Forum Discussion

Mike_Maher's avatar
Mike_Maher
Icon for Nimbostratus rankNimbostratus
Mar 27, 2014

SFTP Security with Big-IP

I am wondering what sort of security I can provide for an SFTP connection coming into my enviroment. Looking at PSM I see I can control what commands are being send over an FTP connection, but I am looking to control what directories you can GET data from and what directories you can PUT data to. Does anyone know if this is possible, and what type of licensing is needed to make it work. I am running 11.4.1 so maybe LT Policies might buy me something?

 

1 Reply

  • If by "SFTP" you mean SSH File Transfer Protocol, that's going to be tough to do. There's no direct support for decrypting SSH traffic. FTPS would probably be easier, as we could certainly offload the SSL.