Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Fortra: GoAnywhere Gateway: Reverse Proxy for Secure File Transfer

Fortra
07/30/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


licensed module for the managed file transfer system. And one of the big selling points or benefits of the gateway is the reverse proxy functionality. So with the gateway, when an end user wants to log into the GoAnywhere system, they initiate a connection into a listener here on the gateway device. GoAnywhere maintains an outbound control channel that monitors for the user traffic. When we detect a login attempt, we go ahead and open up a separate outbound data channel. We tie into the user login attempt, we go ahead and validate their credentials. And if everything is copacetic, we have an end-to-end connection here that allows the file transfer to take place. The big benefit from a security perspective is that the firewall connectivity on the backend firewall here is all outbound only. There is no inbound ports that need to be opened between the gateway and the MFT service. So that's the gateway at a high level. To go ahead and talk to the gateway configuration, the gateway does not have its own interface. So the gateway is managed through the GoAnywhere admin console here, through services, through the gateway manager. And I'm going to show you configuration here on my gateway as an example. So the controller address, this is the IP address for the server that the gateway is installed on. Then the controller port, this is the port that the gateway is listening for that control channel from the MFT system that I mentioned a few moments ago. The shared secret, the SSL enable, the SSL context protocol, these are all ways of adding security onto the connection from the GoAnywhere managed file transfer system to the gateway. And then minimum number of threads, maximum number of threads, thread keep alive time, these are timing settings as far as the connections between the gateway and the MFT system. Once you've got the initial gateway configured, we're going to go ahead and establish the listeners here. So the listeners are going to be determined in part by what services you go ahead and activate through the service manager. You have to have an active service running before you can attach a gateway to it. So once you have the services that you're going to make available started, HTTPS, SFTP, without question the two most common. Once you have the services started up, you come back over here to the gateway, and then you go ahead and configure your gateway listeners. So we again specify the from address. This is the IP address for the gateway. The from port is the listener port that the gateway is listening on for external traffic from the public internet. The to address is the MFT server IP address. In my case, they're the same because I'm running both components on my laptop, but generally speaking, they will be different. The link to listener is a relatively new feature. The link to listener puts some intelligence on the connection between the external HTTPS service and the internal go anywhere MFT HTTPS service. Then the load balancer rule goes ahead and establishes how we're going to load balance in the event that we have multiple MFT systems running here on the back end. Once your gateway is configured, once your gateway is started, then the way you can test it is to come in through either the web client, such as this one I have configured here, and go ahead and attempt to log in. Or you can test it using an SCP or FFTP service, such as WinSCP or FileZilla. And we're going to go ahead and stop there because I'm coming up on time. And my login attempt, we're going to try this one more time. So you can see from the login attempt, this is the view you're going to see initially. But if you get this far, you know that the gateway listener is configured properly and we are connecting back to the HTTPS service. So thank you very much for your time. I hope this was useful.

TL;DR

  • GoAnywhere Gateway is a reverse proxy module that keeps sensitive files out of the DMZ by using outbound-only connections from the MFT server to the Gateway, eliminating the need for inbound firewall ports.
  • The Gateway maintains an outbound control channel that monitors for user login attempts, then opens separate data channels to validate credentials and enable secure file transfers while protecting the private network.
  • Configuration is managed through the GoAnywhere admin console with settings for controller address, SSL security, thread management, and listeners for HTTPS and SFTP services that link external traffic to internal MFT systems.

Summary

This technical demonstration walks through the GoAnywhere Gateway module, a separately licensed component for Fortra's managed file transfer system that provides reverse proxy functionality to keep sensitive files out of the DMZ. The Gateway operates by having external users initiate connections to a listener on the Gateway device, while GoAnywhere maintains an outbound control channel that monitors for user traffic. When a login attempt is detected, the system opens a separate outbound data channel to validate credentials and establish an end-to-end connection for file transfer. The key security advantage is that the backend firewall requires only outbound connectivity—no inbound ports need to be opened between the Gateway and the MFT service. The video demonstrates configuration through the GoAnywhere admin console, including controller settings, SSL security options, thread management, and listener setup for HTTPS and SFTP services. The presenter shows how to link external Gateway listeners to internal MFT services and test connectivity through web clients or SCP/SFTP tools like WinSCP or FileZilla.

