LTM: Configuring outgoing (passive) FTP connections
I have a number of internal nodes behind a LTM (11.4.1 HF3) using non-routable IP addresses. These nodes need to connect to external FTP servers to retrieve data from them using passive FTP.
The only thing I was planning to do then was to configure a SNAT on the LTM to permit those internal nodes to get a routable IP address so that they can reach the FTP destination for the control and data port connections.
The question I have is if configuring a SNAT is all I need to do, or if there is any sort of limitation in the F5 unit that requires doing something else.
The reason for the question is because I found some links in support.f5.com that seem to tell something is not ok with FTP but i still dont get what is wrong with the setup i was planning for my specific case.
Thanks in advance!
Just to finish this topic, i have configured a SNAT only and FTP works perfectly for outgoing connections initiated from members in the internal realm.
For reference, this is the SW build I ended up using:
Main Package Product BIG-IP Version 11.4.1 Build 711.0 Edition Hotfix HF11 Date Tue Aug 30 12:18:51 PDT 2016