cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
259
Views
0
Helpful
2
Replies

NAT Trans table question???

rshullaw
Level 1
Level 1

Question:

My router is doing both static NAT and dynamic from a pool of public addresses. When I execute a sh ip nat trans command, the output shows most of my Inside local and global addresses, both static and dynamic, with a a following tcp port of 21. Why is that? Will I need to consider this when building my access-lists?

Thanks!

2 Replies 2

mchin345
Level 6
Level 6

TCP 21 is FTP control, probably more users on your network are initiating file transfers.If you want users not to do any file transfers you can block them using access list.

Thanks for the reply.

I realize that 21 is the standard representation for FTP control, but every single nat translation on the inside has the :21 referenced after it and there is simply no possible way that every user on the network has initiated a file transfer? Any other thoughts or possibilities?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: