Cisco ASA 5505 firewall - how to open ports for FTP client?

For years, I used XP Pro and the command line to send files to an FTP server. Recently, I changed to Windows 7 Pro and also introduced a Cisco ASA 5505 firewall appliance- both on the client side.  Now it fails, and I don't know which change is causing the problem (O/S? or firewall?).

Nothing has changed on the server end.

On the client end, the results are the same with Windows Firewall disabled.

From the Win7 command line, I can connect, but all attempts to send will end with "Connection closed by remote host." This is true using PASV mode, too.

If I use Filezilla GUI on the same PC, I can connect and send files.

On a different PC, a Win7 PC at my house, with no ASA, I can successfully connect AND send. This makes me suspect the ASA, rather than Windows.

However, the fact that Filezilla works (with the ASA in place) tends to suggest that the open ports on the ASA are NOT the problem.

http://www.mdjnet.dk/ftp.html - shows that FTP client needs 2-way data flow.  (refer to case#3 and case#4 if interested)

How can Filezilla succeed while command line FTP fails on the same PC, behind the same firewall? Is the Windows command line FTP using different ports than Filezilla client?

Is it just a matter of opening port 20 and 21 to everything outside and everything inside? What's the syntax for that on the ASA?

Thanks for reading.
oakie22Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

giltjrCommented:
0
oakie22Author Commented:
I don't know if I have the right settings in my firewall.

How can FileZilla be working if the required ports are not open?
0
giltjrCommented:
Filezilla supports both active and passive data transfers.

The MS supplied command line ftp only support active data transfers.

It's possible you have eveything setup to support passive, but not active.

For active you need to allow inbound traffic to any high port, with a source port of 20.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Networking

From novice to tech pro — start learning today.