I am having issues to make work a passive FTP server with explicit TLS encryption because ASA is blocking the response on a random port, even when I have enabled this configuration:
access-list ftp-list extended permit tcp any any gt 1000
match access-list ftp-list
Problem is that we are using explicit ftp with TLS encryption and this is probably the reason because the ASA is not able to inspect that traffic and block the connection. Do you know if there is a solution for this? Thanks!
You're right the encryption will stop the ASA from seeing the packet and therefore won't be able to dynamically open the ports. The passive FTP port range is configured on the server so you could contact whoever manages that, otherwise they tend to be within 49152-65535. FTP isn't a nice protocol for security.