FTP troubles

Unanswered Question
Jan 14th, 2010
User Badges:

Dear ALL,


I'm going to show to all of you a problem concerning file transfer that involves a Cisco PIX 515E 6.3 (4), an  ftp server (SERV-U) and a client side.


Client side is composed of an automatic procedure  (in order to download files) running on a Windowx XP and an ISA Server 2000.


Every 5 file transfer, at least 2 fail with this kind of error:


from ftp server side


Error sending file customer-file.txt, aborting (0 bytes/sec - 0 bytes, unable to open data connection)


and from PIX side


%PIX-6-303002:  Customer Public IP Retrieved FTP Server Public IP:customer-file.txt
%PIX-4-106023:  Deny tcp src inside:FTP Server Private IP/20 dst outside:Customer Public IP /4198 by access-group "acl-outbound"



.........................................but, there is not any acl-outbound denying that kind of traffic



Please, anyone of experienced that kind of trouble?



                                           Regards


                                           Alberto Brivio

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
albertobrivio42 Fri, 01/15/2010 - 00:22
User Badges:

Hi,



the ACE concerning the problem are:


access-list acl-inbound permit icmp any any                               first line
access-list acl-inbound permit tcp any host A.B.C.D eq ftp
access-list acl-inbound deny ip any any                                     last line


access-list acl-outbound permit icmp any any                             first line
access-list acl-outbound permit tcp 192.168.0.0 255.255.255.0 any eq ftp
access-list acl-outbound deny ip any any                                    last line


moreover there is the following line


fixup protocol ftp 21

Ganesh Hariharan Fri, 01/15/2010 - 01:12
User Badges:
  • Purple, 4500 points or more
  • Community Spotlight Award,

    Member's Choice, February 2016

Hi Alberto,


Following can be the reasons which has resulted the below issue in pix for ftp communication:-


eny protocol src [interface_name:source_address/source_port]
dst interface_name:dest_address/dest_port [type {string}, code {code}] by access_group
acl_ID

Explanation: An IP packet was denied by the ACL. This message displays even if
you do not have the log option enabled for an ACL.

Recommended Action: If messages persist from the same source address, messages
could indicate a foot printing or port scanning attempt. Contact the remote host
administrators.

FTP connection from src_ifc:src_ip/src_port to  dst_ifc:dst_ip/dst_port,
user username action file filename

Explanation: This event is generated whenever a client uploads or downloads a
file from the FTP  server. src_ifc The interface where the client resides. src_ip The
IP address of the client. src_port The client port. dst_ifc The interface where
the server resides. dst_ip The IP address of the FTP server. dst_port The server
port. username The FTP username. action The stored/retrieved actions. filename The
file stored or retrieved.

Recommended Action: None.

FTP connection from src_ifc:src_ip/src_port to dst_ifc:dst_ip/dst_port,
user username action file filename

Explanation: This event is generated whenever a client uploads or downloads a
file from the FTP  server. src_ifcThe interface where the client resides. src_ipThe
IP address of the client. src_port The client port. dst_ifc The interface where
the server resides. dst_ip The IP address of the FTP server. dst_port The server
port. username The FTP username. action The stored/retrieved actions. filename The
file stored or retrieved.

Recommended Action: None.

HTH

Regards
Ganesh.H



albertobrivio42 Mon, 01/18/2010 - 07:56
User Badges:

I'm going to upgrade pix on next days.


Just for info for all people reading thread,  removing access-list controlling traffic from inside to outside, problem disappears.



                                                                               Regards


                                                                               Alberto Brivio

Actions

This Discussion