Solved

Enabling FTPS/PORT990 on Cisco ASA

Posted on 2012-03-14
2
1,506 Views
Last Modified: 2012-06-01
Im having a problem enabling FTPS/Port 990 on my Cisco ASA 5520
0
Comment
Question by:cisco_pro30
2 Comments
 

Author Comment

by:cisco_pro30
ID: 37720283
Here is what my policy map has in it.  



!
policy-map global_policy
 class inspection_default
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect netbios
  inspect rsh
  inspect rtsp
  inspect skinny
  inspect sqlnet
  inspect sunrpc
  inspect tftp
  inspect sip
  inspect xdmcp
  inspect pptp
!
0
 
LVL 6

Accepted Solution

by:
alienXeno earned 500 total points
ID: 37736622
In plain FTP, the firewall can inspect the control channel and hence it knows the port details of the data channel that is going to get established from the ftp server to the client.

This will enable the firewall to automatically open the data channel ports.

In FTPS, even the control channel traffic is encrypted, so the firewall can no longer inspect the details exchanged over the control port and hence the data channel connection attempt will fail.


Also , check http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_qanda_item09186a00805b87d8.shtml#q13
 

For this to work.

Create rules in your firewall as follows

 

1) Allow Any to FTPS server on port 990.

2) Allow FTPS Server port 989 to any.

 

This should allow the data channel tcp session to get established.
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
How to configure this in fortinet firewall 2 65
Sonicwall TZ 190 2 22
VLAN Question 13 44
Another machine has a duplicate ip? 11 27
A few customers have recently asked my thoughts on Password Managers.  As Security is a big part of our industry I was initially very hesitant and sceptical about giving a program all of my secret passwords.  But as I was getting asked about them mo…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question