09-19-2026 02:42 AM
On firewalls such as the Cisco ASA, is it sufficient to allow only port 21/tcp in order to permit FTP Active Mode data transfer?
Client → Server (21/tcp)
Server (20/tcp) → Client
If I allow port 21/tcp, will the system track the data connection and automatically allow the 20/tcp connection from the server as well?
Solved! Go to Solution.
09-19-2026 03:00 AM
Hi @CHISHIUNG,
the answer is yes if you have FTP application inspection active in the service policy that handles the flow.
Depending on the ASA configuration, the default global policy may already include the 'inspect ftp' statement but you need to check this.
HTH!
09-19-2026 03:00 AM
Hi @CHISHIUNG,
the answer is yes if you have FTP application inspection active in the service policy that handles the flow.
Depending on the ASA configuration, the default global policy may already include the 'inspect ftp' statement but you need to check this.
HTH!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide