Forum Discussion

Angel_Martinez_'s avatar
Angel_Martinez_
Icon for Nimbostratus rankNimbostratus
Nov 05, 2007

MS Firewall Client - BigIP LTM - ISA Server

Hi

 

 

We're having problems to set up a Virtual Server for load balancing of ISA Servers.

 

 

For the web traffic the virtual server works right but we can't do a FTP session.

 

 

We have set up 3 VS

 

 

VS:80

 

pool

 

ISA Server1

 

ISA Server2

 

 

VS:21 with a profile ftp.

 

pool

 

ISA Server1

 

ISA Server2

 

 

VS:1745 for the Firewall Client protocol.

 

pool

 

ISA Server1

 

ISA Server2

 

 

We're sure that someone had the same problem before.

 

 

Could you give us any help, please?

 

 

Thank you in advanced

 

 

 

4 Replies

  • Deb_Allen_18's avatar
    Deb_Allen_18
    Historic F5 Account
    For normal FTP connections over 21/20 all you should need to define is the ftp profile.

     

     

    Are both active & passive FTP failing?

     

     

    I'd start by taking a close look at a packet trace to see what's actually happening on the serverside flow.

     

     

    /deb
  • we're having a similar issue.

     

    trying to do Active FTP with a vendor.

     

    FTP works great from the LTM.

     

    Works 10% of the time from the ISA servers via a SNAT, not automap.

     

     

    any suggestions would be great.
  • Can any one confirm that it is possible to load balance the ISA/TMG Firewall Client traffic on port 1745 using a standard F5 VIP

     

    If I try it the connection opens and closes immediately. The ISA/TMG server shows the port 1745 connection, the encapsulated ftp connection and an immediate close on both.

     

    If it is possible, what general configuration do you use on the F% VIP

     

    Thanks

     

    Steve

     

    • Steve_A_130918's avatar
      Steve_A_130918
      Icon for Nimbostratus rankNimbostratus
      Just for info, the connection through the TMG, without going via the F5, works correctly.