Cisco ASA incoming FTP connections problem when "inspect" IS enabled.

Hi All.

We have a Cisco ASA 5505 providing security for 2x servers in a data-centre. The servers behind the firewall both host FTP servers of their own and connect outbound to other FTP servers.

First problem we had was FTP from the internet to the servers was not working. We got rid of the "inspect ftp" statement - and all was fine. This unfortunatly causes problems with FTP connects these servers make to other servers out on the internet.

Any advise would be apprechiated.


Cheers,
SynergyWorksAsked:
Who is Participating?
 
SynergyWorksConnect With a Mentor Author Commented:
For us a change of FTP server software seemed to work. I guess it was crap software not doing what it should and upsetting the firewall.
0
 
SynergyWorksAuthor Commented:
Hi.

I have re-enabled inspect FTP and this gives me working FTP out to the internet... and allows clients to connect to our servers using active FTP only. Passive fails.

How the heck do we get passive to go through this ASA 5505? I have enabed the FTP servet to use Passive ports 32000 > 33000 and forwarded these in the ASA.


Cheers,

Rob
0
 
2PiFLCommented:
In addition to the above;

(config)#ftp mode passive
0
Managing Security Policy in a Changing Environment

The enterprise network environment is evolving rapidly as companies extend their physical data centers to embrace cloud computing and software-defined networking. This new reality means that the challenge of managing the security policy is much more dynamic and complex.

 
SynergyWorksAuthor Commented:
ftp mode passive is already present :(

Note: If I remove the 'inspect ftp' statement - all works fine (Passive & Active) but the servers then can't access other FTP sites out on the internet. It fails at the port command.
0
 
naughtonCommented:
have you permitted both ftp and ftp-data into the firewall>
0
 
SynergyWorksAuthor Commented:
Yup.

If I remove "inspect ftp" statement... all works fine... (passive and active ftp to our server) but I need to keep that statement so us downloading things from the internet (ISO mirrors etc) still works.


Cheers,
0
 
bkrontzCommented:
I'm having the same issues. Ugh.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.