Vendor pings our host but doesnt resolve, but when connecting to sftp from personal devices it works fine, the issue seems to be BETWEEN our networks. How can this be resolved?

Sigfred Rodriguez 0 Reputation points
2025-02-24T14:31:52.3766667+00:00

We have a blob container that we created SFTP connections to for our vendors. I can connect to the host with the created credentials fine in and outside of our IP range, from personal devices and from work devices. So I know it works. I can also run nslookup on the host and it resolves.

We have a vendor who the blob container is for who cannot connect using the credentials and when running ping or nslookup does not resolve, although when accessing the host on a personal device, they are able to.

Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
3,393 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Hari Babu Vattepally 1,725 Reputation points Microsoft Vendor
    2025-02-24T16:02:51.7766667+00:00

    Hi @Sigfred Rodriguez ,

    Greetings!

    I understand that the vendor is facing network issues while attempting to connect to the Azure Blob container via SFTP.

    Please check the below troubleshooting steps to resolve the issue:

    • Please make sure that the vendor's network permits outbound traffic on port 22, which is necessary for SFTP connections.
    • Also, please ensure that there are no firewall rules or network policies are blocking the connection.
    • Make sure that the vendor's DNS settings are properly configured to resolve the Azure Blob container's hostname.
    • Use nslookup command to verify DNS resolutions.
        nslookup <storage-account-name>.blob.core.windows.net
      
    • Make sure to add the vendor's IP address to the allowed list if you have IP whitelisting turned on for your storage account. Also, you can handle IP whitelisting in the Azure portal by going to the Networking section of your storage account.
    • Make sure the vendor is using a compatible SFTP client and that the settings on the client are set up correctly.
    • Refer to the limitations and known issues with SFTP support for Azure Blob Storage to ensure compatibility. Also, make sure the vendor's network is set up right to access the private endpoint if you're using one for the storage account.
    • The vendor can utilize this connection string format for private endpoints:
        sftp <username>@<storage-account-name>.privatelink.blob.core.windows.net
      
    • Please have the vendor test the connection from various networks to see if the problem is just with their corporate network.

    Please refer the below documents for additional information:

    Connect to Azure Blob Storage from an SFTP Client.

    Limitations & Known Issues with SFTP in Azure Blob Storage.

    By following the above steps and following the above documents, you should be able to resolve the SFTP connection issue for your vendor.

    Please do consider to “up-vote” wherever the information provided helps you, this can be beneficial to other community member. If you have any other questions or are still running into more issues, let me know in the "comments" and I would be happy to help you.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.