Skip to Main Content
IBM Sterling


This portal is to open public enhancement requests for IBM Sterling products and services. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Functionality already exists
Categories Security
Created by Guest
Created on Nov 20, 2023

Failed to authenticate with SFTP/FTPs, doesn't display any information of the source

Hi

currently, we have a policy to lock an account after 3 failed connections on SFTP or FTPs protocol.

In the communication session, it's possible to have the IP source when the authentication is successfull, but when the connection failed, the IP is not displayed (so difficult to blacklist).

This case occured several times and identifying the IP source is really difficult because we don't have it.

Regards

 

  • Admin
    Mark Allen
    Reply
    |
    Mar 20, 2024

    Thank you for confirming that DMI is enabled. Can you check the correlation events associated with the transfers? We believe that the IP information would be part of the correlation events.


    If you are using a load balancer or proxy in front of the SFTP servers, that could obfuscate the source IP. We would recommend using SSP/SEAS in this case because the source IP is included in events sent to B2Bi and available in the correlation events.

  • Guest
    Reply
    |
    Feb 28, 2024

    Hi

    DMI is enabled but the IP is no available

    After opening a PMR, IBM support recommended to raise an new request.

    Regards

    Manuel.

  • Admin
    Mark Allen
    Reply
    |
    Feb 28, 2024

    Thank you for your response. Talking this case over with our development team, there is a way to obtain this information already by using DMI:

    • Ensure that DMI is enabled, it is turned on by default but you will want to ensure that it is active so that this information is captured

    • Then go to BP monitor --> Advanced search --> communication sessions

    • Here you can look up session information by IP or protocol or status

    • Note that there will be a performance impact to having DMI enabled


    Thank you for taking the time to provide your ideas to IBM. We truly value our relationship with you and appreciate your willingness to share details about your experience, your recommendations, and ideas.

  • Guest
    Reply
    |
    Feb 14, 2024

    Hi

    currently for SFTP, we don't use Secure Proxy.

    The connection arrive on a external Perimeter server and the account is declared in Sterling integrator accounts.

    The incoming flows for SI arrive from external and internal. So it's difficult to identify the IP source.

    Regards

  • Admin
    Mark Allen
    Reply
    |
    Feb 14, 2024

    Thank you for taking the time to provide your ideas to IBM. I truly value our relationship with you and appreciate your willingness to share details about your experience, your recommendations and ideas.

    I need a little more information to understand your idea. Are you currently using Sterling Secure Proxy in your environment? SSP may provide this functionality if all authentication attempts are going though that system where it may be logged.


    I'm looking forward to your response. Once I can develop a clear picture of your request, I'll be able to let you know if we can add your idea to our future offering roadmap.