cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
177
Views
0
Helpful
1
Replies

DMZ configuration in ASA

itdsmartnet
Level 1
Level 1

hi, i have configured DMZ zone in my ASA 5550 version 7.1(2). The configuration for DMZ is as follow.

access-list outside_int extended permit tcp any host XX.XX.XX.9 eq ftp

static (inside,DMZ) 30.30.30.0 30.30.30.0 netmask 255.255.255.252

static (DMZ,outside) XX.XX.XX.9 10.5.0.5 netmask 255.255.255.255

static (DMZ,inside) XX.XX.XX.9 10.5.0.5 netmask 255.255.255.255

access-group outside_int in interface outside

It was working fine for two days, suddenly the users starts complaining about their FTP sessions. when i try to ping FTP server it reply with 50-100ms, before that it reply with < 1ms. I remove that FPT server and plug in my laptop to the DMZ zone to check the response time, it also reply with 50-100 ms delay. Now when i try to upload from inside to my FTP server in DMZ zone, it starts uploading but after 5-6% of uploading it gives error messages "[9/15/2008 2:01:38 PM] Child transfer failed." and when i try to upload file < 1 Mb , it is uploaded.

Need help please.

1 Reply 1

mvsheik123
Level 7
Level 7

Hi,

This may not be the exact reason, but...

static (inside,DMZ) 30.30.30.0 30.30.30.0 netmask 255.255.255.252

is netmask is not 255.255.255.0..?

Also, please post the configs, that might help in t-shooing the issue.

Thanks

MS

Review Cisco Networking products for a $25 gift card