cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
558
Views
0
Helpful
1
Replies

ASA5505 Configure FTP on differnt port, ex. 58158

admin_2
Level 3
Level 3

Hi!

I'm trying to configure ASA 5505 to pass FTP connection to Win2003 IIS FTP server on port 58158.

Works fine with port 21 but not any other port.

I get : 227 Entering Passive mMode (192.168.1.10,142,158)

The server sent a passive answer with a non routable address.

This IP is the internal server address.

When I use port 21 the IP address above is the external address ocf the router and everything works fine.

Using static NAT rule Interface inside, server IP address. Translated Interface outside, use Interface IP address.

Enablr Port Address Translation, TCP port 21 to 21 (or 58158 to 58158)

Any idea?

1 Reply 1

Herbert Baerten
Cisco Employee
Cisco Employee

You'll have to configure FTP inspection for this port, e.g.:

class-map class-ftp

match port tcp eq 58158

policy-map global_policy

class class-ftp

inspect ftp

service-policy global_policy global

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card