Technology Solutions and Services Enterprise Services Support & Delivery Aon Secure File Transfer EMEA Secure file transfer service January 2013 port Document Title Sub-Title of Report Document Date
Table of Contents Welcome 3 Account 4 Sign-up and activation 4 Access 5 Web based access 5 Initial logon 6 Navigation 7 Change password 7 SFTP access 8 Initial logon and password change 8 Navigation 8 Restrictions 8 Structure 9 Automation 10 Contact Information 10 Technology Solutions and Services Enterprise Services Support & Delivery 2
Welcome Welcome to the Aon Secure File Transfer EMEA service (SFT). This document describes the basics for using this service and allows you to get started with exchanging files with Aon or our partners. The SFT service groups users, folders and interfaces in customer areas. These define segregation of setups and will be used to identify your configuration when you reach out for support. Customer areas can be setup for production only or for production and test, depending on the requirements. In a production only configuration one single customer area is provided which will be setup for the production data flow. After inception of a production only area and agreement of all parties involved this area will transition to production state, using the same configuration (user name, configuration). In a production and test configuration two distinct customer areas will be provided. This type of setup is to be used for systems/interfaces that provide to segregated data flows, one with production data and one with non-production data typically provided by production and UAT systems. These two distinct customer areas will have unique user names, configuration and folder access. Data between these two areas is not exchanged between them. The data within a customer area is shared amongst all users of a customer area, you don t have personal storage on the SFT service. The default for files is to have retention of 30 days after which they are automatically removed. If file volumes are significant the retention can be further reduced. This will always be agreed with the Aon business unit requestor, but defaults to 30 days. The SFT service is not intended as a long term file server. The SFT service is built on IPswitch MoveIT products to facilitate the service file transfer service and is hosted within the EMEA region. Technology Solutions and Services Enterprise Services Support & Delivery 3
Account Sign-up and activation Your access will be or has been requested by one of the Aon business units. There is no need to explicitly request an account to this service directly; your Aon contact can request additional accounts if required. Accounts are setup for either test or production exclusively. You can identify your account as either test or production account by checking your username. The digits of your username indicate the customer area to which it belongs. Customer areas 1000-1999 are test areas and customer areas 2000-2999 are production areas. Production areas with n belong to test areas n 1000. In example: Username c1000example belongs to test customer area 1000 Username c2000example belongs to production customer area 2000 Customer area 1000 represents the test area of production area 2000 Two types of accounts exist: - Named user accounts This is the default account type and should be used for individuals (Aon or external) to gain access to the services. Every individual will require an user assigned user account. Sharing of user accounts is prohibited. This account type can be used via the web based portal or via SFTP. - Interface accounts This type of account is to be used for interfacing with the SFT service and should only be used for internal or external machine based processes, i.e. periodic data upload to the SFT service. Individuals should not be using this account to logon to the service. This type of account will typically be setup in combination of public-key SFTP authentication. For named user accounts you will receive several e-mails from the SFT service once your account has been setup by our implementation team. These e-mails will allow you to activate the account and to setup your password. Upon creation you will received the following e-mails (in order): - Subject: New User Account for Aon Secure File Transfer EMEA service (sftp.emea.aon.com) Sender: Aon Corporation EMEA BV SFT Service <sftp.emea@aon.com> This e-mail indicates that your account has been created and invites you to proceed with activation. The link provided in the e-mail will navigate you to a page where you will need to confirm the username provided in this e-mail to retrieve the password request e-mail - Subject: New User Password Request Confirmation Sender: Aon Corporation EMEA BV SFT Service <sftp.emea@aon.com> This e-mail informs you that the password request has been received and provides the link to set your password Technology Solutions and Services Enterprise Services Support & Delivery 4
Access The service provided allows users to connect using two methods: Web based access - Web based access via web your web browser - SFTP access via any SFTP client The SFT service is accessible via a HTTPS secure web portal which is primarily intended for user interaction with the service. Users are able to download and upload files as well as changing their e- mail address and password. The secure web portal is not intended for system interfaces with the service. The SFTP access method described in the next paragraph is intended for such interface. Users can access the web based portal via: https://sftp.emea.aon.com/ Technology Solutions and Services Enterprise Services Support & Delivery 5
Initial logon The web portal will prompt for your username and password. Accounts will be locked out after 5 consecutive failures in 5 minutes. This lockout will expire automatically after 30 minutes. After initial successful login you will be prompted with the possibility to activate the ActiveX or Java Upload/Download Wizard. These wizards aren t mandatory but will allow you to locally validate downloads and upload files with integrity validation. After choosing to either activate or disable the wizard you will be redirected to the Folders view which allows you to navigate to the customer area setup for your use. The structure of the customer area is described in chapter Structure. Technology Solutions and Services Enterprise Services Support & Delivery 6
