Sample code for 30+ languages & platforms
Tcl

Connect to an SFTP Server Through a Jump Host

See more SFTP Examples

Demonstrates the Chilkat SFtp.ConnectThroughSsh method, which connects to an SFTP server through an already connected and authenticated Ssh object. The first argument is the jump-host Ssh object, and the second and third are the destination hostname and port.

Background: This is the "jump host" (bastion) pattern: the application connects to a reachable gateway, then tunnels onward to an SFTP server that is only accessible from inside the network. Each hop authenticates separately with its own credentials. The result is a normal SFtp object — still requiring its own authentication and InitializeSftp — that happens to be routed through the first connection.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

#  Demonstrates the SFtp.ConnectThroughSsh method, which connects to an SFTP server through an
#  already connected and authenticated Ssh object (a jump host).  The 1st argument is the Ssh
#  object, and the 2nd and 3rd are the destination hostname and port.

set sshJump [new_CkSsh]

#  Connect and authenticate to the jump host first.
set port 22
set success [CkSsh_Connect $sshJump "jump.example.com" $port]
if {$success == 0} then {
    puts [CkSsh_lastErrorText $sshJump]
    delete_CkSsh $sshJump
    exit
}

#  Normally you would not hard-code the password in source.  You should instead obtain it
#  from an interactive prompt, environment variable, or a secrets vault.
set password "mySshPassword"

set success [CkSsh_AuthenticatePw $sshJump "myJumpLogin" $password]
if {$success == 0} then {
    puts [CkSsh_lastErrorText $sshJump]
    delete_CkSsh $sshJump
    exit
}

#  Connect to the SFTP server through the jump host.
set sftp [new_CkSFtp]

set success [CkSFtp_ConnectThroughSsh $sftp $sshJump "sftp.internal.example.com" $port]
if {$success == 0} then {
    puts [CkSFtp_lastErrorText $sftp]
    delete_CkSsh $sshJump
    delete_CkSFtp $sftp
    exit
}

#  Authenticate to the SFTP server (its own credentials), then initialize SFTP.
set success [CkSFtp_AuthenticatePw $sftp "mySshLogin" $password]
if {$success == 0} then {
    puts [CkSFtp_lastErrorText $sftp]
    delete_CkSsh $sshJump
    delete_CkSFtp $sftp
    exit
}

set success [CkSFtp_InitializeSftp $sftp]
if {$success == 0} then {
    puts [CkSFtp_lastErrorText $sftp]
    delete_CkSsh $sshJump
    delete_CkSFtp $sftp
    exit
}

puts "Connected to the SFTP server through the jump host."

CkSFtp_Disconnect $sftp
CkSsh_Disconnect $sshJump

delete_CkSsh $sshJump
delete_CkSFtp $sftp