Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

FTP fixup problem?

We have FTP servers on the inside and DMZ of our 515E running 6.2(3), with static routing through the firewall in every direction. We observe regular failures accessing the servers from both outside and inside. The faults concern the data transfer, usually time-outs but sometimes can't build data connection (425).

We use the PORT flavour of the protocol, and a variety of clients. The servers are ProFtpd for Linux.

Bill

2 REPLIES
Gold

Re: FTP fixup problem?

Hello Bill,

Have you got any logging output? If not can you turn this on the PIX and post the results please:

logging on

logging buffer debug

Try a connection, then:

sho logg

Thanks - Jay

New Member

Re: FTP fixup problem?

Jay,

Sorry about the delay, but it's taken some time to get meaningful logging. I've got snips from a PIX log and two TCPDUMP's, one from each side of the PIX. The file is largish, so I'm E-mailing it to you directly.

'server' is on the DMZ and 'client' is inside.

As you will see, the first FIN packet from the client fails to make it through the PIX, in the case of the 8th transfer in this batch. This is typical behaviour.

Thanks for your interest.

Bill

90
Views
0
Helpful
2
Replies