Open Passive FTP Connection through Cisco ASA5520 Firewall

plokij5006
plokij5006 used Ask the Experts™
on
I am looking for help to allow members of our LAN to access passive FTP connections through a Cisco ASA5520 Firewall. The main issue i have is that i don't speak Cisco at all. I long for a web interface but alas no. If anyone can help point me in the right direction. Here is some information that i hope is relevant.

WAN port is called    Example_Outside
LAN port is called      Example_Inside

If it can be done using network-object and access-list i would be very grateful. I would even be delighted to get this to work on a single PC with IP address 192.168.45.234

Thank you
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Commented:
Please add ftp to the inspection list, using either ASDM or the console.

policy-map global_policy
 class inspection_default
   inspect ftp

HTH,
Dan
kevinhsiehNetwork Engineer

Commented:
I suggest you use ASDM for ASA management. So much easier for managing security rules, network groups, nested network groups, etc. Cisco routers and switches I use CLI, but ASDM GUI for ASA firewall.
Top Expert 2014

Commented:
Dan's comment is spot on.  The only issue you may have is if you are using encrypted ftp (ftp-ssl).  Since the session is encrypted the ASA can't inspect the commands.  If the server supports the CCC command, after you login you can issue it.  That will cause all commands to be sent in clear text so the ASA can inspect.

If the server does not support the CCC command, then you need to find out what port range the server uses for passive ftp connections and then setup a rule that allows outbound tcp packets destine to the server within that port range.
Ensure you’re charging the right price for your IT

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Hello

I have added

policy-map global_policy
 class inspection_default
   inspect ftp

unfortunately no change. The connection isn't encrypted. The outbound connection is fine, it's the return, it is unable to retrieve the directory listing.

Thank you for the suggestions of setting up ASDM but on a firewall of this age the spec of the PC required is XP and NOT patched with an old version of firefox - Ok to do but not an option as i am remote.

Commented:
1. Can you please post the result of the following command, obfuscating the real IPs?

sho run


2. ASDM is a Java app. It runs on Win XP - Win 10. No Firefox required.
kevinhsiehNetwork Engineer

Commented:
I use ASDM on Windows 8.1 and Windows 10 using current version of Java just fine. I don't even have Firefox.

Author

Commented:
Thank you again for the replies. here is the output requested
xxxxxxFWGW.txt
Top Expert 2014

Commented:
What FTP client are you using to test with?  The ftp client that comes with Windows only supports active FTP.

Is there away you can run a packet capture to verify what the client is sending out and what the server is returning?  To do this you will need to run the capture in  front of the firewall on the firewall.

Author

Commented:
Closing down ticket - we never got a solution.
Awarding points to Dan, for the most in-depth resposnes.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial