cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1061
Views
0
Helpful
2
Replies

FTP extended passive mode vs inspect

ROBERTO TACCON
Level 4
Level 4

Does the inspection on Cisco PIX or ASA os (7/8) support the FTP extended passive mode

http://en.wikipedia.org/wiki/Ftp

"In extended passive mode, the FTP server operates exactly the same as passive mode, however it only transmits the port number (not broken into high and low bytes) and the client is to assume that it connects to the same IP address that was originally connected to. Extended passive mode was added by RFC 2428 in September 1998."

Thanks in advance.

RT

2 Replies 2

Its supported in code 7.0 and later.

6.x code doesnt support it

Syed

What about IOS?

7201 with IOS c7200p-adventerprisek9-mz.150-1.M8.bin

Zone Based Firewall

match protocol ftp

inspect

Had to disable EPRT and EPSV on the server, but it's not good idea, all new ftp clients tend to prefer them.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card