cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1171
Views
0
Helpful
2
Replies

ACE load balancing of SSH

dustin.black
Level 1
Level 1

I need to be able to load balance SSH connections from a single external IP address of our ACE module to any number of servers. I can't modify the SSH servers to make their encryption keys match, but I need to get around the problem of the key for the ACE IP appearing to change from the client's perspective. I'd like to be able to proxy the connection like I do for SSL, but I haven't found a way to do that.

Any suggestions are much appreciated!

2 Replies 2

owillins
Level 6
Level 6

If you want to use SLB only, you must configure certain parameters and disable some of the ACE security features .

perform the following things

"Configuring a global permit-all ACL and applying it to all interfaces in a context to open all ports

"Disabling TCP/IP normalization

"Disabling ICMP security checks

"Configuring SLB

Maybe I'm missing something, but how does that get around the problem of the client receiving different SSH encryption keys from the different load balanced servers?

Thanks!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card