Home  
  Microsoft  
  Cisco  
  CompTIA  
  CWNP  
  InfoSecurity  
  Forums  
  Blogs  
  Topsites  
  Watch free videos online  
     
  Subnet Calculator  
  Online Degrees  
  Exam Vouchers  
  Free Magazines  
     

  Watch free videos online  
   

 

Register Practice Exams TechNotes Members List Search Today's Posts Mark Forums Read
Go Back   TechExams.net IT Certification Forums > General > Off-Topic
Reply
 
Thread Tools
Senior Member
Registered Member
 
itdaddy's Avatar
 
Join Date: Jan 2006
Posts: 1,106

Certifications: A+, CCNA, MCP
itdaddy will become famous soon enough
Old 06-01-2009, 02:08 AM   #1 (permalink)
Default GeneFTP ftp/ssl ? anyone use this? firewall issues

Quote:
425 Cannot open data connection.
Attemping PASV mode transfer...
PASV
227 Entering Passive Mode (192,168,15,10,118,111)
192.168.15.10 -> 209.94.168.243
LIST
Connect socket #944 to 209.94.168.243, port 30319...
hey guys anyone use GeneFTP server. I really like it but
I have my ASA and it says some how I have a data port screw up.
Cause I cannot get it to list outside on the public WAN. If I use it in simple ftp mode port 20/21 i can access everything fine on the public wan
But i want to use it in ftp/ssl mode i want to keep it secure. I know it is myt firewall because in can use the ftp/ssl on my inside LAn fine but when it traverses inside to outside or really outside to inside. it authenticates fine but the data pathway is screw up and I have not a clue what to do.
I have allowed port 1024 and checked the box on the ftp server to force this port but no good. Anyone have this kind of issue? like i said the authentication works but when it tries to list the directories says the above issue. error.
thanks for your help...



__________________
itdaddy

"...so many toys....so little time!"


Last edited by itdaddy; 06-01-2009 at 02:10 AM.
itdaddy is offline   Reply With Quote

Login/register to remove this advertisement.
was here.
Registered Member
 
Join Date: Apr 2008
Location: UK
Posts: 2,806

tiersten is a glorious beacon of lighttiersten is a glorious beacon of lighttiersten is a glorious beacon of lighttiersten is a glorious beacon of lighttiersten is a glorious beacon of light
Old 06-01-2009, 02:48 AM   #2 (permalink)

I have no idea what you wrote there. Are you saying that passive FTP can't traverse your ASA?

tiersten is online now   Reply With Quote
Senior Member
Registered Member
 
msteinhilber's Avatar
 
Join Date: Jan 2008
Location: Deforest, WI
Posts: 1,020

Certifications: B.S. Technology Mgmt., MCTS: Vista Configuration, MCTS: Windows 7, Configuring
msteinhilber is just really nicemsteinhilber is just really nicemsteinhilber is just really nicemsteinhilber is just really nice
Send a message via AIM to msteinhilber
Old 06-01-2009, 03:05 AM   #3 (permalink)

Did you open up the ports that you have defined for passive mode FTP? The ASA supports options to inspect FTP traffic which can determine the passive ports being used for a session, but in your case since you are using secure FTP, the control channel will be encrypted and the ASA would not be able to inspect the packets to determine which port to dynamically open.

msteinhilber is offline   Reply With Quote
Senior Member
Registered Member
 
itdaddy's Avatar
 
Join Date: Jan 2006
Posts: 1,106

Certifications: A+, CCNA, MCP
itdaddy will become famous soon enough
Old 06-01-2009, 03:40 AM   #4 (permalink)

I really am trying to say that something is not allowing the Listing of the directories. when i do not use ftp/ssl it works fine but for some reason
I do not know what is not allowing the listing of data..I am not sure how ftp/ssl works. I mean I am using port 21 and I guess port 20 but what port is used for SSL? I am unfamiliar with really some of things my coreftp client needs. and how to set up my GeneFTP server..it has settings for passive mode on the server. I forced it to use 1024 on the server and did some static entries on the asa but something is not allowing the directory listing of data. it says that in the error message..was hopeing someone used GeneFTP server. I have used titan and ftp/ssh and it works fine with my asa firewall settings. I have never setup a ftp/ssl before and I am unfamiliar in what it is needed. Thanks for helping....



__________________
itdaddy

"...so many toys....so little time!"

itdaddy is offline   Reply With Quote
Senior Member
Registered Member
 
msteinhilber's Avatar
 
Join Date: Jan 2008
Location: Deforest, WI
Posts: 1,020

Certifications: B.S. Technology Mgmt., MCTS: Vista Configuration, MCTS: Windows 7, Configuring
msteinhilber is just really nicemsteinhilber is just really nicemsteinhilber is just really nicemsteinhilber is just really nice
Send a message via AIM to msteinhilber
Old 06-01-2009, 04:05 AM   #5 (permalink)

I checked out the Gene6 site, did you enable redirect passive IP and enter your public IP?

msteinhilber is offline   Reply With Quote
Senior Member
Registered Member
 
itdaddy's Avatar
 
Join Date: Jan 2006
Posts: 1,106

Certifications: A+, CCNA, MCP
itdaddy will become famous soon enough
Old 06-01-2009, 02:34 PM   #6 (permalink)

msteinhilber

I saw that config inthe ip bind section. But wasnt sure I had to do that.
will try it and see what it does. do you know what it does?
plus my public ip changes and will try my DNS name and see if
i can get it work; but it i must be blocking something or some port;(



__________________
itdaddy

"...so many toys....so little time!"

itdaddy is offline   Reply With Quote
Senior Member
Registered Member
 
itdaddy's Avatar
 
Join Date: Jan 2006
Posts: 1,106

Certifications: A+, CCNA, MCP
itdaddy will become famous soon enough
Old 06-01-2009, 02:56 PM   #7 (permalink)

Gene6 FTP Server v3 - Manual

I think I see what you mean. I will look at config and see what I messed up; thanks for the help



__________________
itdaddy

"...so many toys....so little time!"

itdaddy is offline   Reply With Quote
Senior Member
Registered Member
 
itdaddy's Avatar
 
Join Date: Jan 2006
Posts: 1,106

Certifications: A+, CCNA, MCP
itdaddy will become famous soon enough
Old 06-01-2009, 05:45 PM   #8 (permalink)

msteinhilber

dude you are a genius. As soon as I added my website sftp.itdaddy.net
and made the PASV port static 1024 and of course added some ACLs and a static entry in my ASA 5505 bam FTP/SSL works perfect.

thanks for pointing that out to me and cutting thru my babbling.

I appreciate your guidance mate!

Robert



__________________
itdaddy

"...so many toys....so little time!"

itdaddy is offline   Reply With Quote
Bookmarks
Go Back TechExams.net IT Certification Forums > General > Off-Topic
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off



All times are GMT. The time now is 05:43 PM.

 
 
Featured Sponsors

TrainSignal - “Hands On” computer training for IT professionals. Network+ Training, MCSE, Cisco & more! Visit Train Signal’s free training site to get loads of Free Computer Training, videos, articles and practice exams.

Preplogic - Sign up now to get Unlimited Access to PrepLogic's entire video training library. Enjoy open access to Microsoft Server 2008, CCNA, CISSP®, PMP and many more. Get Unlimited Access

 

Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
TechExams.net 2009