Skip to main content

Connection Settings

An SFTP connection needs a reachable hostname, compatible encryption, and a Files.com user that is allowed to connect. The settings below apply to clients connecting to your Files.com site.

Account and Authentication

The user's Protocol Access must allow SFTP. The account's authentication method determines which credentials it accepts. An account set to None (Use SSH or API keys) needs an SSH/SFTP key for SFTP authentication rather than a password.

Register the user's public SSH key before connecting with its matching private key. The server's host key serves a different purpose: it lets the client confirm the identity of the server. Use the appropriate host key fingerprint when configuring a new connection or migrating an existing service.

If the account requires a password change, the user must complete it through the web interface before signing in through SFTP. For accounts with two-factor authentication, the protocol authentication requirements determine the supported method and how to supply the code. Unattended transfers use key authentication so that each connection does not depend on a person supplying a code.

Hostname

Set the hostname to [your_subdomain].files.com or to the custom domain for your site, if applicable.

We do not recommend using IP addresses, because they may change. Using an IP address is not officially supported, and we cannot assist with troubleshooting if you choose to do so.

Port

Use the default port 22.

If port 22 is blocked or interfered with by your corporate firewall, try port 3022 as an alternative.

If neither port is reachable, the network or firewall administrator needs to allow the connection.

Firewalls and IP Whitelisting

The client's network must allow outbound SFTP traffic on port 22 or 3022. When a firewall uses an IP whitelist, it must allow every address that can serve the chosen hostname; allowing only one address can cause intermittent failures.

For a custom domain, allow both dedicated IP addresses shown on your site's Firewall page and connect to that custom domain. Those dedicated addresses do not apply to connections made to [your_subdomain].files.com.

Without a custom domain, allow the Files.com owned IP range. A rule covering the range allows the connection to use any server in the hostname pool.

These are destination addresses allowed by the client's firewall. A Files.com IP Whitelist controls the source addresses from which users can connect; it is a separate access control.

Ciphers

Your SFTP app and Files.com will only connect if both sides agree to use a secure cipher. Insecure ciphers may be rejected by either side.

Configure your SFTP app to use a supported, secure cipher. Refer to your app's documentation to learn how to configure ciphers for your connection.

Timeout

Your SFTP app will connect to Files.com using its default timeout setting.

Very short timeout settings can cause connection issues, so set the connection timeout value to 120 seconds or more.

Retry Logic

Some SFTP apps include a built-in retry feature. Your app will connect to Files.com using its default retry settings.

If this setting is configurable, we recommend setting your app to attempt 3 connection retries, with 10-second intervals between retries. This allows a failed connection to one server in the hostname pool to automatically retry via another pool member.

Keepalives

Files.com gracefully disconnects SFTP sessions after 120 seconds with no new commands or data transfer. This prevents unused sessions from occupying connection resources.

Most SFTP apps complete transfers in progress and reconnect once the user issues another command. These idle timeouts are normal, and most SFTP apps handle them without issues.

Some apps do not handle these timeouts gracefully. To prevent idle timeouts, many apps offer a "keepalive" setting. Files.com supports keepalives to keep the session open without sending new commands. If your app aborts a transfer or errors out due to the idle timeout message, enable keepalives every 30 seconds to maintain the SFTP connection and avoid timeout messages. The keepalive setting sends either a null packet or a dummy command to simulate user interaction between the app and our SFTP service.