Forum Discussion

Kirit_Patel_521's avatar
Kirit_Patel_521
Icon for Nimbostratus rankNimbostratus
Feb 17, 2016

Active ftp outbound fails on LTM code 11.5.3

ALL

 

I migrated to f5 from Cisco CSS and my active outbound ftp broke. When I capture packets I see it failing because the NAT translation is not happening on F5. In my capture i see 172.16.82.11 address instead of 172.16.86.21 address . what am i missing?

 

Here is my config

 

ltm pool /Finance/mhf_pool_172.16.86.21-ftp { members { /Finance/172.16.82.11:11021 { address 172.16.82.11 } /Finance/172.16.82.11:21021 { address 172.16.82.11 } /Finance/172.16.82.11:31021 { address 172.16.82.11 } /Finance/172.16.82.12:11021 { address 172.16.82.12 } /Finance/172.16.82.12:21021 { address 172.16.82.12 } /Finance/172.16.82.12:31021 { address 172.16.82.12 } } monitor /Common/tcp_half_open

 

ltm virtual /Finance/mhf_172.16.86.21-ftp { auto-lasthop disabled destination /Finance/172.16.86.21:21 ip-protocol tcp mask 255.255.255.255 pool /Finance/mhf_pool_172.16.86.21-ftp profiles { /Common/ftp { } /Common/tcp { } } source 0.0.0.0/0 translate-address enabled translate-port enabled }

 

ltm snat /Finance/snatoutpool { auto-lasthop disabled origins { 172.16.82.11/32 { } 172.16.82.12/32 { } 172.16.82.13/32 { } 172.16.82.14/32 { } } translation /Finance/172.16.86.21 vlans { /Common/VLAN2 } vlans-enabled

 

ltm snat-translation /Finance/172.16.86.21 { address 172.16.86.21 traffic-group /Common/traffic-group-1 }

 

ltm snatpool /Finance/SNAT_172.16.86.21 { members { /Finance/172.16.86.21 } }

 

The virtual server in question is mhf_172.16.86.21.-ftp