SFTP ISSUES

 We have faced couple of sftp connectivity issues in our non prod environments in the past one week. Here is brief description about the issues and how we resolved them.

Issue 1: sftp connection hangs without throwing any error.

Public ip of one of the third party applications we are connecting got changed. We sent change in firewall rule to our firewall team. Team made change post that too we were not able to connect sftp server. Here is the verbose output:

sftp -vvv -P 22222 user@104.x.x.x
OpenSSH_7.4p1, OpenSSL 1.0.2k-fips 26 Jan 2017
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: /etc/ssh/ssh_config line 58: Applying options for *
debug2: resolving “104.x.x.x” port 22222
debug2: ssh_connect_direct: needpriv 0
debug1: Connecting to 104.x.x.x [104.x.x.x] port 22222.
debug1: Connection established.
debug1: identity file /home/user/.ssh/id_rsa type 1
debug1: key_load_public: No such file or directory
debug1: identity file /home/user/.ssh/id_rsa-cert type -1
debug1: Enabling compatibility mode for protocol 2.0
debug1: Local version string SSH-2.0-OpenSSH_7.4


From above output, sftp was able to establish connection (see output in bold) but there is no response from sftp server and connection just hangs. Our initial efforts were focused on sftp server side. But later we found that as the port 22222 was non standard port for sftp, even though firewall allowed initial connection handshake, it blocked traffic once it identified that traffic was for ssh. It is standard practice in firewalls not to allow traffic on non standard ports for standard protocols for security reasons. Connection issue was resolved once exception policy was added to firewall.

Issue 2: Algorithm negotiation fail

This issue happened in one of our non-prod Boomi envs. sftp related flows were working fine on weekend. Come Monday, integrations flows were broken. We analyzed if there were any updates to Boomi or if Boomi process was restarted over weekend. None of it happened. We reported issue to sftp team and they told us that ssh cipher suites got changed on sftp server as per recommendation from security team. As these new cipher algorithms are not currently available with Boomi, we see sftp connection started failing. As a workaround, we requested team rollback changes while we work on permanent solution.

Comments

Popular posts from this blog

HOW WE REDUCED SOA OSB PROVISIONING FROM 4 DAYS TO 4 HOURS

NOT ABLE TO START RABBITMQ CLUSTER: CANNOT DECLARE A QUEUE ‘~S’ ON NODE ‘~S’: ~255P

SOA SUITE 12.2.1.4 INSTALLATION: GOT EXCEPTION WHEN AUTO CONFIGURING THE SCHEMA COMPONENT(S) WITH DATA OBTAINED FROM SHADOW TABLE