Forum Discussion

Ed_Summers's avatar
Ed_Summers
Icon for Nimbostratus rankNimbostratus
Oct 26, 2016

Outbound TCP port 21 through SNAT

BIGIP version 12.1.1 HF1

 

Issue: SNAT is not building server-side connections for a TCP session destined to port 21

 

A colleague was troubleshooting a customer complaint of an FTP connection not working. The source of traffic is an internal, privately-addresses server that is in a SNAT origin list. The destination is an external server that the BIGIP can reach via the default route. Basic IP connectivity had been confirmed via traceroute, which does work through the SNAT.

 

Tried a basic TCP connection (using Cisco ASA 'tcp ping' utility...it simply sends a TCP SYN, expects a SYN/ACK, then resets the connection). For connections to port 21, the BIGIP receives the traffic (confirmed via tcpdump) but does not build the server-side connection (observed both via tcpdump and the connection table). However trying to a different port using same source/destination is successful. Also tried using a different source address (destination port 21) which failed. Issue appears to follow the destination port.

 

Did some searching through and DevCentral but do not see the same issue addressed. Anyone run into this issue and have an explanation?

 

3 Replies