For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

AdrianBrunhuber's avatar
AdrianBrunhuber
Icon for Nimbostratus rankNimbostratus
May 23, 2016

Both Specific port and Wildcard VS on the same VIP

Hi F5 gurus ,

I need help to understand what is the best practice in the following scenario. I have the following VS

s : 

FTP (port 21)
SFTP (port 22)
SFTP implicit ( port 990) 

Because explicit FTPs (TLS)  also was needed I had to build a wildcard VS (all ports) . 

I understand that if a specific port is VS exists the traffic will be processed by that VS and it defaults to the wildcard. 
On the technical side everything seems to be working fine , however I

FTP (port 21) SFTP (port 22) SFTP implicit ( port 990)

Because explicit FTPs (TLS) also was needed I had to build a wildcard VS (all ports) .

I understand that if a specific port is VS exists the traffic will be processed by that VS and it defaults to the wildcard. On the technical side everything seems to be working fine , however I

m wondering about the best practice , which brings me to the following questions : 

Should I leave port specific VS

Should I leave port specific VS`s in place or delete them and let the traffic be processed by the wildcard VS.

Thanks, Adrian