Forum Discussion

Albert__Tase_70's avatar
Albert__Tase_70
Icon for Nimbostratus rankNimbostratus
May 13, 2009

ftps issues

Hello

 

 

is there a way to resolve the following issue with an Irule.

 

I currently have a support case also opened on this issue.

 

 

we have the f5 in front of a firewall the servers sit behind the firewall and are routed to the f5 the f5 has the real server ips in the pool. I need to get the ftps to connect to ftp software globalScape I tired solution 9437 but by setting a masqerade ip on th ftp box to the external vip address still no dice. Cannot not use ip forwarding or l4 because server not directly connected is there any way with an irule to get around this if so how ?

 

 

 

Thanks

1 Reply

  • I have had this come up before and the only way to resolve was to do the following:

     

    1. Server needs to be in the same vlan as the BIG-IP (which you do not have)

     

    2. Attach the ftp virtual server IP to the loopback interface on the ftp server

     

    3. Configure FTP server to listen on the virtual server IP that is attached to its loopback interface

     

    4. Configure the virtual server to NOT translate IP.

     

    5. Server uses BIG-iP as the default gateway

     

     

    Since FTPS is secured between the client and the server, there is not much BIG-IP can do as a device in the middle without visibility into the FTP session.