Active ftp outbound fails on LTM code 11.5.3
ALL
I migrated to f5 from Cisco CSS and my active outbound ftp broke. When I capture packets I see it failing because the NAT translation is not happening on F5. In my capture i see 172.16.82.11 address instead of 172.16.86.21 address . what am i missing?
Here is my config
ltm pool /Finance/mhf_pool_172.16.86.21-ftp { members { /Finance/172.16.82.11:11021 { address 172.16.82.11 } /Finance/172.16.82.11:21021 { address 172.16.82.11 } /Finance/172.16.82.11:31021 { address 172.16.82.11 } /Finance/172.16.82.12:11021 { address 172.16.82.12 } /Finance/172.16.82.12:21021 { address 172.16.82.12 } /Finance/172.16.82.12:31021 { address 172.16.82.12 } } monitor /Common/tcp_half_open
ltm virtual /Finance/mhf_172.16.86.21-ftp { auto-lasthop disabled destination /Finance/172.16.86.21:21 ip-protocol tcp mask 255.255.255.255 pool /Finance/mhf_pool_172.16.86.21-ftp profiles { /Common/ftp { } /Common/tcp { } } source 0.0.0.0/0 translate-address enabled translate-port enabled }
ltm snat /Finance/snatoutpool { auto-lasthop disabled origins { 172.16.82.11/32 { } 172.16.82.12/32 { } 172.16.82.13/32 { } 172.16.82.14/32 { } } translation /Finance/172.16.86.21 vlans { /Common/VLAN2 } vlans-enabled
ltm snat-translation /Finance/172.16.86.21 { address 172.16.86.21 traffic-group /Common/traffic-group-1 }
ltm snatpool /Finance/SNAT_172.16.86.21 { members { /Finance/172.16.86.21 } }
The virtual server in question is mhf_172.16.86.21.-ftp