Class ProxyConfig
- All Implemented Interfaces:
Serializable,SdkPojo,ToCopyableBuilder<ProxyConfig.Builder,ProxyConfig>
Contains configuration for PROXY protocol version 2 (PPv2) support on an Transfer Family server. When enabled, Transfer Family reads the added PPv2 header from incoming connections to extract the client's source IP address. This address is then available in Amazon CloudWatch Logs entries and is passed to custom identity providers during authentication, enabling IP-based access policies. For more information, see Working with Network Load Balancers.
- See Also:
-
Nested Class Summary
Nested Classes -
Method Summary
Modifier and TypeMethodDescriptionstatic ProxyConfig.Builderbuilder()final booleanfinal booleanequalsBySdkFields(Object obj) Indicates whether some other object is "equal to" this one by SDK fields.final <T> Optional<T> getValueForField(String fieldName, Class<T> clazz) final inthashCode()static Class<? extends ProxyConfig.Builder> final ProxyModesftpMode()Specifies whether the Transfer Family server requires or ignores a PPv2 header containing the client's source IP address on incoming SFTP connections.final StringSpecifies whether the Transfer Family server requires or ignores a PPv2 header containing the client's source IP address on incoming SFTP connections.Take this object and create a builder that contains all of the current property values of this object.final StringtoString()Returns a string representation of this object.Methods inherited from interface software.amazon.awssdk.utils.builder.ToCopyableBuilder
copy
-
Method Details
-
sftpMode
Specifies whether the Transfer Family server requires or ignores a PPv2 header containing the client's source IP address on incoming SFTP connections. If you don't specify a value, the default is
NONE-
NONE: the server reads and ignores any PPv2 header on incoming SFTP connections. This is the default value. Use this value when your SFTP server is not behind an NLB, or when you do not need to preserve the client's source IP address through an NLB. -
PROXY_PROTOCOL_V2_ENFORCED: the server requires a valid PPv2 header on every incoming SFTP connection. When a valid header is present, the server applies it and uses the source IP address from the header. If a connection arrives without a PPv2 header, the server refuses the connection and logs an error to Amazon CloudWatch Logs indicating that the expected PPv2 header was missing. Use this value when your SFTP server is behind an NLB with PPv2 enabled on the target group.With
PROXY_PROTOCOL_V2_ENFORCEDyou must restrict the server's VPC endpoint security group to allow inbound traffic only via the trusted NLB. For more information, see Working with Network Load Balancers.
If the service returns an enum value that is not available in the current SDK version,
sftpModewill returnProxyMode.UNKNOWN_TO_SDK_VERSION. The raw value returned by the service is available fromsftpModeAsString().- Returns:
- Specifies whether the Transfer Family server requires or ignores a PPv2 header containing the client's
source IP address on incoming SFTP connections. If you don't specify a value, the default is
NONE-
NONE: the server reads and ignores any PPv2 header on incoming SFTP connections. This is the default value. Use this value when your SFTP server is not behind an NLB, or when you do not need to preserve the client's source IP address through an NLB. -
PROXY_PROTOCOL_V2_ENFORCED: the server requires a valid PPv2 header on every incoming SFTP connection. When a valid header is present, the server applies it and uses the source IP address from the header. If a connection arrives without a PPv2 header, the server refuses the connection and logs an error to Amazon CloudWatch Logs indicating that the expected PPv2 header was missing. Use this value when your SFTP server is behind an NLB with PPv2 enabled on the target group.With
PROXY_PROTOCOL_V2_ENFORCEDyou must restrict the server's VPC endpoint security group to allow inbound traffic only via the trusted NLB. For more information, see Working with Network Load Balancers.
-
- See Also:
-
-
sftpModeAsString
Specifies whether the Transfer Family server requires or ignores a PPv2 header containing the client's source IP address on incoming SFTP connections. If you don't specify a value, the default is
NONE-
NONE: the server reads and ignores any PPv2 header on incoming SFTP connections. This is the default value. Use this value when your SFTP server is not behind an NLB, or when you do not need to preserve the client's source IP address through an NLB. -
PROXY_PROTOCOL_V2_ENFORCED: the server requires a valid PPv2 header on every incoming SFTP connection. When a valid header is present, the server applies it and uses the source IP address from the header. If a connection arrives without a PPv2 header, the server refuses the connection and logs an error to Amazon CloudWatch Logs indicating that the expected PPv2 header was missing. Use this value when your SFTP server is behind an NLB with PPv2 enabled on the target group.With
PROXY_PROTOCOL_V2_ENFORCEDyou must restrict the server's VPC endpoint security group to allow inbound traffic only via the trusted NLB. For more information, see Working with Network Load Balancers.
If the service returns an enum value that is not available in the current SDK version,
sftpModewill returnProxyMode.UNKNOWN_TO_SDK_VERSION. The raw value returned by the service is available fromsftpModeAsString().- Returns:
- Specifies whether the Transfer Family server requires or ignores a PPv2 header containing the client's
source IP address on incoming SFTP connections. If you don't specify a value, the default is
NONE-
NONE: the server reads and ignores any PPv2 header on incoming SFTP connections. This is the default value. Use this value when your SFTP server is not behind an NLB, or when you do not need to preserve the client's source IP address through an NLB. -
PROXY_PROTOCOL_V2_ENFORCED: the server requires a valid PPv2 header on every incoming SFTP connection. When a valid header is present, the server applies it and uses the source IP address from the header. If a connection arrives without a PPv2 header, the server refuses the connection and logs an error to Amazon CloudWatch Logs indicating that the expected PPv2 header was missing. Use this value when your SFTP server is behind an NLB with PPv2 enabled on the target group.With
PROXY_PROTOCOL_V2_ENFORCEDyou must restrict the server's VPC endpoint security group to allow inbound traffic only via the trusted NLB. For more information, see Working with Network Load Balancers.
-
- See Also:
-
-
toBuilder
Description copied from interface:ToCopyableBuilderTake this object and create a builder that contains all of the current property values of this object.- Specified by:
toBuilderin interfaceToCopyableBuilder<ProxyConfig.Builder,ProxyConfig> - Returns:
- a builder for type T
-
builder
-
serializableBuilderClass
-
hashCode
-
equals
-
equalsBySdkFields
Description copied from interface:SdkPojoIndicates whether some other object is "equal to" this one by SDK fields. An SDK field is a modeled, non-inherited field in anSdkPojoclass, and is generated based on a service model.If an
SdkPojoclass does not have any inherited fields,equalsBySdkFieldsandequalsare essentially the same.- Specified by:
equalsBySdkFieldsin interfaceSdkPojo- Parameters:
obj- the object to be compared with- Returns:
- true if the other object equals to this object by sdk fields, false otherwise.
-
toString
-
getValueForField
-
sdkFields
-
sdkFieldNameToField
- Specified by:
sdkFieldNameToFieldin interfaceSdkPojo- Returns:
- The mapping between the field name and its corresponding field.
-