SFTP Adapter Configuration - Basic

Use this screen to specify system-level communications information for SFTP connections to and from Secure Proxy.

Refer to the field definitions in the following table. You can set up a configured Proxy Adapter to multiple Secure Proxy engines so you can push one adapter configuration from the Configuration Manager to multiple engine instances.

To manage Secure Proxy engines with a configured Adapter:
  • Click Add Engine + to add a new engine to the configured adapter.
  • Click Copy to copy an existing engine to the configured adapter.
  • Click Remove to remove a specific engine to the configured adapter.

Field Name

Description

Adapter Name

Adapter Name identifies the name to assign to the adapter you create. Valid values are 1-150 alphanumeric characters with no spaces. Special characters allowed are period (.), dash (-), and underscore (_).

Description

Description assigns a description to help you identify the adapter you create. Description can be up to 255 characters.

Listen Port

Port number to use to listen for inbound connections. Valid values are between 1-65535.

Netmap

Netmap identifies the name of the netmap to associate with the adapter you are defining. If the netmap has not been created, click + to add the netmap.

Routing Type

Route requests from SFTP clients based on user ID or another type of user identification. Select one of the following choices:
  • Standard
  • Userid based — Only routes to a matching outbound node and matching routingNodeName identified in the LDAP. If the outbound node can not be determined, it will fail.
  • Userid based with a default fallback — Routes to a matching outbound node and matching routingNodeName identified in the LDAP; however, if there is no associated outbound node found, the will make the connection to the default outbound node.

Engine

Engine identifies the Secure Proxy server in the DMZ where the adapter will listen for inbound connections to be routed to the outbound node. Select an engine from the list. You must define an engine before you can create an adapter.

Inbound PS

Inbound Perimeter Server. Select the perimeter server for the inbound connection in the Perimeter Server Mapping - Inbound Perimeter Server field. To use a remote perimeter server, you must define the server before you associate it with an inbound connection.

Outbound PS

Outbound Perimeter Server. Select the perimeter server to use for the outbound connection in the Perimeter Server Mapping - Outbound Perimeter Server field. To use a remote perimeter server, you must define it before you can associate it with an outbound connection.

EA PS

External Authentication Perimeter Server. Select the perimeter server to use for the Sterling External Authentication Server connection in the Perimeter Server Mapping - External Authentication Perimeter Server field. To use a remote perimeter server, you must define it before you can associate it with an Secure Proxy connection.

EA Server

External Authentication Server. External Authentication Server identifies the server to use. Select the server from the pull-down list. You must define a Sterling External Authentication Server before you can select the server from the list.

ICAP Server for Incoming File Scan Select one of the already defined ICAP servers, which will be used to process anti virus and malware scanning requests.
ICAP Server for Outgoing File Scan Select one of the already defined ICAP DLP(Data Loss Prevention) servers, which will be used to process DLP(Data Loss Prevention) scanning requests.
ICAP PS

Select the ICAP Perimeter Server (PS), which will be used to connect to ICAP Server per engine basis for a given SFTP Adapter.

Startup Mode

Startup Mode identifies how the adapter is started. auto starts the adapter as soon as it is pushed to the engine. manual requires that the adapter be manually started.

Local Host Key Store

Local Host Key Store identifies the local host key store you created to store local host keys. Select the local host key store that contains the local host key to use to authenticate Secure Proxy to the inbound node connections.

Local Host Key

Local Host Key identifies the local host key you have added to the key store. Select the local host key from the drop-down list that will used to authenticate Secure Proxy to the inbound node connections. If you make changes to the local host key, you must restart the adapter before the change is recognized.