Hi All,
I am fairly certain this is something that happens all the time and a very easy thing to do for most. I have never set up a dmz and am not the best at pix. I have an asa 5510 and I am trying to setup a ftp server in the dmz that i can reach from inside and outside(neither works as of now). I have done the following:
access-list outside_access_in extended permit tcp any host eq ftp
access-list DMZ1_access_in extended permit tcp host 192.168.60.15
192.168.9.0 255.255.255.0 eq ftpglobal (outside) 1 interface nat (outside) 0 access-list outside_nat0_inbound outside nat (inside) 0 access-list inside_nat0_outbound nat (inside) 1 0.0.0.0 0.0.0.0
static (DMZ1,outside) 192.168.60.10 netmask 255.255.255.255 static (DMZ1,outside) 192.168.60.15 netmask 255.255.255.255 static (inside,DMZ1) 192.168.9.0 192.168.9.0 netmask 255.255.255.0 access-group outside_access_in in interface outside access-group DMZ1_access_in in interface DMZ1
The ftp host private ip in the dmz is 192.168.60.15. Private hosts inside reside on 192.168.9.0.
When I view the live log, I do not see any errors, just the following when i attempt a connection from the inside:
6|Jan 05 2007 09:53:39|302014: Teardown TCP connection 67046549 for DMZ1:192.168.60.15/21 to inside:192.168.9.75/1420 duration 0:00:30 bytes 0 SYN Timeout 6|Jan 05 2007 09:53:30|302013: Built outbound TCP connection 67046634 for DMZ1:192.168.60.15/21 (192.168.60.15/21) to inside:192.168.9.75/1421 (192.168.9.75/1421) 6|Jan 05 2007 09:53:08|302013: Built outbound TCP connection 67046549 for DMZ1:192.168.60.15/21 (192.168.60.15/21) to inside:192.168.9.75/1420 (192.168.9.75/1420) 6|Jan 05 2007 09:53:08|302014: Teardown TCP connection 67046336 for DMZ1:192.168.60.15/21 to inside:192.168.9.75/1419 duration 0:00:30 bytes 0 SYN TimeoutI do not have any egress filtering (no acl on my inside int). The asa has the necessary inspect ftp command.
Can someone please help?
TIA,
R