I am having a slight problem with FTP for my users. I know I am missing something stupid, but I just can't find it. Basically anyone one on the outside Ethernet1 can FTP in both Passive and Active (this is what I need), however my users Ethernet0 can not connect to outside FTP sites in Passive mode, but are succesful in active mode. My users need to be able to connect in both modes. Below is the access-list.
Thank you
Glen
interface Ethernet0
ip access-group 120 in
no ip mroute-cache
no cdp enable
!
interface Ethernet1
ip access-group 121 in
no ip mroute-cache
duplex auto
no cdp enable
access-list 120 permit tcp any any eq www
access-list 120 permit tcp any any eq ftp-data
access-list 120 permit tcp any any eq ftp
access-list 120 permit tcp any any eq telnet
access-list 120 permit tcp any any eq 3389
access-list 120 permit tcp any any eq domain
access-list 120 permit udp any any eq domain
access-list 120 permit icmp any any
access-list 120 permit tcp any any established
access-list 120 permit tcp any any eq 8080
access-list 120 deny udp any any range 0 1023
access-list 120 deny udp any any eq 2140
access-list 120 deny udp any any eq 18753
access-list 120 deny udp any any eq 20433
access-list 120 deny udp any any eq 27444
access-list 120 deny udp any any eq 31335
access-list 120 permit tcp any any eq 143
access-list 120 permit tcp any any eq smtp
access-list 120 permit tcp any any eq 443
access-list 120 permit tcp any any eq 1024
access-list 120 permit tcp any any eq 1026
access-list 120 permit tcp any any range 5500 5700
access-list 120 permit tcp any any eq 15871
access-list 120 permit tcp any any eq 24243
access-list 120 permit tcp any eq ftp-data any gt 1023
access-list 120 permit tcp any eq ftp-data any gt 1024
access-list 121 permit tcp any any eq www
access-list 121 permit tcp any any eq ftp-data
access-list 121 permit tcp any any eq ftp
access-list 121 permit tcp any any eq telnet
access-list 121 permit tcp any any eq 3389
access-list 121 permit tcp any any eq domain
access-list 121 permit icmp any any
access-list 121 permit tcp any any established
access-list 121 permit tcp any any eq 8080
access-list 121 permit udp any any range 1024 65535
access-list 121 deny udp any any range 0 1023
access-list 121 deny udp any any eq 2140
access-list 121 deny udp any any eq 18753
access-list 121 deny udp any any eq 20433
access-list 121 deny udp any any eq 27444
access-list 121 deny udp any any eq 31335
access-list 121 permit tcp any any eq smtp
access-list 121 permit tcp any any eq 143
access-list 121 permit tcp any any eq 443
access-list 121 permit tcp any any eq 1024
access-list 121 permit tcp any any eq 1026
access-list 121 permit tcp any any range 5500 5700
access-list 121 permit tcp any eq ftp-data any gt 1023
access-list 121 permit tcp any eq ftp-data any gt 1024
Thank you
Glen
interface Ethernet0
ip access-group 120 in
no ip mroute-cache
no cdp enable
!
interface Ethernet1
ip access-group 121 in
no ip mroute-cache
duplex auto
no cdp enable
access-list 120 permit tcp any any eq www
access-list 120 permit tcp any any eq ftp-data
access-list 120 permit tcp any any eq ftp
access-list 120 permit tcp any any eq telnet
access-list 120 permit tcp any any eq 3389
access-list 120 permit tcp any any eq domain
access-list 120 permit udp any any eq domain
access-list 120 permit icmp any any
access-list 120 permit tcp any any established
access-list 120 permit tcp any any eq 8080
access-list 120 deny udp any any range 0 1023
access-list 120 deny udp any any eq 2140
access-list 120 deny udp any any eq 18753
access-list 120 deny udp any any eq 20433
access-list 120 deny udp any any eq 27444
access-list 120 deny udp any any eq 31335
access-list 120 permit tcp any any eq 143
access-list 120 permit tcp any any eq smtp
access-list 120 permit tcp any any eq 443
access-list 120 permit tcp any any eq 1024
access-list 120 permit tcp any any eq 1026
access-list 120 permit tcp any any range 5500 5700
access-list 120 permit tcp any any eq 15871
access-list 120 permit tcp any any eq 24243
access-list 120 permit tcp any eq ftp-data any gt 1023
access-list 120 permit tcp any eq ftp-data any gt 1024
access-list 121 permit tcp any any eq www
access-list 121 permit tcp any any eq ftp-data
access-list 121 permit tcp any any eq ftp
access-list 121 permit tcp any any eq telnet
access-list 121 permit tcp any any eq 3389
access-list 121 permit tcp any any eq domain
access-list 121 permit icmp any any
access-list 121 permit tcp any any established
access-list 121 permit tcp any any eq 8080
access-list 121 permit udp any any range 1024 65535
access-list 121 deny udp any any range 0 1023
access-list 121 deny udp any any eq 2140
access-list 121 deny udp any any eq 18753
access-list 121 deny udp any any eq 20433
access-list 121 deny udp any any eq 27444
access-list 121 deny udp any any eq 31335
access-list 121 permit tcp any any eq smtp
access-list 121 permit tcp any any eq 143
access-list 121 permit tcp any any eq 443
access-list 121 permit tcp any any eq 1024
access-list 121 permit tcp any any eq 1026
access-list 121 permit tcp any any range 5500 5700
access-list 121 permit tcp any eq ftp-data any gt 1023
access-list 121 permit tcp any eq ftp-data any gt 1024