09-08-2010 01:27 PM - edited 03-11-2019 11:37 AM
Hello experts,
I have a 5520 and PASV FTP is working fine but ACTIVE FTP is not. I have enabled ftp inspection and I am actually seeing resets.
Service-policy: global_policy
Class-map: ESMTP-POLICY
Inspect: esmtp _default_esmtp_map, packet 0, drop 0, reset-drop 0
Class-map: inspection_default
Inspect: dns preset_dns_map, packet 1307204594, drop 5704127, reset-drop 0
Inspect: ftp, packet 4004288, drop 0, reset-drop 45
In the capture that I did in the OUTSIDE interface I am seeing NO problems with control channel however with the data channel Iam seeing problems. The Server tries to connect using port 20 to the client however in the next packet there is a reset from the ASA to the ftp server.
In the inside capture the packet from the server on port 20 to the client is never seeing so it's the ASA.
I have a ZBF in the inside however like I said the request from the server on port 20 to the client on port X is never seeing in the capture.
Why whould the FTP INSPECTION reset the connection?
Im not using any regex to reset connections or something similar that could be causing this behavior.
Please help.
09-08-2010 01:51 PM
Hi Diego,
Can you get simultaneous captures on either side of the ASA for a full FTP session? Also, you'll want to gather syslogs at the debug level during the FTP session.
-Mike
09-08-2010 01:59 PM
Ok I will get the logs I will keep you posted.
09-08-2010 03:11 PM
What code are you running mate?
You might want to enable debugging for ftp inspection - I *think* that this is debug ftp? (sorry I don't have a unit to hand), then check the logs, the ftp client might not be conforming to the RFC.
BTW - this is a total stab in the dark! And I've just seen that I pretty much written what Mike said above. Give that man some points :-)
cheers
09-09-2010 08:57 AM
tomorrow I will be able to do more troubleshooting thank u.
09-08-2010 04:04 PM
Hello,
From your description, it seems like the server is on the outside and the
client is on the inside. Do you have one-to-one NAT mapping for the client?
If it is not there, can you configure one-to-one static (IP-to-IP) and see
if the active FTP works?
Regards,
NT
09-09-2010 08:55 AM
Ok I will try with a one2one static to see wath happens.
Thank you very much.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide