<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126242#M3719</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/133094"&gt;@jeremy98&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thanks for further details. So, let's start with following test. Run below code in databricks notebook:&lt;/P&gt;&lt;LI-CODE lang="python"&gt;import requests
requests.get("https://api.ipify.org").text&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;The above command should return public IP address. That address should be the same as the one that was added to SFTP server whitelist.Could you check it?&lt;/P&gt;</description>
    <pubDate>Wed, 23 Jul 2025 18:14:21 GMT</pubDate>
    <dc:creator>szymon_dybczak</dc:creator>
    <dc:date>2025-07-23T18:14:21Z</dc:date>
    <item>
      <title>Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126208#M3712</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Hi community,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I’m experiencing a strange issue with my connection from Databricks to an SFTP server.&lt;/P&gt;&lt;P&gt;I provided them with an IP address created for Databricks via a NAT gateway, and that IP is whitelisted on their side. However, even though I have the correct credentials, I’m still having trouble connecting to the SFTP server.&lt;/P&gt;&lt;P&gt;Could you help me understand what might be causing this issue and what I should check or fix?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 13:53:55 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126208#M3712</guid>
      <dc:creator>jeremy98</dc:creator>
      <dc:date>2025-07-23T13:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126213#M3715</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/133094"&gt;@jeremy98&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Could you provide us exact error that you get?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 15:02:57 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126213#M3715</guid>
      <dc:creator>szymon_dybczak</dc:creator>
      <dc:date>2025-07-23T15:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126221#M3716</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks, so I'm trying to use paramiko to connect with some credentials given from one of our clients to send outbound data.&lt;BR /&gt;&lt;BR /&gt;This is the error that I'm receiving:&amp;nbsp;&lt;STRONG&gt;Authentication failed: transport shut down or saw EOF&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 15:17:11 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126221#M3716</guid>
      <dc:creator>jeremy98</dc:creator>
      <dc:date>2025-07-23T15:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126242#M3719</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/133094"&gt;@jeremy98&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thanks for further details. So, let's start with following test. Run below code in databricks notebook:&lt;/P&gt;&lt;LI-CODE lang="python"&gt;import requests
requests.get("https://api.ipify.org").text&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;The above command should return public IP address. That address should be the same as the one that was added to SFTP server whitelist.Could you check it?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 18:14:21 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126242#M3719</guid>
      <dc:creator>szymon_dybczak</dc:creator>
      <dc:date>2025-07-23T18:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126243#M3720</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/110502"&gt;@szymon_dybczak&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response.&lt;/P&gt;&lt;P&gt;We’ve set up a static IP using a NAT Gateway, which our compute resources within the virtual network are now using. I attempted to create an outbound rule in the Network Security Group to allow traffic from the virtual network (where the object is being sent) to the SFTP server. The destination is set to the IP address where I want to send the data. Is it correct my reasoning? Btw, it doesn't work &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 18:21:43 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126243#M3720</guid>
      <dc:creator>jeremy98</dc:creator>
      <dc:date>2025-07-23T18:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126245#M3721</link>
      <description>&lt;P&gt;and yes, the IP that we set, is whitelisted from the customer side&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 18:22:29 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126245#M3721</guid>
      <dc:creator>jeremy98</dc:creator>
      <dc:date>2025-07-23T18:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126248#M3723</link>
      <description>&lt;P&gt;So your approach is correct. NAT gateway will provide stable egrees IP address and that address could be whitelisted in SFTP server. But remember to route outbound traffic from databricks subnets to that NAT Gateway using i.e &lt;STRONG&gt;User-Defined Routes.&lt;/STRONG&gt;&lt;BR /&gt;When you wrote: &lt;STRONG&gt;"Btw, it doesn't work".&amp;nbsp;&lt;/STRONG&gt;You mean that following script didn't work?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;import requests
requests.get("https://api.ipify.org").text&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;If above script returned public IP address of your NAT Gateway then I have another thing to check. I had weird issues in the past with paramiko. Could you check if you are able to connect with pysftp?&lt;/P&gt;&lt;P&gt;1. First install library&lt;/P&gt;&lt;LI-CODE lang="python"&gt;pip install pysftp&lt;/LI-CODE&gt;&lt;P&gt;2. Try to connect&lt;/P&gt;&lt;LI-CODE lang="python"&gt;import pysftp

hostname = 'your_hostname'
username = 'your_username'
password = 'your_password'

cnopts = pysftp.CnOpts()
cnopts.hostkeys = None

try:
    with pysftp.Connection(host=hostname, username=username, password=password, cnopts=cnopts)  as sftp:
        print("SFTP connection successful")
except Exception as e:
    print("SFTP connection failed: ", str(e))&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 18:46:30 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126248#M3723</guid>
      <dc:creator>szymon_dybczak</dc:creator>
      <dc:date>2025-07-23T18:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126256#M3725</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/110502"&gt;@szymon_dybczak&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Yes, I confirmed that I'm getting the same IP returned from the NAT Gateway. I also tried connecting using pysftp, but unfortunately, I still can't connect to the client's SFTP server.&lt;/P&gt;&lt;P&gt;Regarding the outbound rule—I believe I might need your guidance here. I added an outbound rule (priority 115) in the Network Security Group (NSG) to allow traffic on port 22 to the specified IP address within the virtual network where the NSG is attached. Could you confirm if that setup is correct?&lt;/P&gt;&lt;P&gt;Also, I think I may have missed this part you mentioned:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;EM&gt;"But remember to route outbound traffic from Databricks subnets to that NAT Gateway using e.g. User-Defined Routes."&lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I'll look into implementing a User-Defined Route for outbound traffic from the Databricks subnets to the NAT Gateway. Please let me know if there's anything else I should verify.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 23:29:35 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126256#M3725</guid>
      <dc:creator>jeremy98</dc:creator>
      <dc:date>2025-07-23T23:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126258#M3726</link>
      <description>&lt;P&gt;Do u mean this setup miss?&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/110502"&gt;@szymon_dybczak&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jeremy98_0-1753313617288.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/18447i630C0527487E113F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jeremy98_0-1753313617288.png" alt="jeremy98_0-1753313617288.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 23:33:46 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126258#M3726</guid>
      <dc:creator>jeremy98</dc:creator>
      <dc:date>2025-07-23T23:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126281#M3727</link>
      <description>&lt;P&gt;ping&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 07:50:25 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126281#M3727</guid>
      <dc:creator>jeremy98</dc:creator>
      <dc:date>2025-07-24T07:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126311#M3730</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/133094"&gt;@jeremy98&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Your network setup should be correct. If you got expected IP address performing the above test that means that your Databricks subnets are using NAT Gateway for egress traffic correctly.&lt;BR /&gt;Ok, could you run in shell cell following command?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;nc -zv your_sftp_address 22&lt;/LI-CODE&gt;&lt;P&gt;Also, when you tried to connect using pysftp, what error did you get? The same one as with paramiko?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 09:29:17 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126311#M3730</guid>
      <dc:creator>szymon_dybczak</dc:creator>
      <dc:date>2025-07-24T09:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126316#M3731</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/110502"&gt;@szymon_dybczak&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;*I tried to use pysftp and we got the same error still.&lt;/P&gt;&lt;P&gt;But, we don't understand that if we run this command:&lt;/P&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;```import&lt;/SPAN&gt;&lt;SPAN&gt; socket&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;def&lt;/SPAN&gt; &lt;SPAN&gt;get_ssh_egress_ip&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;destination&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"xxxx"&lt;/SPAN&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;sock &lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; socket.&lt;/SPAN&gt;&lt;SPAN&gt;socket&lt;/SPAN&gt;&lt;SPAN&gt;(socket.AF_INET, socket.SOCK_DGRAM)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;try&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;# Connect to port 22, no data sent, just triggers OS to assign route&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;sock.&lt;/SPAN&gt;&lt;SPAN&gt;connect&lt;/SPAN&gt;&lt;SPAN&gt;((destination, &lt;/SPAN&gt;&lt;SPAN&gt;22&lt;/SPAN&gt;&lt;SPAN&gt;))&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;local_ip &lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; sock.&lt;/SPAN&gt;&lt;SPAN&gt;getsockname&lt;/SPAN&gt;&lt;SPAN&gt;()[&lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;print&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;f&lt;/SPAN&gt;&lt;SPAN&gt;"Detected egress IP used for SSH to &lt;/SPAN&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;SPAN&gt;destination&lt;/SPAN&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;SPAN&gt;local_ip&lt;/SPAN&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;except&lt;/SPAN&gt; &lt;SPAN&gt;Exception&lt;/SPAN&gt; &lt;SPAN&gt;as&lt;/SPAN&gt;&lt;SPAN&gt; e:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;print&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;f&lt;/SPAN&gt;&lt;SPAN&gt;"Error detecting egress IP: &lt;/SPAN&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;SPAN&gt;e&lt;/SPAN&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;finally&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;sock.&lt;/SPAN&gt;&lt;SPAN&gt;close&lt;/SPAN&gt;&lt;SPAN&gt;()&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;get_ssh_egress_ip&lt;/SPAN&gt;&lt;SPAN&gt;()```&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;we have the subnet IP and not the NAT Gateway IP. So, maybe the subnet is not forwarded to consider the NAT IP...&lt;BR /&gt;&lt;BR /&gt;and running the bash command ... we got "xxxx ... &lt;SPAN&gt;22 (ssh) open"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 09:38:21 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126316#M3731</guid>
      <dc:creator>jeremy98</dc:creator>
      <dc:date>2025-07-24T09:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126326#M3733</link>
      <description>&lt;P&gt;If your Databricks subnets are linked to NAT Gateway then all outbound traffic should be via this gateway.&amp;nbsp;&lt;BR /&gt;Do you have possibility to ask SFTP administrator for logs? What IP address they can see when you're trying to connect? Reply &lt;STRONG&gt;&lt;SPAN&gt;"xxxx ...&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;22 (ssh) open"&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;indicates that from network perspective you were able to reach destination server and the port is open.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 10:10:34 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126326#M3733</guid>
