KB Article #61425

Inbound SFTP from WS FTP 12.0.1 to XSR Server using termination in DMZ window size issue

Problem

I need to see all of the SFTP activity on my SecureRelay for protocol troubleshooting purposes. How do I capture this?


Resolution

Since a WireShark, snoop, or TCPDump won't be very useful due to the SSH encryption, we need to client or server to provide these traces. We can activate ssh traces by temporarily setting the p_secure_relay_ra_jvm_extra_parameters variable in the XSR profile to:
p_secure_relay_ra_jvm_extra_parameters="-Xmx512m -Dcom.axway.ssh.log.level=TRACE -Dcom.axway.ssh.log.location=ssh.log"



The jvm size -Xmx***m should remain the same as their current setting.
The new setting will take effect when your reload the profile and restart the SecureRelay Router Agent.
The log will grow very quickly, even with little traffic, so be sure there is sufficient space and monitor it closely. Be sure to disable this as soon as your testing is complete.