We have a Cisco ASA 5505 that we're running Serv-U 7.2.0.1 behind. None of our clients could make a passive connection so through a bit of troubleshooting we removed Inspect FTP and things started working fine.
Now one of our clients is unable to connect via passive or active for some reason.
Server Log:
[02] Fri 15Aug08 12:28:46 - (009148) Connected to 67.151.89.98 (local address 192.168.61.248, port 21) [03] Fri 15Aug08 12:28:46 - (009148) IP-Name: nypost.tanhelp.com (67.151.89.98) [21] Fri 15Aug08 12:28:46 - (009148) 220-RLS FTP Server
[21] Fri 15Aug08 12:28:46 - (009148) 220- OUR COMPANY NAME
[21] Fri 15Aug08 12:28:46 - (009148) 220- [21] Fri 15Aug08 12:28:46 - (009148) 220-This is a private computer system. This computer [21] Fri 15Aug08 12:28:46 - (009148) 220-system, including all related equipment, networks [21] Fri 15Aug08 12:28:46 - (009148) 220-and network devices, are for authorized use only.
[21] Fri 15Aug08 12:28:46 - (009148) 220-Any unauthorized use is illegal and punishable by
[21] Fri 15Aug08 12:28:46 - (009148) 220-criminal prosecution. If you are not authorized
[21] Fri 15Aug08 12:28:46 - (009148) 220-to access this system please disconnect now. All [21] Fri 15Aug08 12:28:46 - (009148) 220-transactions to this system are logged.
[21] Fri 15Aug08 12:28:46 - (009148) 220- [21] Fri 15Aug08 12:28:46 - (009148) 220-For access or to report problems, please contact [21] Fri 15Aug08 12:28:46 - (009148) 220 IT Support.
[20] Fri 15Aug08 12:28:46 - (009148) USER username [21] Fri 15Aug08 12:28:46 - (009148) 331 User name okay, need password.
[20] Fri 15Aug08 12:28:46 - (009148) PASS ********** [02] Fri 15Aug08 12:28:46 - (009148) User "username" logged in [21] Fri 15Aug08 12:28:46 - (009148) 230 User logged in, proceed.
[20] Fri 15Aug08 12:28:46 - (009148) SYST [21] Fri 15Aug08 12:28:46 - (009148) 215 UNIX Type: L8 [20] Fri 15Aug08 12:28:46 - (009148) FEAT [21] Fri 15Aug08 12:28:46 - (009148) 211-Extensions supported
[21] Fri 15Aug08 12:28:46 - (009148) UTF8
[21] Fri 15Aug08 12:28:46 - (009148) OPTS MODE;MLST;UTF8
[21] Fri 15Aug08 12:28:46 - (009148) CLNT
[21] Fri 15Aug08 12:28:46 - (009148) CSID Name; Version;
[21] Fri 15Aug08 12:28:46 - (009148) HOST domain
[21] Fri 15Aug08 12:28:46 - (009148) SITE PSWD;SET;INDEX;ZONE;CHMOD;
MSG;EXEC;H
ELP
[21] Fri 15Aug08 12:28:46 - (009148) AUTH TLS;SSL;TLS-C;TLS-P;
[21] Fri 15Aug08 12:28:46 - (009148) PBSZ
[21] Fri 15Aug08 12:28:46 - (009148) PROT
[21] Fri 15Aug08 12:28:46 - (009148) CCC
[21] Fri 15Aug08 12:28:46 - (009148) SSCN
[21] Fri 15Aug08 12:28:46 - (009148) RMDA directoryname
[21] Fri 15Aug08 12:28:46 - (009148) DSIZ
[21] Fri 15Aug08 12:28:46 - (009148) AVBL
[21] Fri 15Aug08 12:28:46 - (009148) MODE Z
[21] Fri 15Aug08 12:28:46 - (009148) THMB BMP|JPEG|GIF|TIFF|PNG max_width max_height pathname
[21] Fri 15Aug08 12:28:46 - (009148) REST STREAM
[21] Fri 15Aug08 12:28:46 - (009148) SIZE
[21] Fri 15Aug08 12:28:46 - (009148) MDTM
[21] Fri 15Aug08 12:28:46 - (009148) MDTM YYYYMMDDHHMMSS[+-TZ];filen
ame
[21] Fri 15Aug08 12:28:46 - (009148) XCRC filename;start;end
[21] Fri 15Aug08 12:28:46 - (009148) MLST Type*;Size*;Create;Modify*
;Perm;Win3
2.ea;Win32
.dt;Win32.
dl
[21] Fri 15Aug08 12:28:46 - (009148) 211 End (for details use "HELP commmand" where command is the command of interest) [20] Fri 15Aug08 12:28:46 - (009148) PWD [21] Fri 15Aug08 12:28:46 - (009148) 257 "/" is current directory.
[20] Fri 15Aug08 12:28:46 - (009148) TYPE I [21] Fri 15Aug08 12:28:46 - (009148) 200 Type set to I.
[20] Fri 15Aug08 12:28:46 - (009148) PASV [21] Fri 15Aug08 12:28:46 - (009148) 425 Unable to set up passive listening socket.
[20] Fri 15Aug08 12:28:46 - (009148) PORT 10,100,30,25,7,91 [21] Fri 15Aug08 12:28:46 - (009148) 530 Only client IP address allowed for PORT command.
[02] Fri 15Aug08 12:29:03 - (009136) Session idle time out [21] Fri 15Aug08 12:29:03 - (009136) 421 Connection timed out - closing.
[02] Fri 15Aug08 12:29:03 - (009136) Closed session
Client Log:
Status: Connected
Status: Retrieving directory listing...
Command: PWD
Response: 257 "/" is current directory.
Command: TYPE I
Response: 200 Type set to I.
Command: PASV
Response: 425 Unable to set up passive listening socket.
Command: PORT 10,100,30,25,7,91
Response: 530 Only client IP address allowed for PORT command.
Error: Failed to retrieve directory listing
What do you make of that? It looks like the client is passing the LAN IP instead of the external. What can I do about that?
Start Free Trial