06-07-2019 05:54 AM
I have a server on my DMZ that runs a service on FTP.
I do not have an access-list permitting traffic from outside to the DMZ on ftp.
FTP is not inspected on the global policy
But the FTP service is accessible from the outside network.
Is there any reason? and how can this be stopped.
Also note an access list has been configured to deny, however it still persist.
06-07-2019 01:12 PM
Is this a publicly accessible server that sits on the DMZ via NAT?
We would really need to see some config otherwise it would all be guess work.
Some questions..
What are the security levels on the interfaces?
You mention a deny ACL also.
Does this reference real/mapped address if NATd?
What interface and what direction is the ACL applied.
Most helpful would be source / destination IP and config output.
06-08-2019 12:29 AM
06-08-2019 11:17 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide