Sample code for 30+ languages & platforms
Xbase++

FTP through SSH Tunnel with Dynamic Port Forwarding

See more FTP Examples

Demonstrates how to start a background thread that runs a portable SSH tunnel w/ dynamic port forwarding that the foreground thread can be used for establishing FTP sessions through an SSH tunnel.

Note: Some developers may be accustomed to starting an stunnel.exe proxy from https://www.stunnel.org. The stunnel.exe is not necessary here. Chilkat's background thread fulfills the task of what the external stunnel.exe does. Therefore, your application is self-contained, meaning that it can run anywhere because the SSH tunnel proxy is built-in.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oTunnel
LOCAL cSshHostname
LOCAL nSshPort
LOCAL oFtp
LOCAL cLocalFilename
LOCAL cRemoteFilename
LOCAL nWaitForThreadExit

nSuccess := 0

//  This example assumes the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

nSuccess := 0

oTunnel := CreateObject("Chilkat.SshTunnel")

cSshHostname := "sftp.example.com"
nSshPort := 22

//  Connect to an SSH server and establish the SSH tunnel:
nSuccess := oTunnel:Connect(cSshHostname, nSshPort)
IF (nSuccess != 1)
    ? oTunnel:LastErrorText
    oTunnel:destroy()
    RETURN
ENDIF

//  Authenticate with the SSH server via a login/password
//  or with a public key.  
//  This example demonstrates SSH password authentication.
nSuccess := oTunnel:AuthenticatePw("mySshLogin", "mySshPassword")
IF (nSuccess != 1)
    ? oTunnel:LastErrorText
    oTunnel:destroy()
    RETURN
ENDIF

//  Indicate that the background SSH tunnel thread will behave as a SOCKS proxy server
//  with dynamic port forwarding:
oTunnel:DynamicPortForwarding := 1

//  We may optionally require that connecting clients authenticate with our SOCKS proxy server.
//  To do this, set an inbound username/password.  Any connecting clients would be required to 
//  use SOCKS5 with the correct username/password.
//  If no inbound username/password is set, then our SOCKS proxy server will accept both
//  SOCKS4 and SOCKS5 unauthenticated connections.

oTunnel:InboundSocksUsername := "chilkat123"
oTunnel:InboundSocksPassword := "password123"

//  Start the listen/accept thread to begin accepting SOCKS proxy client connections.
//  Listen on port 1080.
nSuccess := oTunnel:BeginAccepting(1080)
IF (nSuccess != 1)
    ? oTunnel:LastErrorText
    oTunnel:destroy()
    RETURN
ENDIF

//  Now that a background thread is running a SOCKS proxy server that forwards connections
//  through an SSH tunnel, it is possible to use any Chilkat implemented protocol that is SOCKS capable,
//  such as HTTP, POP3, SMTP, IMAP, FTP, etc.  The protocol may use SSL/TLS because the SSL/TLS
//  will be passed through the SSH tunnel to the end-destination.  Also, any number of simultaneous
//  connections may be routed through the SSH tunnel.

oFtp := CreateObject("Chilkat.Ftp2")

//  Indicate that the HTTP object is to use our portable SOCKS proxy/SSH tunnel running in our background thread.
oFtp:SocksHostname := "localhost"
//  The SocksPort must equal the port passed to BeginAccepting above.
oFtp:SocksPort := 1080
oFtp:SocksVersion := 5
//  The SOCKS5 login/password set here must equal the InboundSocksUsername/Password set above.
oFtp:SocksUsername := "chilkat123"
oFtp:SocksPassword := "password123"

//  This is the actual FTP server domain or IP address, and the login/password for the user account on the destination FTP server.
oFtp:Hostname := "ftp.someFtpServer.com"
oFtp:Username := "myLogin"
oFtp:Password := "myPassword"
oFtp:AuthTls := 1

//  Connect and login (via the SSH tunnel) to the FTP server.
nSuccess := oFtp:Connect()
IF (nSuccess != 1)
    ? oFtp:LastErrorText
    oTunnel:destroy()
    oFtp:destroy()
    RETURN
ENDIF

//  Change to the remote directory where the file is located.
//  This step is only necessary if the file is not in the root directory
//  for the FTP account.
nSuccess := oFtp:ChangeRemoteDir("junk")
IF (nSuccess != 1)
    ? oFtp:LastErrorText
    oTunnel:destroy()
    oFtp:destroy()
    RETURN
ENDIF

cLocalFilename := "c:/temp/hamlet.xml"
cRemoteFilename := "hamlet.xml"

//  Download a file.  (the data connection is also automatically established through the 
//  SSH tunnel using dynamic port forwarding..)
nSuccess := oFtp:GetFile(cRemoteFilename, cLocalFilename)
IF (nSuccess != 1)
    ? oFtp:LastErrorText
    oTunnel:destroy()
    oFtp:destroy()
    RETURN
ENDIF

//  The disconnect is disconnecting with the FTP server and closes the SSH tunnel.
//  The background tunnel thread is still running, and may be used for subsequent FTP connections,
//  or even connections for any other purpose, such as HTTP, IMAP, SMTP, POP3, etc.
nSuccess := oFtp:Disconnect()

//  When the app is finished with the tunnel, it can cleanup..

//  Stop the background listen/accept thread:
nWaitForThreadExit := 1
nSuccess := oTunnel:StopAccepting(nWaitForThreadExit)
IF (nSuccess != 1)
    ? oTunnel:LastErrorText
    oTunnel:destroy()
    oFtp:destroy()
    RETURN
ENDIF

//  Close the SSH tunnel (would also kick any remaining connected clients).
nSuccess := oTunnel:CloseTunnel(nWaitForThreadExit)
IF (nSuccess != 1)
    ? oTunnel:LastErrorText
    oTunnel:destroy()
    oFtp:destroy()
    RETURN
ENDIF

oTunnel:destroy()
oFtp:destroy()