Forum Discussion

Gary_Walderich_'s avatar
Gary_Walderich_
Icon for Nimbostratus rankNimbostratus
Sep 04, 2007

Any Luck with proxying FTPS or SFTP?

Has anyone had any luck with Proxying Secure FTP connections? Is this possible with the BigIP?

 

 

I currently have the latest and greatest 9.4.1 code with applied hotfix1.

 

 

-GW

3 Replies

  • BIG-IP (v4.X or v9.X) does not support FTPS (SSL) or SFTP (subprotocol of SSH2) with SSL acceleration. I think this is what you meant, and not pass-through LB as a generic TCP. Feature request via support is probably all that can be done at the moment. The more request there is, more likely it is to be approved and added as a feature.
  • Our back end servers were trying to establish outbound SFTP (FTP over SSL/TLS - not the sftp ssh subsystem) and the connections would hang trying to step up from FTP to SFTP.

     

     

    We had to set up a wild card forwarding vip to get things working. I wasn't trying to accelerate anything - I was just trying to get SFTP working through the LTM.
  • Did you every find a solution to this. We are experiencing the same issues. I was thinking that I could change the SNAT Packet forwarding from TCP and UDP only to All on the System->General Properties -> Local Traffic -> General but not sure if this will work. Also do not want to open any security risks. Any other ways to accomplish this for the specific servers behind the LTM?

     

     

    Thanks,

     

    Andrea