01-30-2007 03:21 AM - edited 03-11-2019 02:25 AM
We have a problem with running FTP through the PIX, either in active or passive modes.
We have a fixup running for ftp on 21, the pix sits behind a perimeter router, and I have checked that it is not an ACL on it that is causing the issue.
We are using PAT and internal DNS on the inside. We have external DNS for our external IP addresses.
I have seen this article on the Cisco site the error I see is the same but I get a resolve on my IP
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094459.shtml
Anyone any ideas what the problem could be.
01-30-2007 04:03 AM
Hi,
On the Same URL, it has been mentioned that if you are having the same symptoms, and if you are able to get DNS resolution for your ip, then the reason might be due to IDENT protocol.
Here's the URL on troubleshooting this issue.
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094317.shtml
Have you looked at it already...
-VJ
01-30-2007 08:40 AM
I saw that and didn't think it applied, although I did try to add service resetinbound
As for the other step adding the establised permitto 113 will not fly
Maybe it is another issue not related to this article. The problem I see is connections being made sucessfully then at some point during the tranfer it fails.
Below is a log that shows the active connections on 21, the 10.7.48.36 is my address, anyone any idea what the UFRIO section means?
PIX# show conn protocol tcp fport 21
TCP out 72.3.236.219:21 in 10.7.48.36:1082 idle 0:03:21 Bytes 1299 flags UFRIO
TCP out 72.3.236.219:21 in 10.7.48.36:1081 idle 0:04:02 Bytes 227 flags UFRIO
TCP out 88.46.254.34:21 in 10.10.17.30:3343 idle 0:00:00 Bytes 41488 flags UIO
01-30-2007 10:00 AM
Add the detail keyword to the end of your show conn command.
01-30-2007 08:22 PM
Hi,
Thanks for the update.
Refer to the Table 25-10 provided in this URL, for detailed explanation on the connection flags that you observe in the "show conn" output.
From the capture that you have provided, it appears that the outside FTP server is sending a "FIN", which indicates that the server is closing the TCP connection for some reason.
You need to check with the owner of that FTP server to investigate the root cause for why the server is closing the connection.
To augment your observation, you can take a sniffer/ethereal trace from your inside FTP client. In this trace, you will observe that the server is sending a TCP reset packet, indicating a closure of connection.
Provide this capture to FTP server admin and request for an explanation.
Hope this helps.
-VJ
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide