Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

PASV FTP port range forwarding

any command in IOS can forward a range of ports for PASV ftp?

I have a PASV ftp server behind the NAT router. it is too painful to forward each port line by line. For forwarding 20 ports, I need to enter 20 lines. I can't image if I need forward the ports more than that.

what comand can perform that if I want to for the port 5000-6000 to private address



Re: PASV FTP port range forwarding

You might want to look at CBAC (Context-Based Access Control):


New Member

Re: PASV FTP port range forwarding


Thanks for your reply.

I hope my understanding of the CBAC is correct. it is a context based firewall, it temporary open the port based on the behavior of the application.

For the PASV, it opens the incoming port for the duration of the PASV ftp session.

In my saturation, I only have 1 public address with NAT to share the internet connection. I also have 1 PASV FTP server in the local network, it listens a range of FTP port (let say 5000-6000) for the ftp service on the local address 192.168.1.x. The NAT router forward the same range of TCP port (5000-6000) from the public address to the private address 192.168.1.x

it is nearly not possible to for so many port in command line with 1 port 1 line format. That's why I am looking for a solution for port forwarding in range.

CreatePlease login to create content