- Posts: 96
- Thank you received: 0
Allowing FTP through ASA/Firewall
15 years 9 months ago #29095
by timparker
Allowing FTP through ASA/Firewall was created by timparker
I am having some issues with allowing this through our ASA. I started pulling the config apart to post but started googling and I see some stuff about having to allow other high ports. I currently have what I think are the correct ones, 21 and 20.
Anything blatent that I am missing or should I continue to post the config here?
TIA.
Anything blatent that I am missing or should I continue to post the config here?
TIA.
15 years 9 months ago #29100
by timparker
Replied by timparker on topic Re: Allowing FTP through ASA/Firewall
Nevermind on this, I found the answer. For those that might want/need this later. I didn't have :
fixup protocol ftp 21
In my config. Added it in and Poof it works!
fixup protocol ftp 21
In my config. Added it in and Poof it works!
- skepticals
- Offline
- Elite Member
Less
More
- Posts: 783
- Thank you received: 0
15 years 9 months ago #29146
by skepticals
Replied by skepticals on topic Re: Allowing FTP through ASA/Firewall
What exactly does that line do?
15 years 9 months ago #29150
by timparker
Replied by timparker on topic Re: Allowing FTP through ASA/Firewall
That actually is the line from Pix 6.3 code. The ASA though I found out converts it to the correct Policy Map, Traffic Inspection and Service Policy.
15 years 9 months ago #29158
by Smurf
Wayne Murphy
Firewall.cx Team Member
www.firewall.cx
Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
Replied by Smurf on topic Re: Allowing FTP through ASA/Firewall
Basically, the Fixup allows the Firewall to inspect (inspect is actually what is used in version 7+) the traffic. It checks it for RFC Compliancy, etc... but more importantly it makes the firewall FTP aware. This means that the firewall can monitor the FTP Communication and can open the necessary secondary ports that are required with the FTP protocol (i.e. Port 21 for the Command, once data is actually being transmitted, Port 20 is used for the data, this needs to be allowed through the firewall, while its inspecting the traffic, the firewall will notice which port the traffic is coming from and dynamically open it).
It would be worth reading about it within this site, in particular the differences between PASV and ACTIVE (PORT) Modes www.firewall.cx/ftp.php
It would be worth reading about it within this site, in particular the differences between PASV and ACTIVE (PORT) Modes www.firewall.cx/ftp.php
Wayne Murphy
Firewall.cx Team Member
www.firewall.cx
Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
- skepticals
- Offline
- Elite Member
Less
More
- Posts: 783
- Thank you received: 0
15 years 9 months ago #29195
by skepticals
Replied by skepticals on topic Re: Allowing FTP through ASA/Firewall
Thank you for the info. I will check that out.
Time to create page: 0.153 seconds