08-22-2008 08:36 AM
Whats the equivalent of application ftp-control command in ACE configuration. I have a user whose passive ftp is not working. The firewall is allowing passive ports.
08-22-2008 08:51 AM
ftp inspect.
You need something in line with the following config
class-map match-all FTP-Traffic
2 match port tcp eq ftp
policy-map multi-match xyz
class FTP-Traffic
inspect ftp
Syed Iftekhar Ahmed
08-22-2008 10:34 AM
what does inspect ftp command do for me. can u explain it in detail?
08-22-2008 11:06 AM
Same as in any state full firewall FTP Inspect analyzes the PASSIVE MODE command to find out what the negotiated inbound port is, and automatically 'opens' this port from the FTP client through the ACE to the FTP Server.
You can alos use strict feature of ftp inspect to filter out specific control commands
Syed
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide