Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1128
  • Last Modified:

Having trouble getting FTP to work on PIX 501

I have a newly installed PIX 501 that is working (finally).  The last thing I'm having trouble with is ftp.  I use port 2121 for ftp.  When I ftp i get prompted for username and password.  I enter in the information and then get an error that says "the connection with the server was reset"  I have tried this with passive on, and with passive off.  Still the same message.  I'm running kiwi syslog and this is the output.

Aug 11 2004 10:53:39: %PIX-6-302010: 8 in use, 27 most used
Aug 11 2004 10:52:19: %PIX-6-302014: Teardown TCP connection 3022 for outside:218.168.181.179/2093 to inside:192.168.1.10/4899 duration 0:00:01 bytes 56 TCP FINs
Aug 11 2004 10:52:18: %PIX-6-302013: Built inbound TCP connection 3022 for outside:218.168.181.179/2093 (218.168.181.179/2093) to inside:192.168.1.10/4899 (24.1.36.238/4899)
Keep-alive message
Aug 11 2004 10:48:10: %PIX-6-305012: Teardown static TCP translation from inside:192.168.1.10/2121 to outside:24.1.36.238/2121 duration 0:01:05
Aug 11 2004 10:48:07: %PIX-6-302014: Teardown TCP connection 3020 for outside:66.147.170.99/50410 to inside:192.168.1.10/2121 duration 0:00:50 bytes 243 TCP FINs
Aug 11 2004 10:47:39: %PIX-6-106015: Deny TCP (no connection) from 66.147.170.99/50411 to 24.1.36.238/2121 flags PSH ACK  on interface outside
Aug 11 2004 10:47:28: %PIX-6-106015: Deny TCP (no connection) from 66.147.170.99/50411 to 24.1.36.238/2121 flags PSH ACK  on interface outside
Aug 11 2004 10:47:22: %PIX-6-106015: Deny TCP (no connection) from 66.147.170.99/50411 to 24.1.36.238/2121 flags PSH ACK  on interface outside
Aug 11 2004 10:47:19: %PIX-6-106015: Deny TCP (no connection) from 66.147.170.99/50411 to 24.1.36.238/2121 flags PSH ACK  on interface outside
Aug 11 2004 10:47:18: %PIX-6-106015: Deny TCP (no connection) from 192.168.1.10/2121 to 66.147.170.99/50411 flags PSH ACK  on interface inside
Aug 11 2004 10:47:18: %PIX-6-106015: Deny TCP (no connection) from 66.147.170.99/50411 to 24.1.36.238/2121 flags PSH ACK  on interface outside
Aug 11 2004 10:47:17: %PIX-6-302014: Teardown TCP connection 3021 for outside:66.147.170.99/50411 to inside:192.168.1.10/2121 duration 0:00:01 bytes 271 Deny
Aug 11 2004 10:47:17: %PIX-4-406002: FTP port command different address: 66.147.170.99(192.168.101.130) to 192.168.1.10 on interface outside
Aug 11 2004 10:47:17: %PIX-6-302013: Built inbound TCP connection 3021 for outside:66.147.170.99/50411 (66.147.170.99/50411) to inside:192.168.1.10/2121 (24.1.36.238/2121)
Aug 11 2004 10:47:16: %PIX-6-302013: Built inbound TCP connection 3020 for outside:66.147.170.99/50410 (66.147.170.99/50410) to inside:192.168.1.10/2121 (24.1.36.238/2121)
Aug 11 2004 10:47:06: %PIX-6-302014: Teardown TCP connection 3019 for outside:66.147.170.99/50390 to inside:192.168.1.10/2121 duration 0:00:01 bytes 137 TCP FINs
Aug 11 2004 10:47:05: %PIX-6-302014: Teardown TCP connection 3018 for outside:66.147.170.99/50389 to inside:192.168.1.10/2121 duration 0:00:01 bytes 137 TCP FINs
Aug 11 2004 10:47:05: %PIX-6-302013: Built inbound TCP connection 3019 for outside:66.147.170.99/50390 (66.147.170.99/50390) to inside:192.168.1.10/2121 (24.1.36.238/2121)
Aug 11 2004 10:47:05: %PIX-6-302013: Built inbound TCP connection 3018 for outside:66.147.170.99/50389 (66.147.170.99/50389) to inside:192.168.1.10/2121 (24.1.36.238/2121)
Aug 11 2004 10:47:05: %PIX-6-305011: Built static TCP translation from inside:192.168.1.10/2121 to outside:24.1.36.238/2121


Thanks to anyone that can help

0
RayDoran
Asked:
RayDoran
  • 3
  • 2
1 Solution
 
grbladesCommented:
Hi RayDoran,
> Aug 11 2004 10:47:17: %PIX-6-302014: Teardown TCP connection 3021 for
> outside:66.147.170.99/50411 to inside:192.168.1.10/2121 duration 0:00:01
> bytes 271 Deny
> Aug 11 2004 10:47:17: %PIX-4-406002: FTP port command different address:
> 66.147.170.99(192.168.101.130) to 192.168.1.10 on interface outside

From where are you testing the ftp server?
Are you testing it from a machine directly connected to the Internet?
You know you cannot test it from another machine behind the same PIX?
0
 
RayDoranAuthor Commented:
I'm at the office connecting back to the house.  I turned off passive, and directed it back to port 21 and its working.  I think it might be the settings in the ftp server.  
0
 
grbladesCommented:
Could it be a firewall issue at work?
0
 
RayDoranAuthor Commented:
I dont think so because it was working fine before i installed the PIX at the house.  I did test something.  I was able to login to the ftp server and look at the files.  I was even able to download some files, but when I try to upload it wants me to enter in username and password again and again and again.........  It will never upload the file.  I started and ftp program (flashfxp) and was able to upload and download just fine.  Not sure what the deal is??
0
 
grbladesCommented:
I can't see how the PIX could be causing that as you can connect and establish a data connection. Can you turn on logging on the ftp server so you can see all the commands and responses to it.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

  • 3
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now