05-10-2007 01:27 AM - edited 03-11-2019 03:11 AM
Hello,
our customer has a problem with ftp protocol: when he try to GET-FTP from DMZ to INSIDE network after few seconds he received ftp broken pipe!
I have done several tests inserting the PERMIT IP ANY ANY rule but the problem has remained. the PIX was initially equipped with the release 6.3(3): I replaced it with release 6.3(5) as shown in the CSCeg52090 Bug but the problem remains.
Can you help me?
Thanks
Massimiliano
05-10-2007 02:54 AM
Check if he use Passive ftp or active FTP. and what client he is using, most client knows how to handle this automatically.
05-10-2007 09:51 AM
Hi,
we have done test using several ftp client in passive and active mode but the result is always "broken pipe"; further tests have been executed using the ftp directly from the DOS command .... After few seconds the FTP goes down.
Now I think that the only solution is upgrade to 7 software version; what do you think?
Thanks
Massimiliano
05-10-2007 10:15 AM
Could you post your configuration.
-Hoogen
05-10-2007 03:57 PM
are you using 'fixup protocol ftp strict' or without the 'strict'?
have you done any packet captures?
05-11-2007 12:32 AM
Hi,
I am using ftp without strict; when I put packet analyzer on Inside network I see TCP/IP RST PACKET with IP source FTP server after few ACK PACKET FROM FTP client to FTP server. When I put packet analyzer on DMZ network I have the same situation: ACK from FTP server and after RST packet from FTP client to FTP server. I don't think that there is TCP windows problem: when I excluded the pix and I execute ftp lan to lan there is not problem. What do you think?
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: