Forum Discussion

Felix_29330's avatar
Felix_29330
Icon for Nimbostratus rankNimbostratus
Apr 12, 2011

FTPS Load-balancing Problem

Hi,

 

 

I have setup an LTM to load-balance traffic to 2 FTPS servers.

 

 

The FTPS client works fine when it connects directly to the individual servers, however it fails when it connects to the VIP address.

 

 

When the client connects to the FTPS on the VIP, it successfully connects and authenticates, but there is always a "Connection timed out" error after it issues the 'LIST' command.

 

 

Sometimes it also generates the error "A TLS packet with unexpected length was received" after issuing the LIST command, for which reason directory listing fails.

 

 

My LTM setup

 

 

- The LTM is setup not to terminate the SSL session but to 'pass-through' directly to the FTPS servers.

 

 

- I have a virtual server that listens on port 990 and maps to a Pool consisting of the two FTPS servers, port 990

 

 

- I also have another virtual server (same VIP) that listens on port * and maps to a pool consisting of the two FTPS servers, port * so that any negotiated data transfer port can be captured by the LTM.

 

 

The FTPS client operates in Passive mode.

 

 

I would appreciate any assistance and experiences you can share to help me resolve this problem.

 

 

Thanks. Felix

 

 

 

 

 

 

7 Replies

  • not sure if u've seen this one.

     

     

    sol9347: Configuring passthrough FTPS load balancing

     

    http://support.f5.com/kb/en-us/solutions/public/9000/300/sol9347
  • not sure if u've seen this one.

     

     

    sol9347: Configuring passthrough FTPS load balancing

     

    http://support.f5.com/kb/en-us/solutions/public/9000/300/sol9347
  • Hi Nitass,

     

     

    I applied the solution in your given reference and it worked.

     

     

    It's been a relief. Thanks so much.

     

     

    Felix

     

  • Hi,

     

    I have tried to replicate solution provided within SOL9347 but its not working.

     

    Can I get some help over here?

     

    Regards,