Hi all,
We just replaced our pix 520 with 6.3 with a ASA running 7.02.
We experienced a lot of problems with FTP connections.
I had to allow source port's 20 and 21, on top of the normal rule who allows port 21.
The control channel was no problem, but the data channel could not be set up.
Still after this rules some ftp connections could not be set up.
Now we also added "inspect protocol ftp 21".
Since we allowed this, all seems to work fine. But I still want to get rid of the source port's who are still open.
Anyone seen this before?