...
- After upgrading the ASA to 9.12.4.35, FTP inspection will not work correctly. - ASA doesn't allow Data-channel traffic for Passive FTP to pass through and be dropped for the below reason : Drop-reason: (nat-no-xlate-to-pat-pool) Connection to PAT address without pre-existing xlate
- FTP inspection is enabled on the ASA - ASA running version 9.12.4.35, and the FTP server is published externally through a NAT statement on the ASA on port 21 ( only ) ex: nat (dmz,wan_1) source static server_priv server_public service source-ftp source-ftp
Option 1: Downgrade to 9.12.3 or upgrade to 9.16 Option 2: Manually create the xlate entries by publishing the server on all (Data + Control) ports if possible or on all ports : nat (dmz,wan_1) source static server_priv server_public
Cisco Integration
Learn more about where this data comes from
Bug Scrub Advisor
Streamline upgrades with automated vendor bug scrubs
BugZero Enterprise
Wish you caught this bug sooner? Get proactive today.