Solved

Port 990 FTPS , on cisco ASA firewall

Posted on 2009-05-11
3
2,706 Views
Last Modified: 2012-05-06
I have a Cisco ASA5520 firewall.

I have installed a FTPS server on a webserver and want to connect to it from within our network.

What is the command to allow everyone inside our network to connect to only this webserver via port 990

Have i got the correct command:

access-list inside_access_in extended permit tcp any host (WEB IP ADDRESS) eq 990


thanks

0
Comment
Question by:vconstantinou
3 Comments
 
LVL 7

Accepted Solution

by:
egyptco earned 500 total points
ID: 24353152
citation from cisco FAQ:

Q. Is FTP with TLS/SSL supported through the Security Appliance?

    A. No. In a typical FTP connection, either the client or the server must tell the other what port to use for data transfer. The PIX is able to inspect this conversation and open that port. However, with FTP with TLS/SSL, this conversation is encrypted and the PIX is unable to determine what ports to open. Thus, the FTP with TLS/SSL connection ultimately fails.

    One possible workaround in this situation is to use an FTP client that supports the use of a "clear comannd channel" while still using TLS/SSL to encrypt the data channel. With this option enabled, the PIX should be able to determine what port needs to be opened.
0
 
LVL 7

Expert Comment

by:willbaclimon
ID: 24358881
Also ftps usually needs return port ranges specified aswell
0
 

Expert Comment

by:nguovn
ID: 26298777
Can you show me the command to do "clear data channel" for ftps
Thanks,
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

Cisco Pix/ASA hairpinning The term, hairpinning, comes from the fact that the traffic comes from one source into a router or similar device, makes a U-turn, and goes back the same way it came. Visualize this and you will see something that looks …
When I upgraded my ASA 8.2 to 8.3, I realized that my nonat statement was failing!   The log showed the following error:     %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows It was caused by the config upgrade, because t…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now