05-10-2007 01:27 AM - edited 03-11-2019 03:11 AM
Hello,
our customer has a problem with ftp protocol: when he try to GET-FTP from DMZ to INSIDE network after few seconds he received ftp broken pipe!
I have done several tests inserting the PERMIT IP ANY ANY rule but the problem has remained. the PIX was initially equipped with the release 6.3(3): I replaced it with release 6.3(5) as shown in the CSCeg52090 Bug but the problem remains.
Can you help me?
Thanks
Massimiliano
05-10-2007 02:54 AM
Check if he use Passive ftp or active FTP. and what client he is using, most client knows how to handle this automatically.
05-10-2007 09:51 AM
Hi,
we have done test using several ftp client in passive and active mode but the result is always "broken pipe"; further tests have been executed using the ftp directly from the DOS command .... After few seconds the FTP goes down.
Now I think that the only solution is upgrade to 7 software version; what do you think?
Thanks
Massimiliano
05-10-2007 10:15 AM
Could you post your configuration.
-Hoogen
05-10-2007 03:57 PM
are you using 'fixup protocol ftp strict' or without the 'strict'?
have you done any packet captures?
05-11-2007 12:32 AM
Hi,
I am using ftp without strict; when I put packet analyzer on Inside network I see TCP/IP RST PACKET with IP source FTP server after few ACK PACKET FROM FTP client to FTP server. When I put packet analyzer on DMZ network I have the same situation: ACK from FTP server and after RST packet from FTP client to FTP server. I don't think that there is TCP windows problem: when I excluded the pix and I execute ftp lan to lan there is not problem. What do you think?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide