11-07-2006 02:26 PM - edited 02-21-2020 01:17 AM
I am experiencing intermittant FTP through an ASA 5500 running 7.2(2). Has anyone seen this issue or heard of it. no changes are being made to the firewall access-list during this time. Counters on the ACLs only go up occasionally when FTP is working on both 20 data and 21 control ports.
02-05-2007 07:16 AM
Did you ever find out an answer? I am experiencing similar problems.
02-26-2007 07:41 AM
Hi Guys,
How did you get on with this?
I'm not sure if our problem is similar. Basically we have a client who has some scripts running on an internal machine which downlods updates from an external site via ftp. Since upgrading from the pix to ASA (using various versions of software, currently on 7.2(2) the ftp via command prompt hangs. Where as ftp via a browser works okay.
02-27-2007 06:25 AM
TAC was not able to determine the problem, but we found a work around. Basically, we had to shut off protocol inspection for the AS400 FTP sessions and then permit it for everyone else.
02-27-2007 02:15 PM
Yep we did that and it worked. we also have upgraded the s/w due to another bug.
02-28-2007 08:30 AM
Would you mind posting the portion of your config regarding bypassing the specific traffic, the policy map, and service policy? I spoke too soon when I said it was fixed. Thanks.
My issue is that even though I specifically say that only one subnet should get inspected via class-map and ACL, it appears that everything is still being inspected.
02-28-2007 11:17 PM
Hi Guys,
Our next plan of attack is to try the following:
http://www.ciscotaccc.com/security/showcase?case=K35419735
We'll let you know how it goes.
03-15-2007 10:39 AM
Wow,
We have the exact problem (upgrade to ASA from PIX) but the ftp connection is made, it's only when the user does a list (ls) on the remote system that their session gets terminated (RST-O)
We have another egress point still using a PIX so we tried the same thing and it works fine.
The big difference with ours is we have an SSM and our policy map directs all traffic to it, so I originally thought it was the IPS module, but now by what I'm reading, it's the ASA.
I'm going to open a TAC case on this as it seems to be rampant so they should get it fixed.
Bob
03-21-2007 01:06 PM
Did this work?
We're having this issue, too, and I haven't been able to solve it.
03-15-2007 10:57 AM
Hi,
I just saw on another thread in this forum the same issue that was blamed on the Microsoft CLI Ftp client not really going into passive mode when you set it. It still uses active.
I tested with a "real" ftp client and FTP works properly every time.
I hope this helps...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide