Syed Iftekhar Ahmed Fri, 08/22/2008 - 08:51
User Badges:
  • Blue, 1500 points or more

ftp inspect.


You need something in line with the following config


class-map match-all FTP-Traffic

2 match port tcp eq ftp


policy-map multi-match xyz

class FTP-Traffic

inspect ftp


Syed Iftekhar Ahmed

kirit_patel Fri, 08/22/2008 - 10:34
User Badges:

what does inspect ftp command do for me. can u explain it in detail?

Syed Iftekhar Ahmed Fri, 08/22/2008 - 11:06
User Badges:
  • Blue, 1500 points or more

Same as in any state full firewall FTP Inspect analyzes the PASSIVE MODE command to find out what the negotiated inbound port is, and automatically 'opens' this port from the FTP client through the ACE to the FTP Server.


You can alos use strict feature of ftp inspect to filter out specific control commands


Syed

Actions

This Discussion