3.3 SFTP Proxy
SFTP Proxy
“Managing devices” rules are used for SSH/TELNET proxies. The “Device Access Protocol” is set as “SFTP” to connect to a device via the Single Connect SFTP Proxy.
Also, in order to enable SFTP access for devices which have already been defined with SSH; a parameter must be set for user groups.
Firstly, the device that is required for both SFTP and SSH is added with SSH access protocol (see also: Managing device). Then,
- Log in to the Single Connect Web GUI
- Navigate to User Management > User Accounts > User Group Definition
- Right-click on the user group and select Show properties
- Set the
Connection to Single Connect SFTP Proxy
Users can establish SFTP connection with multiple options which are described below:
With a global user:
When a Single Connect user with privileged access (like root or admin) connects to devices, they can connect to those devices without knowing the privileged user password. The Global Username should be defined to use this feature. Settings can be found from Managing devices.
There are 3 ways to connect to a device with a global username:
- Global Password: Set
- SAPM Password: If there is an SAPM account defined for the global user and the device that user wants to connect to.
- SSH Key: Set
When connecting to a device with a global username via SFTP proxy, the priority rules applied are below:
- If there is a defined SAPM account, the SAPM password is used as the password for the Global User as first priority.
- If the SAPM account is not defined, the global SSH Key is used to connect the device as second priority
- If these two options are not defined in the device properties, the global password is used for the connection to the device. Global password has the least priority.
With local or LDAP user:
If the Global Username is not defined in the device properties, Single Connect user can connect to devices that have access with Single Connect credentials.
Note |
|---|
To ensure this connection type with local or LDAP users, Single Connect users’ credentials should be defined in the target devices. |
Device Group Properties for SFTP Proxy:
Property Key | Definition |
|---|---|
globalUsername | The username to use when connecting to all devices covered by the device group. This username must be pre-defined as a user on all devices in the device group. |
globalPassword | It is the password of the “globalUsername” The password to use when connecting to all devices covered by the device group. |
globalSshKey | This property applies to SSH and SFTP Proxies in Session Manager Modules. If connecting to devices with an SSH Key is preferred, “globalSshKey” should be defined for the Device Group. |
When the “addSessionUserToUserSelection”, “addManualLoginToUserSelection” and “GlobalUsername” properties are defined for a Device group, the connection options are listed below:
Users can use their own SFTP clients to connect to a Single Connect Proxy. To connect to a Single Connect SFTP Proxy, type Single Connect’s IP address as the host IP address and 3333 as the connection port. (3333 is default SSH/Telnet Proxy Port. The port number can be changed by system administrator.)
Managerial Approval for User connecting to SFTP device
To enable managerial approval via e-mail or mobile notification for users connecting to devices, the “approvalRequiredForConnection” property must be set as “true” on the device group that has the target devices.
SFTP Proxy Encryption and Key Exchange Algorithms
Please ask consultation from Kron Technical Support [email protected]