FXP med Cisco PIX501
Jeg har lige sat en server op med RaidenFTPD 2.4.449 med FXP enable med PASV Mode, og har åbnet portene i min PIX501. Men mine venner kan ikke fxp til mig, her er fejlenTYPE I
200 Type set to I.
TYPE I
200 Type set to I.
PASV
Entering Passive Mode (206,158,102,123,90,134).
206,158,102,123,90,134
it's stop rite ther
mit PASV Mode Range er : 1401-1411
her er min PIX501 konfiguration
: Written by enable_15 at 13:58:20.122 CEDT Wed Aug 13 2003
PIX Version 6.3(1)
interface ethernet0 10baset
interface ethernet1 100full
nameif ethernet0 outside security0
nameif ethernet1 inside security100
enable password 6nTJHm.ZtzfaZP.7 encrypted
passwd 6nTJHm.ZtzfaZP.7 encrypted
hostname pixfirewall
domain-name activeconnect.dk
clock timezone CEST 1
clock summer-time CEDT recurring last Sun Mar 2:00 last Sun Oct 3:00
fixup protocol ftp 20
fixup protocol ftp 21
fixup protocol h323 h225 1720
fixup protocol h323 ras 1718-1719
fixup protocol http 80
fixup protocol ils 389
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol sip 5060
fixup protocol sip udp 5060
fixup protocol skinny 2000
fixup protocol smtp 25
fixup protocol sqlnet 1521
names
access-list outside_access_in permit icmp any any echo-reply
access-list outside_access_in permit tcp any host 80.199.37.152 eq smtp
access-list outside_access_in permit tcp any host 80.199.37.152 eq 32000
access-list outside_access_in permit tcp any host 80.199.37.152 eq https
access-list outside_access_in permit tcp any host 80.199.37.152 eq ftp
access-list outside_access_in permit tcp any host 80.199.37.152 eq 5900
access-list outside_access_in permit tcp any host 80.199.37.152 eq www
access-list outside_access_in permit tcp any host 80.199.37.152 eq 3389
access-list outside_access_in permit tcp any host 80.199.37.152 eq ident
access-list outside_access_in permit tcp any host 80.199.37.152 eq 59
access-list outside_access_in permit tcp any host 80.199.37.152 eq ftp-data
access-list outside_access_in permit tcp any host 80.199.37.152 eq 286
access-list outside_access_in permit udp any host 80.199.37.152 eq 286
access-list outside_access_in permit tcp any host 80.199.37.152 eq 2849
access-list outside_access_in permit udp any host 80.199.37.152 eq 2849
access-list outside_access_in permit udp any host 80.199.37.152 eq 21
access-list outside_access_in permit udp any host 80.199.37.152 eq 20
access-list outside_access_in permit tcp any interface outside range 5000 5011
access-list outside_access_in permit udp any interface outside range 5000 5011
access-list outside_access_in permit tcp any interface outside range 1401 1411
access-list outside_access_in permit udp any interface outside range 1401 1411
access-list outside_access_in permit tcp any host 80.199.37.152 eq 29692
access-list outside_access_in permit udp any host 80.199.37.152 eq 29692
access-list outside_access_in permit tcp any host 80.199.37.152 eq 23179
pager lines 24
logging on
logging timestamp
logging console informational
logging monitor informational
logging buffered informational
logging trap informational
logging history informational
logging host inside 192.168.1.10
mtu outside 1500
mtu inside 1500
ip address outside pppoe setroute
ip address inside 192.168.1.1 255.255.255.0
ip verify reverse-path interface outside
ip verify reverse-path interface inside
ip audit info action alarm
ip audit attack action alarm
pdm location 192.168.1.0 255.255.255.0 inside
pdm location 172.29.0.0 255.255.0.0 outside
pdm location 194.192.110.10 255.255.255.255 outside
pdm location 172.29.16.0 255.255.255.0 outside
pdm location 172.29.16.0 255.255.254.0 outside
pdm location 192.168.1.10 255.255.255.255 inside
pdm location 80.199.37.152 255.255.255.255 outside
pdm location 212.242.93.96 255.255.255.224 outside
pdm logging informational 512
pdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
static (inside,outside) tcp interface smtp 192.168.1.10 smtp netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 32000 192.168.1.10 32000 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface https 192.168.1.10 https netmask 255.255.255.255 0 0
static (inside,outside) tcp interface www 192.168.1.10 www netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 5900 192.168.1.10 5900 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface ftp 192.168.1.10 ftp netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 3389 192.168.1.10 3389 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface ident 192.168.1.10 ident netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 59 192.168.1.10 59 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface ftp-data 192.168.1.10 ftp-data netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 5000 192.168.1.10 5000 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 5001 192.168.1.10 5001 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 5002 