Forum Discussion
Can the SWG module be used as an FTP forward proxy
Hi;
I am trying to use the SWG as a secure "passive ftp" gateway in the same manner it is used for http and https traffic.
Moreover, the aim is to use NTLM authentication to identify ftp users then authorize them. For instance, upon successful authentication, John from group HR is allowed to access ftp.hr.com while Sam from group Sales is not allowed to access ftp.hr.com.
This is in a similar manner to the implementation described in the following link for http/https traffic.
https://support.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-secure-web-gateway-implementations-11-5-0/5.html
Is this possible for ftp as well as http/https?
Kindly Wasfi
4 Replies
- Brad_Parker
Cirrus
I do not believe so. FTP is a very different protocol that HTTP and the key part about SWG is the W for WEB. The only possibility would be to explicitly proxy FTP over HTTP which I don't think the BIGIP supports.
- sfuerst_116779Historic F5 Account
The BigIP can have a SOCKS explicit proxy virtual, that will allow proxying of FTP. I don't think this will work with authetication though.
- Wasfi_182818
Altostratus
I don't mean to state the obvious, but just to double check, do you need the SWG license for implementing SOCKS explicit proxy? - sfuerst_116779Historic F5 AccountI don't think you do. It is a LTM feature.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com