Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

"inspect ftp" the culprit for HTTP to FTP downloading timeout

Hi,

When I removed the "inspect ftp" from the default global policy in my PIX, the HTTP to FTP redirection works and I can download files from HP.

But if it's there, it times out and I get a dialog box in Firefox that says:

"The connection to the server was reset while the page is loading."

At this particular time, the "Connect to ftp.hp.com" starts to show in the lower left corner of the Firefox browser.

What's the pros and cons of removing the inspect ftp?

Any other solution without removing this line?

PIX ver. 7.2(2)

TIA,

Archie

1 REPLY
Silver

Re: "inspect ftp" the culprit for HTTP to FTP downloading timeou

FTP application inspection prepares secondary channels for FTP data transfer. Ports for these channels are negotiated through PORT or PASV commands. The channels are allocated in response to a file upload, a file download, or a directory listing event.If double-encoding is used in the URL then it may cause this issue with "FTP Inspection" enabled.So it will work after disabling the inspection.

Refer the URL listed below for more information on FTP inspection:

1)FTP--http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/inspect.html#wp1234738

201
Views
0
Helpful
1
Replies