Primeur Online Docs
Data Mover 1.20
Data Mover 1.20
  • ๐Ÿš€GETTING STARTED
    • What is Primeur Data Mover
    • Main features of Primeur Data Mover
    • Primeur Data Mover deployment
    • Navigate through Primeur Data Mover
  • ๐Ÿ‘ฅActors
    • Who are the actors
    • Create your first actor
    • Configure an actor ๐Ÿš€
      • Users Tab
      • Groups Tab
      • VFS Tab
      • File Resource Tab
      • Connection Contract Tab
      • Client Connections Tab
    • Search files by actor
    • Actor Lineage ๐Ÿš€
      • Aggregation of flows by protocol ๐Ÿš€
      • Lineage with connection contracts ๐Ÿš€
      • Lineage with input, mediation and output contracts ๐Ÿš€
      • Lineage with any contract type ๐Ÿš€
  • ๐Ÿ“Contracts
    • What is a contract
    • Create your first contract
      • Create an Input Contract
        • Define the contract info
        • Associate the contract with the actor
        • Define the contract actions
        • Set the contract variables
      • Create a Mediation Contract
      • Create an Output Contract
      • Create a Connection Contract
        • Create a contract clause
        • Associate the VFS with file processing rules
        • File Processing Rules
    • Managing contracts ๐Ÿš€
  • ๐ŸงฑWorkflows
    • What is a workflow
    • Create your first workflow template
    • Trigger types
      • Trigger types for input contracts
      • Trigger types for mediation and output contracts
    • Service tasks
      • Standard service tasks
      • Triggerable service tasks ๐Ÿš€
      • Spazio selectors and filebox metadata management
      • Error management
    • Variables
      • Variables in workflows and contracts
      • Handling process variables
    • Workflow templates
      • System workflow templates
        • Workflow templates for input contracts
        • Workflow templates for mediation contracts
        • Workflow templates for output contracts
      • Custom workflow templates
        • Workflow template toolbar
        • Workflow template Shape repository panel
        • Workflow template working area
        • Workflow template BPMN-diagram panel
      • Error workflow templates
    • Editing workflow templates
    • DataFlow Instance Context (DFIC) ๐Ÿš€
  • ๐Ÿ”“Security
    • Identity and Access Management
    • Users & Groups
      • Setting the password policy
      • Creating Internal Users ๐Ÿš€
      • Creating Internal Groups
      • Creating External Users
      • Creating External Groups
    • Key Stores and Trust Stores
      • Key Store ๐Ÿš€
        • Creating a Key ๐Ÿš€
        • Creating a Certificate ๐Ÿš€
        • Importing a Key or a Certificate
        • Creating a Symmetric key
        • Examples
      • Trust Store ๐Ÿš€
        • Importing Keys ๐Ÿš€
        • Importing Certificates
      • Untrusted Cache ๐Ÿš€
      • Trusting an element
        • When do I use the Keys tab?
        • When do I use the Certificates tab?
      • PGP Key Store / PGP Trust Store
        • Configuring the PGP Key Store
        • Importing keys into the PGP Trust Store
  • ๐Ÿ›ธTRANSPORT PROTOCOLS AND CONNECTORS
    • Data Mover client and server roles
    • Client Connections
      • Client Connection: FTP
      • Client Connection: FTPS
      • Client Connection: SFTP
      • Client Connection: HTTP
      • Client Connection: HTTPS
      • Client Connection: PESIT
      • Client Connection: SMB v3 or later versions
      • Client Connection: POP3 IMAP
      • Client Connection: SMTP
      • Client Connection: PR4/PR4S
      • Client Connection: PR5
      • Client Connection: PR5S
      • Client Connection: HDFS
      • Client Connection: HDFSS
      • Client Connection: Amazon S3 ๐Ÿš€
      • Client Connection: Google Cloud Storage
        • Credentials
      • Client Connection: Azure Blob Storage
      • Client Connection: IBM Sterling Connect:Direct
      • Appendix
    • Server Connections ๐Ÿš€
      • Server Connection: FTP
      • Server Connection: FTPS
      • Server Connection: SFTP
      • Server Connection: HTTP
      • Server Connection: HTTPS
      • Server Connection: PeSIT
      • Server Connection: PR4
      • Server Connection: PR5
      • Server Connection: PR5S ๐Ÿš€
      • Server Connection: IBM Sterling Connect:Direct
    • Stopping all servers in one go
  • ๐Ÿ›ฐ๏ธDMZ GATEWAYS
    • DMZ Gateways
    • DMZ Clusters
  • ๐ŸŽงFILE EVENT LISTENER
    • What is the File Event Listener
    • Configuring File Event Listeners
      • Setting the File Event Listener Engine
      • Defining a contract for the File Event Listener
      • Setting events to be monitored
    • RegEx Rules ๐Ÿš€
    • Monitoring File Event Listeners
  • ๐Ÿ”ICAP
    • ICAP Engines
    • Configuring an ICAP Engine
    • Defining an ICAP rule
  • ๐Ÿ“šCLUSTERING
    • STENG, Clusters and Servers
    • Adding a cluster and a STENG
    • Deleting a STENG
  • ๐Ÿ•’MONITORING
    • Jobs
      • Details about Jobs ๐Ÿš€
      • jobman.sh CLI
    • Job Manager
    • Job Queues
      • Managing Job Queues
    • File Transfers
      • Ongoing
      • Finished
      • Reports
    • File Transfers Rules
      • Configuring Rules
  • ๐Ÿค“ADMINISTRATION
    • Storage Classes ๐Ÿš€
      • Storage Class: File System ๐Ÿš€
      • Storage Class: SMB v3 or later versions ๐Ÿš€
      • Storage Class: Amazon S3 ๐Ÿš€
      • Storage Class: Google Cloud Storage ๐Ÿš€
      • Storage Class: Azure Blob Storage ๐Ÿš€
    • Retention Classes
    • Virtual File Systems (VFS) ๐Ÿš€
      • Creating a VFS ๐Ÿš€
      • Configuring a VFS
      • Adding Virtual Paths
      • Modifying and Deleting a VFS
      • Searching files in all VFS
    • File Resources
      • Creating File Resources
      • Navigating File Resources
      • How to use File Resources
    • Advanced Settings
  • ๐Ÿ‘‘FILE MANAGER
    • Getting started
    • Logging into File Manager
    • Managing the File Manager ๐Ÿš€
      • The list of results
      • Creating new folders
      • Uploading files
      • Downloading files ๐Ÿš€
      • Searching for files and folders
      • Deleting files ๐Ÿš€
      • Bulk actions ๐Ÿš€
    • File Manager and VFS
    • Customizing File Manager externals
      • The configuration-wui.json file ๐Ÿš€
      • How to customize the Login window and the logo
      • How to customize the footer
      • How to configure the Upload with Metadata option
      • How to customize bulk actions ๐Ÿš€
  • ๐Ÿง‘โ€โš–๏ธFILE ROUTING
    • What is File Routing ๐Ÿš€
    • Routing Rules page
      • The Rules tab
      • The Categories tab
      • The Output tab
    • How to create a rule ๐Ÿš€
      • Add metadata ๐Ÿš€
      • Select ACTIONS
      • Select OUTPUTS
      • Policy for the selection of metadata rules
    • Configuration of the environment in Data One
      • Set up Storage Classes
      • Set up Retention Classes
      • Configure the Actor
      • Set up File Resources
    • Associate the Routing Rule with a Contract
    • Example
  • ๐Ÿ’ฌLOGS & AUDIT
    • Logs ๐Ÿš€
      • Logs options ๐Ÿš€
      • Troubleshooting error analysis in Logs
    • Audit Options ๐Ÿš€
      • Export audit logs ๐Ÿš€
      • List of Audit entity types ๐Ÿš€
      • Audit message codes ๐Ÿš€
    • Log Notifiers ๐Ÿš€
      • FEL message codes
  • ๐Ÿ“ฉNOTIFICATION CHANNELS
    • What are Notification Channels
    • Configuring the default Email Notification Channel
    • Configuring a new Email Notification Channel
    • Trusting Certificates
    • Managing Templates
      • Data Watcher Macros
      • Contract Macros
      • ICAP Macros
      • Central Log Macros
      • Email Templates
      • Editing default templates
      • Loading a new template
  • ๐ŸŸฃDATA MOVER + DATA WATCHER
    • Data Mover in a bundle with Data Watcher
    • Attributes ๐Ÿš€
    • Cut-off Board
      • Cut-off Calendars
    • Dataflow Inquiry
  • ๐ŸŸ DATA MOVER + DATA SHAPER
    • Data Mover in a bundle with Data Shaper
    • Monitoring
    • Execution History
    • Sandboxes
  • ๐Ÿ’ปAPI
    • HTTP MFT Rest API
    • Job Manager APIs ๐Ÿš€
    • SFTP Server sessions APIs ๐Ÿš€
    • Audit Logs APIs ๐Ÿš€
  • ๐ŸงHOW TO...
    • ... use different DNS names - NEW! ๐Ÿš€
    • ... configure a Cron Expression
    • ... configure an Application
    • ... customize a header
    • ... run searches in Data Watcher ๐Ÿš€
    • ... use Data Shaper graphs in Data Mover contracts
    • ... modify DMCFG and deploy it
    • ... tune Data One data retention
  • ๐Ÿ—’๏ธRELEASE NOTES
    • Data One 1.20.10
    • Data One 1.20.9
    • Data One 1.20.8
    • Data One 1.20.7
      • Data One 1.20.7.1
    • Data One 1.20.6
    • Data One 1.20.5
    • Data One 1.20.4
    • Data One 1.20.3
    • Data One 1.20.2
    • Data One 1.20.1
    • Data One 1.20.0
Powered by GitBook
On this page
  1. TRANSPORT PROTOCOLS AND CONNECTORS
  2. Server Connections ๐Ÿš€

Server Connection: FTPS

Fields with the asterisk * are mandatory.

Value
Description

PORT *

Enter the port to connect to the server. This is the TCP/IP port the server will listen to in the STENG node.

PORT RANGE

Enter the range for the ports the server will listen to.

SERVER KEYLABEL *

Enter the Key identifier about keystore store to select Private Key and Certificate to create SSL connection.

ACTIVE DATA CONNECTION LOCAL ADDRESS

Enter the local address for active data connection.

PASSIVE EXTERNAL ADDRESS

This field must be filled in only if OPERATING MODE is set to PASSIVE and will contain the address used for passive connections. If the server is behind NAT, insert the external IP address.

MAX SESSION

Specify the maximum number of active sessions.

CONNECTION TIMEOUT

Define the number of seconds without network activity to wait before closing a session due to inactivity. Default value: 60.

ACTIVE DATA CONN LOCAL OUTPORT

If the OPERATING MODE is set to ACTIVE, enter the port the client must connect to.

REQUIRE CLIENT AUTHENTICATION

Enable the toggle button if you want the server to require SSL Client Authentication to the client that is connecting. If enabled, the CLIENT CERTIFICATION MATCH field appears and the appropriate option must be selected in the drop-down menu โ€“ details in the field here below.

CLIENT CERTIFICATION MATCH

This field appears if the REQUIRE CLIENT AUTHENTICATION button is enabled. It defines if the Certificate required for Client Authentication will be matched and how. Possible values: - NONE: the Certificate will not be matched. The presence of a valid Certificate is enough to proceed. This is the less secure option. - CNEQUALS (default value): the Common Name field of the Certificate must be exactly the same as the user name. This is the most restrictive option. - CNCONTAINS: the Common Name field of the Certificate must contain the user name.

OPERATING MODE

How data connection is established, possible values: - ACTIVE (default value) - PASSIVE When setting the โ€œActive mode file transferโ€, the client will establish a control connection to the server and the server will establish a data connection back to the client. With โ€œPassive mode file transferโ€, the client will establish both a control connection and a data connection to the server.

DATA PROTECTION

Data channel protection. Possible values: - PROTECTED: Force data channel protection - CLEARTEXT: No data channel protection

SSL CONTROL

Possible values: - EXPLICIT (recommended) - IMPLICIT Selecting EXPLICIT, an explicit SSL/TLS connection will be set via AUTH command. Selecting IMPLICIT, an implicit SSL/TLS connection will be set. Most FTP/S Servers listen for implicit connections to port 990.

AUTHENTICATION PROTOCOL

Select the SSL authentication protocol. Possible values: - ALL - ONLY SPECIFIC VALUES: SSLv3 TLSv1 TLSv1_1 TLSv1_2 TLSv1_3 SSLv2Hello

ACCEPTED CIPHER SUITES

DMZ mode

NONE (default)

No session proxying through DMZ Gateway applied.

PORT_FORWARDING

Incoming/Outgoing connections to/from STENG server will be proxied inside an SSL tunnel without being validated in advance. DMZ PROXY PORT *: This port represents the tunnel that is opened for connection with the STENG Server.

SESSION_TERMINATION

๐Ÿš€ To change any DMZ port of an FTPS server that belongs to a peer, select the server you want to update. Next, click the pencil icon in the top-right corner of the server card. Enter the new port or ports in the appropriate fields. Finally, click the SAVE button to confirm your changes. Remember that the new port number will only affect the peer's selected server.

PreviousServer Connection: FTPNextServer Connection: SFTP

Last updated 1 day ago

Select the cipherSuites accepted to establish SSL connection. For a list of all accepted Cipher Suites, follow this .

The server session will be terminated inside the DMZ Gateway, before data is sent to STENG server. DMZ PROXY PORT *: This port represents the tunnel that is opened for connection with the STENG Server. SERVER PORT *: DMZ server port used for connection. SERVER KEYLABEL: Select the label of private key to be used by the FTPS server exposed in the DMZ Gateway. REQUIRE CLIENT AUTHENTICATION: Enable the toggle button if you want the server to require SSL Client Authentication to the client that is connecting in DMZ. If enabled, the DMZ CLIENT CERTIFICATION MATCH field appears and the appropriate option must be selected in the drop-down menu โ€“ details in the field here below. If the FTPS client on DMZGateway is connecting to an FTPS Server with clientAuthentication=true on the STENG, check the client certificate coming from the client FTPS into the Untrusted Cache. Then trust the client certificate and check the Trust Store. DMZ CLIENT CERTIFICATION MATCH: This field appears if the Require Client Authentication button is enabled. It defines if the Certificate required for Client Authentication will be matched and how. Possible values: - NONE: the Certificate will not be matched. The presence of a valid Certificate is enough to proceed. This is the less secure option. - CNEQUALS (default value): the Common Name field of the Certificate must be exactly the same as the user name. This is the most restrictive option. - CNCONTAINS: the Common Name field of the Certificate must contain the user name. ACCEPTED CIPHER SUITES: It lists SSL/TLS cipher suites available in the FTP/S server and exposed in the DMZ Gateway. Select the cipherSuites accepted. For a list of all accepted Cipher Suites, follow this . DATA PROTECTION: Set whether the data channel must be protected via SSL in the FTP/S server exposed in DMZ Gateway. Possible values: - PROTECTED: Force data channel protection - CLEARTEXT: No data channel protection SECURITY PROTOCOL: Possible values: - ALL - ONLY SPECIFIC VALUES: SSLv3 TLSv1 TLSv1.1 TLSv1.2 SSLv2Hello SSL PROTOCOL: Select a secure server profile activation mechanism in FTP/S server exposed in DMZ Gateway (see Connection/SSL Control). DMZ PASSIVE EXTERNAL ADDRESS: When an FTP/S client wants transfer data using Passive Mode, it issues the PASV command. Upon receiving that command, the FTP/S server responds with the serverโ€™s IP address and the port number the client must connect to. DMZ PORT RANGE: Range of ports for passive data connection.

๐Ÿ›ธ
link
link