192.168.1.10 5002 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 5003 192.168.1.10 5003 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 5004 192.168.1.10 5004 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 286 192.168.1.10 286 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 286 192.168.1.10 286 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 2849 192.168.1.10 2849 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 2849 192.168.1.10 2849 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 5005 192.168.1.10 5005 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 5006 192.168.1.10 5006 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 5007 192.168.1.10 5007 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 5008 192.168.1.10 5008 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 5009 192.168.1.10 5009 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 5010 192.168.1.10 5010 netmask 255.255.255.255 0 0
static (inside,outside) udp 80.199.37.152 5010 192.168.1.10 5010 netmask 255.255.255.255 0 0
static (inside,outside) udp 80.199.37.152 5009 192.168.1.10 5009 netmask 255.255.255.255 0 0
static (inside,outside) udp 80.199.37.152 5008 192.168.1.10 5008 netmask 255.255.255.255 0 0
static (inside,outside) udp 80.199.37.152 5007 192.168.1.10 5007 netmask 255.255.255.255 0 0
static (inside,outside) udp 80.199.37.152 5006 192.168.1.10 5006 netmask 255.255.255.255 0 0
static (inside,outside) udp 80.199.37.152 5005 192.168.1.10 5005 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 20 192.168.1.10 20 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 21 192.168.1.10 21 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 5011 192.168.1.10 5011 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 5011 192.168.1.10 5011 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 1401 192.168.1.10 1401 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 1401 192.168.1.10 1401 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 1402 192.168.1.10 1402 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 1402 192.168.1.10 1402 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 1403 192.168.1.10 1403 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 1403 192.168.1.10 1403 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 1404 192.168.1.10 1404 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 1405 192.168.1.10 1405 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 1406 192.168.1.10 1406 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 1407 192.168.1.10 1407 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 1408 192.168.1.10 1408 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 1409 192.168.1.10 1409 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 1410 192.168.1.10 1410 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 1411 192.168.1.10 1411 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 1404 192.168.1.10 1404 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 1405 192.168.1.10 1405 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 1406 192.168.1.10 1406 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 1407 192.168.1.10 1407 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 1408 192.168.1.10 1408 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 1409 192.168.1.10 1409 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 1410 192.168.1.10 1410 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 1411 192.168.1.10 1411 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 29692 192.168.1.10 29692 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 23174 192.168.1.10 23174 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 29692 192.168.1.10 29692 netmask 255.255.255.255 0 0
access-group outside_access_in in interface outside
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server RADIUS protocol radius
aaa-server LOCAL protocol local
http server enable
http 80.199.37.152 255.255.255.255 outside
http 192.168.1.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
tftp-server outside ***.***.***.**** /wmhomepix/config
floodguard enable
telnet 212.242.93.96 255.255.255.224 outside
telnet 172.29.16.0 255.255.254.0 outside
telnet 194.192.110.10 255.255.255.255 outside
telnet 192.168.1.0 255.255.255.0 inside
telnet timeout 5
ssh 172.29.16.0 255.255.254.0 outside
ssh 194.192.110.10 255.255.255.255 outside
ssh 212.242.93.96 255.255.255.224 outside
ssh 192.168.1.0 255.255.255.0 inside
ssh timeout 5
console timeout 0
vpdn group pppoe_group request dialout pppoe
vpdn group pppoe_group localname ***********
vpdn group pppoe_group ppp authentication chap
vpdn username ************** password ********
dhcpd lease 3600
dhcpd ping_timeout 750
dhcpd auto_config outside
terminal width 80
Cryptochecksum:7272154d705e31e1296b37f7224e3ebd
pixfirewall(config)#
Hvad kan de være ???????