cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1045
Views
0
Helpful
7
Replies

FTP?

abhi-adte
Level 1
Level 1

hi,

I want to know if I have FTP Server and I want to configure something on firewall or Routers so Client or user have only read-only access to FTP server or user can not upload or download the data from FTP server??

2 Accepted Solutions

Accepted Solutions

Abhinay,

If you want the users to have only read-only permission on the ftp server then, this needs to be done on the ftp server. Firewall has no knowledge of whether you have read-only, full-control, change or write permission to a folder. All it knows is IP address and ports. If the acl allows it it will allow the connection.

Unless you are talking about strict ftp inspection where you can block certain ftp commands like mkdir, put can be dropped and reset when sent via ftp protocol via MPF (modular policy framework)

-KS

View solution in original post

Exactly.

What I'm saying is that an ''advanced'' Layer 7 Policy Map for FTP could include more detailed restrictions (application access) as to specify read-only or write-access, which commands are allowed, etc... (definitely not with an ACL).

You can check this here:

http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/inspect_basic.html#wp1810407

Federico.

View solution in original post

7 Replies 7

Hi,

The ASA can be configured with an FTP map to provide application inspection and instruct the ASA to allow only certain type of commands, and other restrictions.

This is creating a Layer 7 Policy MAP and class MAP for FTP.

Federico.

You are talking abt the FPM or MPF..??    

Well...

FPM is on IOS and MPF is either on IOS or ASAs.

Federico.

this is ok and good; but some one told me it can done via ACL so I tried but its not done from me if u get some thing about it pls share with me...

Abhinay,

If you want the users to have only read-only permission on the ftp server then, this needs to be done on the ftp server. Firewall has no knowledge of whether you have read-only, full-control, change or write permission to a folder. All it knows is IP address and ports. If the acl allows it it will allow the connection.

Unless you are talking about strict ftp inspection where you can block certain ftp commands like mkdir, put can be dropped and reset when sent via ftp protocol via MPF (modular policy framework)

-KS

Exactly.

What I'm saying is that an ''advanced'' Layer 7 Policy Map for FTP could include more detailed restrictions (application access) as to specify read-only or write-access, which commands are allowed, etc... (definitely not with an ACL).

You can check this here:

http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/inspect_basic.html#wp1810407

Federico.

Thanks to all...

Review Cisco Networking for a $25 gift card