Configured ACL's for Firewalls, and FTP is/isn't working? I can FTP to Server2, however, cannot use half the commands, i.e., ftp> ls, ftp> get, etc...
ftp> ls
200 PORT command successful (this is where it hangs).
I thought using both ftp-data tcp/udp would work?
Any ideas?
Server1 10.15.8.240 <-> 7513 NAT <-> 7204 ACL Firewall <-> Server2 10.115.28.20/10.15.12.40 (NAT)
access-list 102 permit icmp 10.0.0.0 0.255.255.255 any
access-list 102 permit tcp any 10.0.0.0 0.255.255.255 established
access-list 102 deny ip any any
access-list 103 permit udp host 10.10.1.10 eq ntp any
access-list 103 permit icmp 10.0.0.0 0.255.255.255 any
access-list 103 permit tcp host 10.15.8.240 host 10.115.28.20 eq telnet
access-list 103 permit tcp host 10.15.8.240 host 10.115.28.20 eq ftp
access-list 103 permit tcp host 10.15.8.240 host 10.115.28.20 eq ftp-data
access-list 103 permit udp host 10.15.8.240 host 10.115.28.20 eq ftp-data
access-list 103 permit tcp 10.115.28.20 255.255.255.255 host 10.15.8.240 eq 80
access-list 103 permit tcp any 10.0.0.0 0.255.255.255 established
access-list 103 deny ip any any
ftp> ls
200 PORT command successful (this is where it hangs).
I thought using both ftp-data tcp/udp would work?
Any ideas?
Server1 10.15.8.240 <-> 7513 NAT <-> 7204 ACL Firewall <-> Server2 10.115.28.20/10.15.12.40 (NAT)
access-list 102 permit icmp 10.0.0.0 0.255.255.255 any
access-list 102 permit tcp any 10.0.0.0 0.255.255.255 established
access-list 102 deny ip any any
access-list 103 permit udp host 10.10.1.10 eq ntp any
access-list 103 permit icmp 10.0.0.0 0.255.255.255 any
access-list 103 permit tcp host 10.15.8.240 host 10.115.28.20 eq telnet
access-list 103 permit tcp host 10.15.8.240 host 10.115.28.20 eq ftp
access-list 103 permit tcp host 10.15.8.240 host 10.115.28.20 eq ftp-data
access-list 103 permit udp host 10.15.8.240 host 10.115.28.20 eq ftp-data
access-list 103 permit tcp 10.115.28.20 255.255.255.255 host 10.15.8.240 eq 80
access-list 103 permit tcp any 10.0.0.0 0.255.255.255 established
access-list 103 deny ip any any