Firewall on Blob SFTP doesn't block Telnet Session

Santosh Kumar 1 Reputation point
2022-12-12T13:37:09.1+00:00

I have setup an SFTP on Azure Blob. Everything works as expected. The network team wanted to test the firewall rules. At this moment access is permitted from one public IP. They ran telnet and sftp commands from an IP which should had been blocked. While SFTP was successfully blocked, the Telnet was not blocked.
Telnet <username>@<sftpserver> 22
This returned with message
Connected to blob...store.core.windows.net
Can anyone explain what is happening.

Azure Blob Storage
Azure Blob Storage
An Azure service that stores unstructured data in the cloud as blobs.
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. SaiKishor-MSFT 17,341 Reputation points Moderator
    2022-12-12T21:40:18.23+00:00

    @Santosh Kumar Thanks for reaching out to Microsoft Q&A. I understand that you are having issues with connecting to SFTP on Azure Blob Storage where although you added an IP address in the firewall setting of the Storage Account, you can still connect to the port 22 via Telnet, is that right?

    • SFTP is a platform level service, so port 22 will be open even if the account option is disabled. If SFTP access is not configured, then all requests will receive a disconnect from the service.

    For more details refer to this document- https://learn.microsoft.com/en-us/azure/storage/blobs/secure-file-transfer-protocol-support#sftp-permission-model

    Hope this helps. Please let us know if you have any more questions and we will be glad to assist you further. Thank you!

    Remember:

    Please accept an answer if correct. Original posters help the community find answers faster by identifying the correct answer. Here is how.

    Want a reminder to come back and check responses? Here is how to subscribe to a notification.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.