cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
260
Views
1
Helpful
1
Replies

Allowing FTP Active Mode

CHISHIUNG
Spotlight
Spotlight

On firewalls such as the Cisco ASA, is it sufficient to allow only port 21/tcp in order to permit FTP Active Mode data transfer?
Client → Server (21/tcp)
Server (20/tcp) → Client

If I allow port 21/tcp, will the system track the data connection and automatically allow the 20/tcp connection from the server as well?

1 Accepted Solution

Accepted Solutions

Hi @CHISHIUNG,

the answer is yes if you have FTP application inspection active in the service policy that handles the flow.
Depending on the ASA configuration, the default global policy may already include the 'inspect ftp' statement but you need to check this.

HTH!

View solution in original post

1 Reply 1

Hi @CHISHIUNG,

the answer is yes if you have FTP application inspection active in the service policy that handles the flow.
Depending on the ASA configuration, the default global policy may already include the 'inspect ftp' statement but you need to check this.

HTH!

Review Cisco Networking for a $25 gift card