I am putting a ASA5510 in front of a ISA Server 2004 with Websense and having a problem with downloading anything via FTP.
Here are my test results:
1) When I go out through a PC directly to the ASA I can download FTP files and all other web content.
2) When I go out through a PC directly to the ISA then out to the internet everything works fine.
3) When I go out through a PC directly to the ISA then through the firewall I can't download FTP files. All other web content works fine.
I receive the following errors from Test 3):
6 Feb 27 2011 23:31:51 172.20.2.100 20699 126.96.36.199 1538 Teardown dynamic TCP translation from inside:172.20.2.100/20699 to FIOS:x.x.x.x(my public IP)/1538 duration 0:00:30
I'm doing NAT on my ASA and apparently on my ISA. I believe this is the issue. The ASA has a public IP. Between the inside ISA port and outside ASA port I have a private nework with the range 172.20.2.x. The inside network where the PC's reside and inside port of the ISA are on 10.35.208.x