× NETGEAR will be terminating ReadyCLOUD service by July 1st, 2023. For more details click here.
Orbi WiFi 7 RBE973
Reply

SFTP to ReadyNAS

tskin
Aspirant

SFTP to ReadyNAS

I am attempting to set up a backup for an external user via SFTP.  I am testing connectivity using FileZilla.  When I connect to SFTP with the ReadyNAS admin account, I can view the folder contents, create files, etc.  When I connect as one of the domain admins, I instead see a folder labeled users;UNIX.mode=0775,owner=33268 (etc.).  

 

User authentication mode is enabled under System -> Services -> FTP and the "enable FTPS" checkbox is checked.  I have created a share specifically for SFTP access (under Shares -> Shares) and Domain Admins have been given read/write permission under the FTP button (under Network Access) and have been added to the security tab (under File Access) also with Read/Write permissions.

 

What am I missing?  Why can the admin account that's local to the box get the correct settings but domain admins can't?  Authentication type is set to Active Directory, by the way.

 

Model: RN4220X|ReadyNAS 4220 10Gbase-T
Message 1 of 9

Accepted Solutions
JennC
NETGEAR Employee Retired

Re: SFTP to ReadyNAS

Hello tskin,

 

So, okay I just found out something.

 

ReadyNAS OS 6 does not currently allow you to enable SSH access on a domain user account, only the admin account. There's no way to restrict who can and cannot access the NAS via SSH/SFTP/SCP if domain accounts are enabled; it's an "all or nothing" setting with AD. As long as they have a domain account, they would have SFTP access to the NAS. Also, ReadyNAS OS 6 does not support SFTP chroots, which prevent users from accessing things that are not for them to see.


Either way, the permissions are based on file access permissions and not share access permission.

 

Regards,

View solution in original post

Message 8 of 9

All Replies
StephenB
Guru

Re: SFTP to ReadyNAS

Just to clarify - are you testing sftp or ftps?

Message 2 of 9
tskin
Aspirant

Re: SFTP to ReadyNAS

SFTP

Message 3 of 9
JennC
NETGEAR Employee Retired

Re: SFTP to ReadyNAS

Hello tskin,

 

You might want to read this discussion.

 

Welcome to the community!

 

Regards,

Message 4 of 9
tskin
Aspirant

Re: SFTP to ReadyNAS

I'd forgotten there was a difference between SFTP and FTPS but why does it work properly with the device account but not with the AD accounts?

Message 5 of 9
JennC
NETGEAR Employee Retired

Re: SFTP to ReadyNAS

Hello tskin,

 

FTPS is encrypting existing FTP protocol over SSL while SFTP is via SSH.

 

Regards,

Message 6 of 9
tskin
Aspirant

Re: SFTP to ReadyNAS

Thanks, JennC, but I'm not drawing the connection between that and authentication.  Why would I be able to connect as an AD user (but can't write to the share) but I can read/write when connecting as an admin to the box?

Message 7 of 9
JennC
NETGEAR Employee Retired

Re: SFTP to ReadyNAS

Hello tskin,

 

So, okay I just found out something.

 

ReadyNAS OS 6 does not currently allow you to enable SSH access on a domain user account, only the admin account. There's no way to restrict who can and cannot access the NAS via SSH/SFTP/SCP if domain accounts are enabled; it's an "all or nothing" setting with AD. As long as they have a domain account, they would have SFTP access to the NAS. Also, ReadyNAS OS 6 does not support SFTP chroots, which prevent users from accessing things that are not for them to see.


Either way, the permissions are based on file access permissions and not share access permission.

 

Regards,

Message 8 of 9
tskin
Aspirant

Re: SFTP to ReadyNAS

Interesting.  Okay, maybe I can make that work.  Thanks, JennC

Message 9 of 9
Top Contributors
Discussion stats
  • 8 replies
  • 8544 views
  • 0 kudos
  • 3 in conversation
Announcements