      <dc:creator>szymon_dybczak</dc:creator>
      <dc:date>2025-07-24T10:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126332#M3734</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/110502"&gt;@szymon_dybczak&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Yes, the subnets are connected to our new NAT gateway, but we’re still experiencing communication issues.&lt;/P&gt;&lt;P&gt;Unfortunately, we don’t have the option to request logs from the SFTP admin. The IP address we’re connecting to (which I haven’t shared here for security reasons) is correct — the port appears to be open.&lt;/P&gt;&lt;P&gt;However, I’m wondering why, when executing the previous code, the source IP is still the private IP. Shouldn’t it be the NAT gateway’s public IP instead?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 10:24:19 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126332#M3734</guid>
      <dc:creator>jeremy98</dc:creator>
      <dc:date>2025-07-24T10:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126333#M3735</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;&amp;nbsp;I’m wondering why, when executing the previous code, the source IP is still the private IP. Shouldn’t it be the NAT gateway’s public IP instead?"&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Regarding this part, I think this piece of code &lt;STRONG&gt;sock.getsockname()[0]&lt;/STRONG&gt; &amp;nbsp;will return the local IP address from subnet (before NAT happens) - so&amp;nbsp;your traffic is leaving from a private IP and SNAT is expected to occur later, at the NAT gateway boundary.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 10:40:53 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126333#M3735</guid>
      <dc:creator>szymon_dybczak</dc:creator>
      <dc:date>2025-07-24T10:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126339#M3736</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/110502"&gt;@szymon_dybczak&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;But, do we need to set an outbound rule in the network security group of databricks?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 11:10:39 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126339#M3736</guid>
      <dc:creator>jeremy98</dc:creator>
      <dc:date>2025-07-24T11:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126344#M3738</link>
      <description>&lt;P&gt;Yes, you should have an outbound rule that will allow outbound traffic from databricks subnets to SFTP destination on propert port&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 12:01:48 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126344#M3738</guid>
      <dc:creator>szymon_dybczak</dc:creator>
      <dc:date>2025-07-24T12:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126349#M3739</link>
      <description>&lt;P&gt;Hi syz,&lt;/P&gt;&lt;P&gt;Do u mean that the source address needs to be the NAT Gateway IP or the databricks subnet? Indeed, the destination IP of the client?&lt;/P&gt;&lt;P&gt;There could be also the needed to have an INBOUND RULE?&lt;/P&gt;&lt;P&gt;ps2: the sftp server is inside their Azure services&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 12:34:32 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126349#M3739</guid>
      <dc:creator>jeremy98</dc:creator>
      <dc:date>2025-07-24T12:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126370#M3740</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/133094"&gt;@jeremy98&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;On your side you should have something like that:&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Outbound NSG Rule (on your Databricks subnet NSG):&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Field Value&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Direction&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;Outbound&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Priority&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;Set it according to your NSG rules (lower number means higher priority)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Source&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;VirtualNetwork or your Databricks subnet IP range&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Source port&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;*&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Destination&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;IP of the SFTP server&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Destination port&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;22&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Protocol&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;TCP&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;Allow&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Name&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;i.e Allow-SFTP-out&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;But to be honest, in this kind of troubleshooting both parties should be involved. Even simple verification on their side, like providing logs with information of IP address is connecting to SFTP could help diagnose the problem faster.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 12:58:30 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126370#M3740</guid>
      <dc:creator>szymon_dybczak</dc:creator>
      <dc:date>2025-07-24T12:58:30Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks to SFTP: Connection Fails Even with Whitelisted NAT Gateway IP</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126375#M3741</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/110502"&gt;@szymon_dybczak&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, the SFTP client needs to whitelist our subnet address? Instead of our NAT gateway IP?&lt;/P&gt;&lt;P&gt;Yep, we are going to ask them if they have some logs, but before they said no..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 13:38:00 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-to-sftp-connection-fails-even-with-whitelisted-nat/m-p/126375#M3741</guid>
      <dc:creator>jeremy98</dc:creator>
      <dc:date>2025-07-24T13:38:00Z</dc:date>
    </item>
  </channel>
</rss>

