ACE load balancing of SSH

Unanswered Question
Nov 21st, 2007

I need to be able to load balance SSH connections from a single external IP address of our ACE module to any number of servers. I can't modify the SSH servers to make their encryption keys match, but I need to get around the problem of the key for the ACE IP appearing to change from the client's perspective. I'd like to be able to proxy the connection like I do for SSL, but I haven't found a way to do that.

Any suggestions are much appreciated!

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
owillins Tue, 11/27/2007 - 12:57

If you want to use SLB only, you must configure certain parameters and disable some of the ACE security features .

perform the following things

"Configuring a global permit-all ACL and applying it to all interfaces in a context to open all ports

"Disabling TCP/IP normalization

"Disabling ICMP security checks

"Configuring SLB Tue, 11/27/2007 - 14:00

Maybe I'm missing something, but how does that get around the problem of the client receiving different SSH encryption keys from the different load balanced servers?



This Discussion