cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
454
Views
0
Helpful
3
Replies

FTP on Non Standard Port - PIX 7 or higher

edw
Level 1
Level 1

Hi,

I'm having problems trying to get FTP working on sites with ports not 21 ? I have 2 FTP sites on my DMZ - FTP 21 works fine but FTP to say 1400 seems to fail IE doesn't get there.... logs show connectiong through PIX not being denied but then says TCP FIN entry ??

Any ideas?

I have tried removeing the inspection engine ?

Thanks

Ed

1 Accepted Solution

Accepted Solutions

kagodfrey
Level 3
Level 3

Hi Ed

You need the inspection engine, and you will also need to create a new class map for it. Take a look at:

http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/inspect.html#wp1383679

...which goes into some detail on allowing ftp on port 1056.

HTH

Regards

Kev

View solution in original post

3 Replies 3

kagodfrey
Level 3
Level 3

Hi Ed

You need the inspection engine, and you will also need to create a new class map for it. Take a look at:

http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/inspect.html#wp1383679

...which goes into some detail on allowing ftp on port 1056.

HTH

Regards

Kev

Hi,

Thanks for point in the right direction.

Ed

Hi,

Unfortantly I'm having problems. I understand the consept however when I try to put it into practise it fails.

So I have specified the access-list for it and assigned it to the new class. I have added this class to the policy global_default

Nothing has changed thou ???

Does anyone have example config with this theory in ?

Thanks

Ed

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card