Forum Discussion
SSH forward proxy
- Jun 15, 2025
Hi Mike12345
Answer is NO. It is NOT possible to use a single F5 Virtual Server to inspect the SSH stream and direct sessions to different backend servers based on hostname or similar identifiers, because this information is encrypted and not available for inspection by the F5 device.
General SSH protocol behavior, confirmed in F5 KB K14806: Overview of the BIG-IP system as a reverse proxy for SSH (https://support.f5.com/csp/article/K14806)
AFM has an SSH proxy where you can send SSH to a pool of backend SSH servers. You could do this with different addresses or ports and use an iRule to send the serverside pool. SSH doesn't have a way to carry the destination server inside the packet in the way that the HTTP Host header works.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com