I have a 2621 configured with the serial interface to the outside world, ethernet 0/0 to DMZ2, ethernet 0/1 to DMZ1, and using ios firewall. When I am connected to DMZ2 I can make FTP communications to the outside world uploading and downloading. When connected to the DMZ1 I am only able to download from the same FTP site. When attempting to upload I get an "Access Denied" message. It appears that the data channel can't be created.
I'm aware of the fixup protocol command but that isn't available on this router. How can I make this work and why does it work on one DMZ but not the other?
I guess your ftp mode is active because in this mode the client initiate connection to ftp server port 21 (command port) then the server initiate a connection to the client from ftp server source port 20 (data port).
In your case the connection to the port 21 is inspected by your inbound inspect ? default ? and will allow only responses to the connection initiated from the outside so connection attempts from the port 20 will be denied.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...