Asa 5505 ftp port forwarding

I have a Cisco asa 5505 that will be connected to a T1. Please advise how to port forward ftp. Also, not sure if I have to use our public ip for the outside interface or create a network between the asa and the T1 hand off. Help!
Who is Participating?
harbor235Connect With a Mentor Commented:

I would configure a public address for the ASA outside interface, otherwise you will need to do NAT on the device that terminates the T-1.
To port forward on the ASA do the following;

global (outside) 1 interface
nat (inside) 0 access-list NONAT
nat (inside) 1 <inside_network>   (/24 assumed)
access-list NONAT <add entries here to prevent NAT'ng, i.e VPN traffic>

static (inside,outside) tcp interface ftp <inside_IP> ftp netmask
access-list outside permit tcp <source_address_for FTP> <mask> host <outside_ip_of_ftp_server> eq ftp

harbor235 ;}
the T1 would most likely be the outside IP.  you would create a small subnet between the T1 Router and the ASA- i.e. a  
the t1 being
the outside ASA being
unless the T1 requires PPPOE authentication.

you would forward ftp traffic on ports 20 and 21 to if using the 1st method.

if PPPOE or PPPOA then the port forward is not required, and the configuration is simpler.

on the ASA, you must permit the traffic from outside to inside using an access list, and then apply this to the outside interface.  you will also need a static nat statement for both port 20 and 21 as to the destination ip address on the inside network.

first - names:

name insideIP servername

then access list:
access-list ACLIN extended permit tcp any host eq ftp
access-list ACLIN extended permit tcp any host eq ftp-data

the static NAT
static (inside,outside) outsideIP ServerName netmask

apply the acl to the interface

access-group ACLIN in interface outside

ensure you have the route set

route outside next_hop_router 1

Use passive FTP and you only need the one port opened

Add this to your config.

ftp mode passive

harbor235 ;}
progonoskoAuthor Commented:
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.