Forum Discussion
Manage SFTP with iRule
- Nov 12, 2014
Yes, an http profile on a non http protocol will break the connection. The http profile is going to validate the data meets http specifications, and it will not.
I don't think you can enable/disable/change the HTTP profile in an irule(I assumed you could when I said it above, but after further research it appears you can't), so a separate port 22 vip is probably required. I think you can keep your port 0 vip and just add a port 22 vip for sftp. If I remember correctly it will use the port 22 vip when it matches that port, and the port 0 vip for everything else. The the entire need for the irule goes away.
No other rules are affecting the SFTP connection. I can see the TCP handshake reaching the VIP but nothing on the server side. Shouldn't the handshake be between the server and the client?
As it is now the handshake happens between client and VIP. Is their some kind of other setting in F5 causing this? F5 is currently configured as SSL offload for HTTP traffic but since this is not the same protocol used in SFTP could it really mather?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
