:40:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006072#M938133</guid>
      <dc:creator>rkalia1</dc:creator>
      <dc:date>2008-05-10T00:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: Unblae to communicate on SFTP port (Port No 22) between diff</title>
      <link>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006073#M938134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;Yes, I'm manage to solve this issue. My client did not tell me that this is secondary IP address of that server. I have told them that its not possible to route on secondary IP and I have configured primary IP rule to allow SFTP rule.&lt;/P&gt;&lt;P&gt;Thanks for your great help...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 May 2008 07:55:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unblae-to-communicate-on-sftp-port-port-no-22-between-different/m-p/1006073#M938134</guid>
      <dc:creator>pannu3679</dc:creator>
      <dc:date>2008-05-10T07:55:52Z</dc:date>
    </item>
  </channel>
</rss>

