cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
414
Views
0
Helpful
2
Replies

Allowing Passive FTP connections on the ASA5540

kduckett
Level 1
Level 1

I am attempting to establish an FTP connection with an outside vendor FTP

server in order to download software patches. The vendor's FTP server switches to Passive FTP mode which means my client has to reconnect to the server using high ports for both the source and destination. The only way that I have found to get the connection to work is to

configure an ACE on my Inside interface ACL that allows an "any to any" connection using tcp ports >1023. To me, this causes a conflict with my security policies as any other connection, to a potentially malicious server, can be created.

What is the recommended way to get Passive FTP to work without compromising security? I have FTP mode passive enabled on the ASA and also have FTP Passive enabled within my

browser.

Thanks,

Keith

1 Accepted Solution

Accepted Solutions

cisco24x7
Level 6
Level 6

"fixup protocol ftp 21".

That will fix your problem without compromising security.

Easy right?

View solution in original post

2 Replies 2

cisco24x7
Level 6
Level 6

"fixup protocol ftp 21".

That will fix your problem without compromising security.

Easy right?

Yes, this was easy and resolved my problem. I really appreciate the assistance.

Thanks,

Keith

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card