| Description | This article describes how to configure a SOCKS proxy to allow SFTP server access. |
| Scope | FortiProxy. |
| Solution |
In this scenario, an internal user requests to access an SFTP server using a FileZilla client, where FortiProxy acts as an intermediate proxy to authenticate this application access traffic.
Go to Proxy Settings -> Explicit Proxy -> Select web proxy name -> Click Edit. Enable the SOCKS Proxy checkbox and enter a port number.
2. To configure proxy authentication scheme: Go to Policy & Objects -> Authentication Rules -> Authentication Schemes -> Create New. Select the authentication method to Basic.
3. To configure proxy authentication rule: Go to Policy & Objects -> Authentication Rules -> Create New. Select Socket Secure under protocol selection to match SOCKS authentication traffic.
4. Create or edit a policy to allow SOCKS proxy traffic.
5. Access to an external SFTP server by using the FileZilla client.
6. Execute the following commands to confirm user authentication and SOCKS proxy access traffic.
diagnose wad user list diagnose wad filter process-id-by-src <client-ip>
fpx # diagnose wad user list ID: 5, VDOM: root, IPv4: 10.165.2.76 fpx #
Wad debug: Matching authentication rule
Wad debug: Matching policy rule [I][p:962] wad_socks_policy_match_one :124 fw_pol_id=1(pol_ctx:mx|A|7?|=p) pflag:H|W|U|A asyn_info=1 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.