Navigation After login you will be displayed with the Folders overview by default. You can also navigate to this section by selecting Folders in the menu on the left. You can navigate through your customer area by clicking on the folders displayed. Typically one would: - select Areas - select Test or Production (depending on the account used to login) - select your area code (starting with c) - click on inwards or outwards - download files by clicking on them or upload files via the Upload a File Now section at the bottom of the page (will only be displayed if permissions allow the user to upload to the specific folder) Alternatively you can quickly navigate to the designated folder by choosing it from the Go To Folder dropdown list in the menu on the left, or from the dropdown list at the top of the page. Change password Policies dictate users to change their password periodically (91 days). A warning that your password expires shortly will be sent 7 days in advance via e-mail. You can also choose to change your password before expiration to your own convenience. Password changes need to be performed via the web interface. To change your password: - Go to the web interface (SFTP does not allow password change) - Log in with your existing user credentials - Navigate to My Account at the right-top of the page - Update your password Technology Solutions and Services Enterprise Services Support & Delivery 7
SFTP access Regular users can also access the SFT service by using a SFTP client to their own liking (using their named user account). This access method can also be and is primarily used by external or internal systems that need to upload or download files via an automated process (using an interface account). For such interfaces the SFTP access can be setup with password, public- / private-key authentication or a combination of both. Setup of this type of accounts is normally completed during the setup of the customer areas as defined on the intake form provided by the Aon business unit. Users and systems can access the SFT service with the SFTP protocol on: Host: sftp.emea.aon.com Port: TCP 22 Fingerprint: b0:fa:8d:f8:84:07:b4:a4:61:57:46:52:35:d7:22:90 Initial logon and password change Named user accounts and interfaces accounts that use password authentication and use SFTP for connecting to the service are still enforced to use the web based portal to setup their initial password and to renew their password as described in chapter Change password (unless an interface account has been exempted from expiration and/or been setup with private/public-key authentication). These users will automatically receive a reminder when required to update their password. Navigation After connecting the SFT service you will be prompted for your username and password (unless key authentication has been setup). Once connected you have access to the shared folders as described in chapter Structure. Restrictions The SFTP protocol implemented for the SFT service does not allow you to change the timestamp of an uploaded file. It is highly recommended to disable this feature on your SFTP client to prevent client side errors. Technology Solutions and Services Enterprise Services Support & Delivery 8
Structure After login (both web based and SFTP) you will recognize a strictly defined folder structure. This is a fixed setup with minor deviation when required for specific setups. However you should at least see the following structure: /Areas/ /Areas/[Test Production] /Areas/[Test Production]/c[1 2][xxx] /Areas/[Test Production]/c[1 2][xxx]/inwards /Areas/[Test Production]/c[1 2][xxx]/outwards This identifies a test or production area The top level of your customer area The location to download incoming files (Aon) The location to upload outgoing files (external) The location to upload outgoing files (Aon) The location to download incoming files (external) Files can be overwritten by default, but file deletion is prohibited. For customer areas with automation on the SFT server the folders inwards and outwards contain a subfolder called done. This folder will contain the files after they have been processed by the SFT service. In such a setup the users and systems should upload files in the inwards and outwards folders, but should download files from the respective done directories: /A/[T P]/c[1 2][xxx]/inwards /A/[T P]/c[1 2][xxx]/inwards/done /A/[T P]/c[1 2][xxx]/outwards /A/[T P]/c[1 2][xxx]/outwards/done The location to upload outgoing files (external) The location to download incoming files (Aon) The location to upload outgoing files (Aon) The location to download incoming files (external) Technology Solutions and Services Enterprise Services Support & Delivery 9
Automation Automation can be configured for the customer areas provided by the SFT service. The details of the automation can be specified by the Aon business unit during request of the setup and will be agreed during implementation of the customer areas. The folder layout of such areas is as described in the previous chapter. Further details are out of scope for this document. Connections initiated by the automation service to external systems originate from any IP in the below ranges: - 165.125.178.9-165.125.178.14 (Primary) - 165.125.176.9-165.125.176.14 (Fail-over) Contact Information Your primary contact for support is your Aon account manager (for external users). Your account manager can reach out to the SFT support team. Aon personnel or account managers can engage support via the Magic Service Desk (preferred) or by e-mail (sftp.emea@aon.com). In all cases please provide your username and/or the customer area code. Technology Solutions and Services Enterprise Services Support & Delivery 10