ftp passive mode

Answered Question
Oct 23rd, 2009
User Badges:

ASA 5505 Version 8.2(1)

Hi,

I have one PC that has to connect to public FTP in passive mode.

But if I understand right in pasive mode PC connects

to randomally data port of server.

What do I have to specify in confoguration of ASA 5505:

Open for PC all ports of specified FTP address

or to give range of data ports that server assigns randomally.


Correct Answer by Patrick0711 about 7 years 6 months ago

Enable the FTP inspection in the global policy-map. This will dynamically open the PASV port ranges will NAT the PASV IP to it's public counterpart if necessary.


With this configuration, you will only need to open port 21 inbound for each host that is to connect via FTP.


policy-map global_policy

class inspection_default

inspect ftp



This link explain the fixup protocol


http://www.ciscopress.com/articles/article.asp?p=24685

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
Patrick0711 Fri, 10/23/2009 - 19:54
User Badges:
  • Bronze, 100 points or more

Enable the FTP inspection in the global policy-map. This will dynamically open the PASV port ranges will NAT the PASV IP to it's public counterpart if necessary.


With this configuration, you will only need to open port 21 inbound for each host that is to connect via FTP.


policy-map global_policy

class inspection_default

inspect ftp



This link explain the fixup protocol


http://www.ciscopress.com/articles/article.asp?p=24685

Actions

This Discussion