Forum Discussion
Albert__Tase_70
Nimbostratus
May 13, 2009ftps issues
Hello
is there a way to resolve the following issue with an Irule.
I currently have a support case also opened on this issue.
we have the f5 in front of a firewall the servers sit behind the firewall and are routed to the f5 the f5 has the real server ips in the pool. I need to get the ftps to connect to ftp software globalScape I tired solution 9437 but by setting a masqerade ip on th ftp box to the external vip address still no dice. Cannot not use ip forwarding or l4 because server not directly connected is there any way with an irule to get around this if so how ?
Thanks
1 Reply
- johns
Employee
I have had this come up before and the only way to resolve was to do the following:
1. Server needs to be in the same vlan as the BIG-IP (which you do not have)
2. Attach the ftp virtual server IP to the loopback interface on the ftp server
3. Configure FTP server to listen on the virtual server IP that is attached to its loopback interface
4. Configure the virtual server to NOT translate IP.
5. Server uses BIG-iP as the default gateway
Since FTPS is secured between the client and the server, there is not much BIG-IP can do as a device in the middle without visibility into the FTP session.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects