Skip to content

Gateway

This manual lists all the configurations that the S-Filer Portal's Configuration CLI can change about the Gateway.

Configuration keyDescriptionDefault value
cfg.babelone.gateway.gui.interface.deploy
Available in2.1.0 +
Turning on this option will automatically start a web interface on the gateway. This web interface will be on the same port as the HTTPS protocol. To be able to use this interface, you will have to create the configuration on the serverfalse
cfg.gateway.server.url
Available in4.1.4 +
URL used by gateway for the communication with the server, e.g., http://localhost:8088/
ftp.external.address
Available in4.2.26 +
This is the address sent in response to PASV command. It should be visible to clients of the FTP(S) server. You should specify this address if the server has multiple network interfaces or is behind "port forwarding" equipment. Leave blank to use the server address.
ftp.server.enable
Available in2.1.0 +
Turn on or off the FTP Server.false
ftp.server.ip
Available in4.8.2 +
IP address where the FTP Server listens for incoming connection request. (Default value is 0.0.0.0 to listen on all interfaces)0.0.0.0
ftp.server.passive.ports.end
Available in4.1.2 +
The end of the range of data ports for passive FTP transfers. This range can overlap the range for FTPS. A too small range will limit the number of concurrent transfers. A range too large will require opening many ports on the firewall.60020
ftp.server.passive.ports.start
Available in4.1.2 +
The start of the range of data ports for passive FTP transfers. This range can overlap the range for FTPS. A too small range will limit the number of concurrent transfers. A range too large will require opening many ports on the firewall.60000
ftp.server.port
Available in2.1.0 +
Port number where the FTP Server listens for incoming connection request. (Standard default value is 21).21
ftps.cipher.management.mode
Available in4.6.1 +
Determines how SSL/TLS ciphers are managed. S-Filer maintains a list of strong ciphers that will evolve over time. The 'Automatic' mode allows to enable only the strong ciphers from this list. For some older clients, weaker ciphers may need to be enabled because they don't support any of the strong ones. The 'JVM Default' mode results in all ciphers present on the JVM to be enabled. For a more fine-grained control, the 'Custom' mode allows to specify all the ciphers that must be enabled in the 'Custom SSL/TLS ciphers' parameter.AUTOMATIC
ftps.custom.ciphers
Available in4.17.0 +
List of SSL/TLS ciphers (separated by comma) that will be enabled if the cipher management mode is 'Custom'. WARNING: Some ciphers specified in this list may not be available depending on the key type of the SSL/TLS private key.TLS_AES_128_GCM_SHA256,TLS_AES_256_GCM_SHA384,TLS_CHACHA20_POLY1305_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256,TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_DHE_RSA_WITH_AES_256_GCM_SHA384,TLS_DHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
ftps.server.enable
Available in2.1.0 +
Turn on or off the FTPS Server.false
ftps.server.ip
Available in4.8.2 +
IP address where the FTP Server listens for incoming connection request. (Default value is 0.0.0.0 to listen on all interfaces)0.0.0.0
ftps.server.passive.ports.end
Available in4.1.2 +
The end of the range of data ports for passive FTPS transfers. This range can overlap the range for FTP. A too small range will limit the number of concurrent transfers. A range too large will require opening many ports on the firewall.60020
ftps.server.passive.ports.start
Available in4.1.2 +
The start of the range of data ports for passive FTPS transfers. This range can overlap the range for FTP. A too small range will limit the number of concurrent transfers. A range too large will require opening many ports on the firewall.60000
ftps.server.port
Available in2.1.0 +
Port number where the FTPS Server listens for implicit connection request. (Standard default value is 990).990
ftps.server.port.explicit
Available in4.1.2 +
Port number where the FTPS Server listens for explicit connection request. (Standard default value is 21, same as FTP).21
ftps.server.private.key
Available in4.9.0 +
SSL/TLS private key for the FTPS server.jetty
http.server.enable
Available in2.1.0 +
Turn on or off the HTTPS server.false
http.server.ip
Available in4.8.2 +
IP Address where the HTTPS server listens for incoming connection request. (Default value is 0.0.0.0)0.0.0.0
http.server.port
Available in2.1.0 +
Port number where the HTTPS server listens for incoming connection request. (Default value is 443 or 80).8081
http.server.private.key
Available in4.9.0 +
SSL/TLS private key for HTTPS server.jetty
http.ssl
Available in2.1.0 +
Determines whether to use the SSL Protocol.true
http.ssl.cipher.management.mode
Available in4.6.1 +
Determines how SSL/TLS ciphers are managed. S-Filer maintains a list of strong ciphers that will evolve over time. The 'Automatic' mode allows to enable only the strong ciphers from this list. For some older clients, weaker ciphers may need to be enabled because they don't support any of the strong ones. The 'JVM Default' mode results in all ciphers present on the JVM to be enabled. For a more fine-grained control, the 'Custom' mode allows to specify all the ciphers that must be enabled in the 'Custom SSL/TLS ciphers' parameter.AUTOMATIC
http.ssl.custom.ciphers
Available in4.17.0 +
List of SSL/TLS ciphers (separated by comma) that will be enabled if the cipher management mode is 'Custom'. WARNING: Some ciphers specified in this list may not be available depending on the key type of the SSL/TLS private key.TLS_AES_128_GCM_SHA256,TLS_AES_256_GCM_SHA384,TLS_CHACHA20_POLY1305_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256,TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_DHE_RSA_WITH_AES_256_GCM_SHA384,TLS_DHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
http.ssl.sni.host.check
Available in4.19.0 +
Determines if the SSL/TLS SNI host check is enabled. SNI (Server Name Indication) is an extension to the SSL/TLS protocol by which a client indicates which hostname it is attempting to connect to at the start of the connection process. If the SNI host check is enabled and the hostname of the server to which the client is trying to connect to is not found in the server certificate, the server returns an invalid SNI error.true
ssh.server.banner
Available in2.1.0 +
Banner displayed when accessing the SSH server.Welcome to S-Filer Portal SSH Server Interface
ssh.server.cipher.management.mode
Available in4.6.1 +
Determines how SSH ciphers are managed. S-Filer maintains a list of strong ciphers that will evolve over time. The 'Automatic' mode allows to enable only the strong ciphers from this list. For some older clients, weaker ciphers may need to be enabled because they don't support any of the strong ones. The 'Allow Weak' mode results in all weaker ciphers being enabled. For a more fine-grained control, the 'Custom' mode allows to specify all the ciphers that must be enabled in the 'Custom SSH ciphers' parameter.AUTOMATIC
ssh.server.connection.idle.timeout
Available in4.17.0 +
Maximum time (in seconds) the SSH connection is kept open without activity.1800
ssh.server.custom.ciphers
Available in4.17.0 +
List of SSH ciphers (separated by comma) that will be enabled if the cipher management mode is 'Custom'. The supported values are listed in the log file during the Gateway startup.aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
ssh.server.custom.hmacs
Available in4.17.0 +
List of SSH HMAC algorithms (separated by comma) that will be enabled if the HMAC algorithm management mode is 'Custom'. The supported values are listed in the log file during the Gateway startup.hmac-sha2-256,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-512-etm@openssh.com
ssh.server.custom.keyexchanges
Available in4.17.0 +
List of SSH key exchange algorithms (separated by comma) that will be enabled if the key exchange algorithm management mode is 'Custom'. The supported values are listed in the log file during the Gateway startup.curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256,diffie-hellman-group18-sha512,diffie-hellman-group17-sha512,diffie-hellman-group16-sha512,diffie-hellman-group15-sha512,diffie-hellman-group14-sha256,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,rsa2048-sha256
ssh.server.enable
Available in2.1.0 +
Turns on or off the SSH Server.false
ssh.server.hmac.management.mode
Available in4.17.0 +
Determines how SSH HMAC algorithms are managed. S-Filer maintains a list of strong HMAC algorithms that will evolve over time. The 'Automatic' mode allows to enable only the strong HMAC algorithms from this list. For some older clients, weaker HMAC algorithms may need to be enabled because they don't support any of the strong ones. The 'Allow Weak' mode results in all weaker HMAC algorithms being enabled. For a more fine-grained control, the 'Custom' mode allows to specify all the HMAC algorithms that must be enabled in the 'Custom SSH HMAC algorithms' parameter.AUTOMATIC
ssh.server.ip
Available in4.8.2 +
IP address where the SFTP Server listens for incoming connection request. (Default value is 0.0.0.0)0.0.0.0
ssh.server.key
Available in4.13.0 +
Key used by the SSH Server.
ssh.server.keyexchange.management.mode
Available in4.17.0 +
Determines how SSH key exchange algorithms are managed. S-Filer maintains a list of strong key exchange algorithms that will evolve over time. The 'Automatic' mode allows to enable only the strong key exchange algorithms from this list. For some older clients, weaker key exchange algorithms may need to be enabled because they don't support any of the strong ones. The 'Allow Weak' mode results in all weaker key exchange algorithms being enabled. For a more fine-grained control, the 'Custom' mode allows to specify all the key exchange algorithms that must be enabled in the 'Custom SSH key exchange algorithms' parameter.AUTOMATIC
ssh.server.max.concurrent.transfers.per.session
Available in4.17.0 +
Maximum number of SSH transfers that can be performed concurrently in a session.50
ssh.server.max.connections
Available in4.17.0 +
Maximum number of concurrent SSH connections allowed (leave blank for unlimited).
ssh.server.max.connections.per.user
Available in4.17.0 +
Maximum number of concurrent SSH connections allowed for a user (leave blank for unlimited).
ssh.server.max.sessions.per.connection
Available in4.17.0 +
Maximum number of concurrent sessions allowed for an SSH connection.10
ssh.server.permanent.transfer.threads
Available in4.17.0 +
Number of threads that are kept permanently alive to manage SSH transfers. Additional threads will be created/destroyed when needed.2
ssh.server.port
Available in2.1.0 +
Port number where the SFTP Server listens for incoming connection request. (Default value is 22)22

Outdated configurations

The configurations listed below cannot be used on the latest version of S-Filer Portal.

Configuration keyDescriptionDefault valueEnd version
ssh.server.host_dsa_key
Available in2.1.0 +
Specifies the DSA host key used by the SSH server../conf/ssh_host_dsa_key4.13.0
ssh.server.host_rsa_key
Available in2.1.0 +
Specifies the RSA host key used by the SSH server../conf/ssh_host_rsa_key4.13.0