SAP Knowledge Base Article - Public

3148291 - Not able to use alternative ports for SFTP communication besides Port 22

Symptom

Currently it's not possible to use different ports than Port 22 for SFTP communication in Integration Center, Security Center or Intelligent Service Center and you may be facing one of the error messages below:

Environment

SAP SuccessFactors HCM Suite

  • Integration Center
  • Security Center
  • Intelligent Service Center

Cause

In summary, Port 22 is associated with the Secure Shell (SSH) protocol, which is widely used for secure remote administration and secure file transfer. It provides encrypted communication and authentication mechanisms for secure access to remote systems and secure file transfers over unsecured networks.

Considering that, Port 22 is the only port supported for SFTP communication with no exceptions. Custom ports are not authorized for communication as they can cause security issues.

Reference: What's New Viewer article

Resolution

  1. Use SFTPs that accept Port 22, such as SuccessFactors SFTPs (SAP-provided);
  2. Ask the third-party provider to make SFTP available on port 22, which is the standard/default SSH port and the only supported option for new configurations in SuccessFactors.

  3. Use an intermediary SFTP/MFT gateway that accepts the connection from SuccessFactors on port 22 and then forwards the file to the third-party server using their required internal port. SSH/SFTP servers can technically be configured to listen on other ports, but the SuccessFactors-facing side would still need to be port 22.
    NOTE: Please also note that the SFTP destination must be reachable from the public internet / SAP SuccessFactors data centers in order for the integration to work.

NOTES

  • If a previously scheduled job was set up with a different port than port 22, it will continue to work (i.e., this announcement only applies to jobs which are newly created or newly scheduled post 2H 2023).
  • If you had a previously scheduled IC job in a port other than 22 and wish to continue using it, please ensure the job is scheduled ahead of Production Release (likewise, any integrations already scheduled with any Port other than 22 will continue working)

See Also

  • KBA 3122406 - How to be able to connect SuccessFactors to a new third-party site (allowlist on SAP side)
  • KBA 2395508 - How to be able to connect SuccessFactors to a new third-party site (allowlist on third-party side)
  • KBA 2088013 - FTP: SF File Transfer Protocols, Secure FTP, SFTP
  • KBA 2659632 - Integration Center can't connect to an external SFTP due to IP restrictions
  • KBA 2088009 - What Port is the SuccessFactors Application using?

Keywords

non, not, standard, custom, alternative, different, port, 22, ISC, SC, intelligent services, IC, integration center, integration centre, security center, Missing/Invalid Destination and Scheduling fields Port, The standard default SFTP port is 22, We do not recommend you to change it to another SFTP port , KBA , LOD-SF-INT-INC-FWK , Integration Center UI Framework , LOD-SF-PLT-IPR , IP Restriction Management , Problem

Product

SAP SuccessFactors HCM Suite all versions

Attachments

Pasted image.png
Pasted image.png
Pasted image.png
Pasted image.png