Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

Bronze

Passive-ftp on an ASA

Ran into an issue trying to allow for passive-ftp on an ASA 5520. I have enable the ftp mode passive, even went so far as to allow an "ip any" to the FTP server in the DMZ and disable the global filtering policy. The client will connect, but cannot transfer files. Any ideas?

4 REPLIES
Cisco Employee

Re: Passive-ftp on an ASA

Hello sean@managednetworks.com,

The client should be initiating both connections to the ftp server. What do the logs show when you try to ftp?

New Member

Re: Passive-ftp on an ASA

find out which port range your ftp server is connecting on and define object services including ftp, ftp-data and the port range eg 1025 3500

Had similar problem and this is how I got round it.

New Member

Re: Passive-ftp on an ASA

Same issue here. Waiting for TAC reply, but would be curious to know if you resolved this.

Bronze

Re: Passive-ftp on an ASA

The issue turned out to be with the customer's FTP server. There was a setting that they did not have correct. ftp mode passive should be all that you need. Sometimes you may have to go into the default global policy and remove the ftp inspect portion. Hope this helps.

439
Views
0
Helpful
4
Replies