cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1627
Views
0
Helpful
3
Replies

ASA, Passive FTP (Explicit FTP with TLS) does not work.

morabusa
Level 1
Level 1

Hi,

I am having issues to make work a passive FTP server with explicit TLS encryption because ASA is blocking the response on a random port, even when I have enabled this configuration:

access-list ftp-list extended permit tcp any any gt 1000
!
class-map ftp-class
match access-list ftp-list
!
policy-map global_policy
class ftp-class
inspect ftp

Problem is that we are using explicit ftp with TLS encryption and this is probably the reason because the ASA is not able to inspect that traffic and block the connection. Do you know if there is a solution for this? Thanks!

3 Replies 3

balaji.bandi
Hall of Fame
Hall of Fame

passitve FTP with TLS you required 1 to 1023 ports - try that and let us know.

 

your ACL show  > 1000

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

I am seeing connection attempts to the ports 40XXX-6XXXX. Anyway, if traffic is encrypted, how the ASA could inspect it? Thanks!

rmathieson7
Level 1
Level 1

You're right the encryption will stop the ASA from seeing the packet and therefore won't be able to dynamically open the ports.  The passive FTP port range is configured on the server so you could contact whoever manages that, otherwise they tend to be within 49152-65535.  FTP isn't a nice protocol for security.

Review Cisco Networking for a $25 gift card