cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2990
Views
5
Helpful
3
Replies

Upgrade of FMC to 6.1 breaks my FTP

hoffa2000
Level 3
Level 3

Hi

I made a transition of my virtual FMC from 5.4 to 6.1 but kept 5.4.x on my ASA Firepower for a while. Nothing has changed in the rule set while I upgraded from 5.4 to 6.1 but the day after I applied the 6.1 config to my Firepower modules I started getting reports of broken FTP transfers.

It's a passive FTP transfer between two servers on two different subnets inspected by ASA Firepower. The ASA log reports the file has been stored on the receiving server but the sending application reports a transfer error and only half the file is in fact stored.

If I omit the flow from Firepower all together the FTP works. I've tried a few Firepower rules with or without IPS, file inspection and plain "allow all" but nothing works.

I am still using the old ASA FTP inspection services which I suspect is interfering. What do you folks think?

Edit: I've done some trial and erroring and it seems the ASA FTP inspections has no effect, it's all about the Firepower. If I create a Trust rule for the specific flow the FTP transfer works. Allow with or without IPS, File inspection or any other features breaks the transfer.

Regards

Fredrik

1 Accepted Solution

Accepted Solutions

Alex Sierra
Level 1
Level 1

I opened a TAC case and the only workaround is putting a trust rule for that FTP server. The other two options are not viable.

Here is the bug:

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvb55994

View solution in original post

3 Replies 3

Oliver Kaiser
Level 7
Level 7

Hi Fredrik,

This is a known bug. I have experienced the same issue using FTD 6.1. The bug is currently not customer visible

kind regards

Oliver

Alex Sierra
Level 1
Level 1

I opened a TAC case and the only workaround is putting a trust rule for that FTP server. The other two options are not viable.

Here is the bug:

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvb55994

clive.hodgetts
Level 1
Level 1

Hi, as mentioned the bug is not public even with a valid CCO. Could you confirm if the issue is fixed by upgrading to 6.2 or 6.2.2?

 

Might save me logging it out to TAC

Review Cisco Networking for a $25 gift card