Chapters

0:00 - Gateway Overview and Architecture
1:21 - Gateway Configuration Basics
2:31 - Setting Up Gateway Listeners
4:02 - Testing Gateway Connectivity

Key Quotes

1:03 "The big benefit from a security perspective is that the firewall connectivity on the backend firewall here is all outbound only. There is no inbound ports that need to be opened between the gateway and the MFT service."
0:26 "When an end user wants to log into the GoAnywhere system, they initiate a connection into a listener here on the gateway device. GoAnywhere maintains an outbound control channel that monitors for the user traffic."
2:42 "You have to have an active service running before you can attach a gateway to it. So once you have the services that you're going to make available started, HTTPS, SFTP, without question the two most common."

FAQ

What is the main security benefit of using GoAnywhere Gateway?

The Gateway eliminates the need for inbound firewall ports between the Gateway and the MFT server. All connectivity on the backend firewall is outbound-only, which keeps sensitive files out of the DMZ and reduces attack surface while supporting compliance requirements.

How do you configure and test the GoAnywhere Gateway?

The Gateway is configured through the GoAnywhere admin console under Services > Gateway Manager, where you set controller address and port, SSL security options, and create listeners for services like HTTPS and SFTP. Testing is done by attempting to log in through a web client or using SCP/SFTP tools like WinSCP or FileZilla.


Categories:
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Network Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Network Security
  • Compliance & Governance
  • Technical Deep Dive
  • Demo
  • Reverse proxy architecture
  • DMZ security
  • Managed file transfer
  • Outbound-only firewall configuration
  • HTTPS and SFTP listeners
  • Compliance and data protection
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Fortra: GoAnywhere Gateway: Reverse Proxy for Secure File Transfer

              Industry Events (Sponsor Hosted)

              • Aug
                03

                Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.

                08/03/202611:00 AM ET
                • Aug
                  06

                  Safeguarding Sensitive Data in the Era of Public AI Platforms

                  08/06/202604:00 AM ET
                  • Aug
                    06

                    Same Tactics, Enhanced Speed: AI Agents’ Impact on Identity Attacks

                    08/06/202602:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 08/03/2026
                      11:00 AM
                      08/03/2026
                      Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.
                      https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-ever-evolving-triage-agent-enhancing-efficiency-each-shift/
                    • 08/06/2026
                      04:00 AM
                      08/06/2026
                      Safeguarding Sensitive Data in the Era of Public AI Platforms
                      https://www.truthinit.com/index.php/channel/2058/safeguarding-sensitive-data-in-the-era-of-public-ai-platforms/
                    • 08/06/2026
                      02:00 PM
                      08/06/2026
                      Same Tactics, Enhanced Speed: AI Agents’ Impact on Identity Attacks
                      https://www.truthinit.com/index.php/channel/2064/same-tactics-enhanced-speed-ai-agents-impact-on-identity-attacks/
                    • 08/07/2026
                      11:30 AM
                      08/07/2026
                      Refreshing Beverage Ideas Paired with Essential Cybersecurity Insights
                      https://www.truthinit.com/index.php/channel/2063/refreshing-beverage-ideas-paired-with-essential-cybersecurity-insights/
                    • 08/13/2026
                      12:00 PM
                      08/13/2026
                      Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                      https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                    • 08/19/2026
                      12:00 PM
                      08/19/2026
                      Becoming Agent Ready: Insights and Strategies with Cyera
                      https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                    • 09/02/2026
                      12:00 PM
                      09/02/2026
                      Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                      https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version