Issue
FTP Test connectivity or FTP server test connectivity fails on using internal or private address.
Error
SSRF protection: FTP host <IP address> resolves to an internal/private address and is not allowed.
Symptoms and Impact
-
Unable to connect to internal/private IP FTP/SFTP servers
-
SSRF protection error messages display
The SSRF security feature introduced blocks FTP/SFTP and CMIS connections to private IP addresses by default, causing legitimate internal connections to fail.
Root Cause
Starting with Pega Infinity 25.1.3, SSRF protection is enhanced to block connections to internal or private IP addresses for:
• FTP integrations
• CMIS integrations
This security improvement is intended to protect against Server-Side Request Forgery vulnerabilities. However, many users host their FTP/SFTP servers on private networks, causing legitimate connections to be blocked by the platform's security layer.
Solution
Update to one of the following Pega Platform versions:
• Pega InfinityTM 25.1.4
• Pega InfinityTM 26.1.1 Patch Release
• Pega InfinityTM 27
Workaround for Pega Platform 24.2.5
- Apply HFix-D2611 and then add the following DSS:
RuleSet: Pega-Engine
Setting Purpose: prconfig/security/ftpssrfallowlist/default
Value: <IP address>
RuleSet: Pega-Engine
Setting Purpose: prconfig/security/cmisssrfallowlist/default
Value: <IP address>
Value: comma-separated list of trusted site-local hosts/IPs
-
Perform a node restart
Workaround For Pega Platform 25.1.3
1. Apply HFix-D2344 and then add the following DSS:
RuleSet: Pega-Engine
Setting Purpose: prconfig/security/ftpssrfallowlist/default
Value: <IP address>
RuleSet: Pega-Engine
Setting Purpose: prconfig/security/cmisssrfallowlist/default
Value: <IP address>
Value: comma-separated list of trusted site-local hosts/IPs
2. Perform a node restart