[f-nsp] PASV FTP behind Load Balancer

Reynald Mahinay rmahinay at valuecommerce.com
Tue Nov 18 23:52:30 EST 2008


Hi David,

You got it right and thanks for this info as I'm really having a
hardtime with the SI. Right now, I just bypass the LB as a workaround.
But I really like to sort this out using SI as a gateway to simplify the
setup.

Reynald

-----Original Message-----
From: david raistrick [mailto:drais at icantclick.org] 
Sent: Wednesday, November 19, 2008 1:34 PM
To: Wouter Prins
Cc: Reynald Mahinay; foundry-nsp at puck.nether.net
Subject: Re: [f-nsp] PASV FTP behind Load Balancer

On Tue, 18 Nov 2008, Wouter Prins wrote:

> NOTE: For servers that use passive FTP, configure the FTP ports to be
> both sticky and concurrent.

I believe the original poster is looking for information on OUTBOUND FTP

(server who's default gateway is the SI) not for INBOUND FTP which would

use a real/virtual.

>> I have a query regarding PASV ftp behind ServerIronXL. The scenario
would be
>> that a host behind the LB will initiate an FTP access to an external
server.


That said, I don't have any answers.....but so far in my experience, the

NAT support on the SI is garbage, both for outbound and inbound traffic.

They finally released a fix for broken traceroutes, but I haven't tested

it.  Hopefully I'll get a chance in a few weeks.

..david

---
david raistrick        http://www.netmeister.org/news/learn2quote.html
drais at icantclick.org             http://www.expita.com/nomime.html





More information about the foundry-nsp mailing list