FTP through PIX to one server

Stinn

[H]ard|Gawd
Joined
Jul 13, 2001
Messages
1,796
Hey Guys
FTP seems to work fine from inside out to almost everywhere, there's just this one server that won't work at all. From outside the pix it works fine if you turn passive mode off, from inside the pix here's what happens:

Connected to 1.2.3.4.
220 Microsoft FTP Service
500 'AUTH GSSAPI': command not understood
500 'AUTH KERBEROS_V4': command not understood
KERBEROS_V4 rejected as an authentication type
Name (1.2.3.4:local): FTPUSER
331 Password required for FTPUSER.
Password:
230 User FTPUSER logged in.
Remote system type is Windows_NT.
ftp> passive
Passive mode off.
ftp> ls
421 Service not available, remote server has closed connection
ftp>


It's a total mystery to me. We are running PIX515E's. I can ftp to lots of other servers without any trouble. Is there something I can do config wise on the pix?
 
if you can ftp to other servers, I would say that its not the pix.

whats the kebreros dealio?

I would run a tcpdump on the firewall and see if there isnt any type of authentication traffic getting blocked. might be some config on the ftp server.
 
At first glance, the server is not running in PASV mode, which would be needed to connect from inside the firewall.
 
so it's nothing i can do from my end?

See when i come in through my pix to one of my ftp servers i have to turn off passive mode for it to work.
 
Back
Top