DMZ configuration in ASA

Unanswered Question
Sep 15th, 2008
User Badges:

hi, i have configured DMZ zone in my ASA 5550 version 7.1(2). The configuration for DMZ is as follow.

access-list outside_int extended permit tcp any host XX.XX.XX.9 eq ftp

static (inside,DMZ) 30.30.30.0 30.30.30.0 netmask 255.255.255.252

static (DMZ,outside) XX.XX.XX.9 10.5.0.5 netmask 255.255.255.255

static (DMZ,inside) XX.XX.XX.9 10.5.0.5 netmask 255.255.255.255

access-group outside_int in interface outside

It was working fine for two days, suddenly the users starts complaining about their FTP sessions. when i try to ping FTP server it reply with 50-100ms, before that it reply with < 1ms. I remove that FPT server and plug in my laptop to the DMZ zone to check the response time, it also reply with 50-100 ms delay. Now when i try to upload from inside to my FTP server in DMZ zone, it starts uploading but after 5-6% of uploading it gives error messages "[9/15/2008 2:01:38 PM] Child transfer failed." and when i try to upload file < 1 Mb , it is uploaded.

Need help please.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
mvsheik123 Mon, 09/15/2008 - 11:33
User Badges:
  • Gold, 750 points or more

Hi,


This may not be the exact reason, but...

static (inside,DMZ) 30.30.30.0 30.30.30.0 netmask 255.255.255.252

is netmask is not 255.255.255.0..?


Also, please post the configs, that might help in t-shooing the issue.


Thanks

MS



Actions

This Discussion