04-29-2004 02:43 AM - edited 02-20-2020 11:22 PM
Hi, I have a Linux server that fetches a file via FTP from a server located on Internett. And each time my PIX sends a syslog message looking something like this:
Apr 29 12:25:43 10.0.0.1 %PIX-4-106023: Deny tcp src outside:129.242.28.57/21 dst inside:62.101.252.32/55198 by access-group "outside_access_in"
Why is the remote server trying to connect back to me?
04-29-2004 03:29 AM
ftp generally uses two connections at once - control commands and data.
what does you outside_access_in access list look like?
04-29-2004 04:17 AM
I have:
fixup protocol ftp 21
access-list outside_access_in permit tcp any interface outside eq www
access-list outside_access_in permit tcp any interface outside eq 6300
access-list outside_access_in permit tcp any interface outside eq 9000
access-list outside_access_in permit tcp any interface outside eq 5060
access-list outside_access_in permit tcp any interface outside eq 5004
access-list outside_access_in permit udp any interface outside eq 5060
access-list outside_access_in permit icmp any any unreachable
access-list outside_access_in permit icmp any any echo-reply
access-list outside_access_in permit icmp any any time-exceeded
I tought the fixup should take care of the return ports?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide