03-26-2019 11:46 AM - edited 02-21-2020 08:59 AM
Hi everyone,
Very strange issue with FTP inspection on Cisco ASA5506-X (9.8(2)20). Passive mode works fine, BUT not for all files...
For example (look at screenshot), user can download any file (txt) except this one 34313622.210.
As you can see at screenshot, size of downloaded file 34313622.210 is incorrect.
In Passive mode all other files can be downloaded without problems. The same issue from time to time apears for others users in different folders. I've checked these files - simple txt files. I can open them without problems on FTP server (Filezilla FTP 0.9.55) for reading or editing.
If I try download the "incorect" file (34313622.210) in Active mode - everything works fine! The issue persists in Passive mode ONLY.
When connection drops in PASV mode I see count of droped packets is growing in ASA. Invalid EPSV format drop grows as well:
Could somebody tell me how to solve it?
My configuration is pretty simple. I did it using this guide.
Solved! Go to Solution.
03-26-2019 03:04 PM
i suggest you raise this with TAC , based on
https://quickview.cloudapps.cisco.com/quickview/bug/CSCso23893
even though you are not running this version. Also test with ftp inspection turned off
03-26-2019 03:04 PM
i suggest you raise this with TAC , based on
https://quickview.cloudapps.cisco.com/quickview/bug/CSCso23893
even though you are not running this version. Also test with ftp inspection turned off
05-15-2019 09:05 AM
03-27-2019 06:37 AM
03-27-2019 11:00 AM
This is IPv4 connection.
03-30-2019 03:44 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide