Active FTP NOT WORKING

Unanswered Question
Sep 8th, 2010

Hello experts,

I have a 5520 and PASV FTP is working fine but ACTIVE FTP is not. I have enabled ftp inspection and I am actually seeing resets.

Service-policy: global_policy

    Class-map: ESMTP-POLICY

      Inspect: esmtp _default_esmtp_map, packet 0, drop 0, reset-drop 0

    Class-map: inspection_default

      Inspect: dns preset_dns_map, packet 1307204594, drop 5704127, reset-drop 0

      Inspect: ftp, packet 4004288, drop 0, reset-drop 45

In the capture that I did in the OUTSIDE interface  I am seeing NO problems with control channel however with the data channel Iam seeing problems. The Server tries to connect using port 20 to the client however in the next packet there is a reset from the ASA to the ftp server.

In the inside capture the packet from the server on port 20 to the client is never seeing so it's the ASA.

I have a ZBF in the inside however like I said the request from the server on port 20 to the client on port X  is never seeing in the capture.

Why whould the FTP INSPECTION reset the connection?

Im not using any regex to reset connections or something similar that could be causing this behavior.

Please help.

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
mirober2 Wed, 09/08/2010 - 13:51

Hi Diego,

Can you get simultaneous captures on either side of the ASA for a full FTP session? Also, you'll want to gather syslogs at the debug level during the FTP session.

-Mike

golly_wog Wed, 09/08/2010 - 15:11

What code are you running mate?

You might want to enable debugging for ftp inspection - I *think* that this is debug ftp? (sorry I don't have a unit to hand), then check the logs, the ftp client might not be conforming to the RFC.


BTW - this is a total stab in the dark! And I've just seen that I pretty much written what Mike said above. Give that man some points :-)

cheers

Nagaraja Thanthry Wed, 09/08/2010 - 16:04

Hello,

From your description, it seems like the server is on the outside and the

client is on the inside. Do you have one-to-one NAT mapping for the client?

If it is not there, can you configure one-to-one static (IP-to-IP) and see

if the active FTP works?

Regards,

NT

Actions

This Discussion