Solved

ASA 5510 on FTP Downloads "The address translation slot was deleted."

Posted on 2011-02-28
4
1,945 Views
Last Modified: 2012-05-11
Hi,

I am putting a ASA5510 in front of a ISA Server 2004 with Websense and having a problem with downloading anything via FTP.

Here are my test results:
1) When I go out through a PC directly to the ASA I can download FTP files and all other web content.
2) When I go out through a PC directly to the ISA then out to the internet everything works fine.
3) When I go out through a PC directly to the ISA then through the firewall I can't download FTP files. All other web content works fine.

I receive the following errors from Test 3):

On ASA:

6      Feb 27 2011      23:31:51            172.20.2.100      20699      173.71.64.133      1538      Teardown dynamic TCP translation from inside:172.20.2.100/20699 to FIOS:x.x.x.x(my public IP)/1538 duration 0:00:30

I'm doing NAT on my ASA and apparently on my ISA. I believe this is the issue. The ASA has a public IP. Between the inside ISA  port and outside ASA port I have a private nework with the range 172.20.2.x. The inside network where the PC's reside and inside port of the ISA are on 10.35.208.x
0
Comment
Question by:First Last
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
4 Comments
 
LVL 1

Author Comment

by:First Last
ID: 34998918
Sorry - the ISA server is giving the following error on FTP downloads from IE:

ISA Server: extended error message :
200 Type set to I.
500 Illegal PORT Command

0
 
LVL 5

Expert Comment

by:torvir
ID: 34999273
You should try to turn on inspection of ftp-traffic in ASA.
If you have a global policy in tha ASA-config, just add "inspect ftp" to it.
Look for a command like "service-policy xxxx global" and add it there.

Here is how you add a global policy with ftp-inspection from scratch:

policy-map global_policy
 class inspection_default
  inspect ftp
service-policy global_policy global

0
 
LVL 1

Accepted Solution

by:
First Last earned 0 total points
ID: 35007153
The Websense ISA Server isn't supposed to be inline with the Cisco ASA. I found this article below that describes how to use the url filtering feature of the ASA to reach out to Websense.
0
 
LVL 1

Author Closing Comment

by:First Last
ID: 35045422
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
port redirection on cisco asa 5520 5 29
Syslog-ng works. Now what? How to filter and manage? 8 92
Cisco Switch VLAN voice and Data 2 42
Cisco VOIP Question 1 31
I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes. "site-to-site" …
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question