GlobalSCAPE EFT Server version 6 is available in a small-to-medium business "SMB" (EFT Server) edition and an enterprise (EFT Server Enterprise) edition. Each edition is built on the same foundation and offer similar core functionality to enable organizations to receive files from business partners or end users over a variety of Internet standard protocols, such as FTP/S, SFTP, and HTTP/S. Add-on modules are available to both products that extend auditing from simple flat-file logging to database driven auditing and customizable reports; provide advanced security controls typically needed by organizations that must comply with security standards such as PCI, HIPAA, or SoX; facilitate ad hoc provisioning of users; provide a richer experience when transferring data over a web browser. During the evaluation period, all functionality is enabled and visible in the EFT Server administration interface. After the trial expires, the functions and modules that are enabled and visible depend on the license purchased. (EFT Server's Web Services interface, Oracle support, and AS2 are available only in the Enterprise edition.) The tables below compare the features available in each edition. Certain features require the activation of one or more of the following modules, as indicated by one or more superscript numbers next to "Optional." For example, "Optional 6,7 " indicates that the feature requires the High Security module (6) and the Auditing and Reporting module (7). 1. SFTP module (included in EFT Server Enterprise) 2. HTTP/S module (included in EFT Server Enterprise) 3. OpenPGP Encryption/Decryption module 4. Secure Ad Hoc Transfer module 5. Web Transfer Client (Requires HTTP/S module; the basic edition is limited to maximum of 5 concurrent users) 6. High Security module (Requires ARM) 7. Auditing and Reporting (ARM) (Oracle support available in EFT Server Enterprise only) 8. DMZ Gateway (Outbound proxy support in EFT Server Enterprise only) 9. AS2 (Available in EFT Server Enterprise only; requires ARM and HTTP modules) 10. Advanced Workflow Engine (AWE module); (Available in EFT Server Enterprise only) SFTP (SSH) SMB Enterprise SFTP (SSH2) Optional 1 SFTP (SSH) key manager Optional 1 Strong encryption (AES-256) Configurable SSH-protoversion-softwareversion Optional 1 Create public and private keys Optional 1 Public key authentication Optional 1 Public key list authentication Optional 1 Public key (per user) assignment Optional 1 Public key and password authentication Optional 1 Password only authentication Optional 1 Public key and/or password authentication Optional 1 FIPS-certified and validated SFTP cryptographic library Optional 6,7 Optional 6,7 1800-290-5054 (USA & Canada); 1-210-308-8267 (worldwide) 1 of 8
SSL (FTPS) SMB Enterprise SSL (explicit and implicit) SSLv2, 3, and TLS SSL key manager NAT support for SSL connections Require client provide SSL certificate Toggle clear command/data channels Specify SSL ciphers Specify SSL version levels IP address and PASV port overrides SSL (FTPS), continued SMB Enterprise Mutual SSL authentication (client certificate authentication) Hiding/disabling of non-allowed ciphers, key lengths, anonymous accounts, etc. Optional 6,7 Optional 6,7 FIPS-certified and validated SSL cryptographic library Optional 6,7 Optional 6,7 SSL certificate-based authentication (no password) Not Available HTTP/S SMB Enterprise HTTPS Optional 2 Customizable client portal Optional 2 Password reset using OWASP guidelines Optional 2 Username retrieval using OWASP guidelines Optional 2 Session-based and basic authentication Optional 2 Single-Sign-On (NTLM) authentication Optional 2 HTTP- to-https auto-redirect Optional 2,6,7 Optional 6,7 HTTP/S Web Transfer Client (Java Applet) Optional 2,5 Optional 5 Platform independent, web-based transfers Optional 2,5 Optional 5 Drag 'n drop transfers Optional 2,5 Optional 5 Folder transfers Optional 2,5 Optional 5 Transfer queue Optional 2,5 Optional 5 Filter by name, date, and size Optional 2,5 Optional 5 Proxy enabled (including Forefront ) Optional 2,5 Optional 5 Customizable interface Optional 2,5 Optional 5 Concurrent (simultaneous) transfers Optional 2,5 Optional 5 CRC integrity checking of completed transfers Optional 2,5 Optional 5 Large file transfer (>2GB) Optional 2,5 Optional 5 1800-290-5054 (USA & Canada); 1-210-308-8267 (worldwide) 2 of 8
FTP SMB Enterprise Checkpoint restart (auto resume) MODE Z compression support File Integrity Checking (XCRC) of completed transfers Block bounce attacks Block anti-timeout measures Block site-to-site transfers (FXP) Multi-part transfers Customizable connection banner message Customizable user limit reached banner message FTP (cont'd) SMB Enterprise Customizable quit session banner message EBCDIC support AS2 (applicability statement 2) SMB Enterprise Inbound (server) and outbound (client) Not Available Optional 9 Drummond certified Not Available Optional 9 Message Level Security (MLS) Not Available Optional 9 AS2 Reliability Profile supported Not Available Optional 9 AS2 Multiple Attachments (MA) Profile supported Not Available Optional 9 Password Rules SMB Enterprise User-initiated password reset Forced reset on initial login Password reuse (users and administrators) Disallow reuse (password history) Password complexity (for administrators), including: Special characters Numeric characters Minimum characters Lower case characters Upper case characters No repeating characters No characters from username No characters from dictionary file Expire password on certain date Optional 6,7 Optional 6,7 Set expiration reminder (e-mail, banner) Optional 6,7 Optional 6,7 Password reset web page Optional 6,7 Optional 6,7 1800-290-5054 (USA & Canada); 1-210-308-8267 (worldwide) 3 of 8
General Security SMB Enterprise Disable account after invalid login attempts Temporarily disable invalid login accounts Lock out account after invalid login attempts Set account expiration date Limit number of logins, number of connections, file size, transfer speed, and user disk quota Protection against Denial of Service (DoS) attacks Hide/modify login banners IP address ban list for Site-wide access IP address ban list for remote administrators IP address ban list for on a per user basis Block Site-to-Site transfers Provide anonymous access File type (extension) ban list Disable account after <n> days of inactivity Optional 6,7 Optional 6,7 Remove account after <n> days of inactivity Optional 6,7 Optional 6,7 General Security (cont'd) SMB Enterprise Conforms to PCI DSS 1.2 standard Optional 6,7 Optional 6,7 PCI DSS compliant host setup wizard Optional 6,7 Optional 6,7 Monitor and report on PCI DSS violations Optional 6,7 Optional 6,7 Generate PCI DSS compliance report Optional 6,7 Optional 6,7 Capture compensating controls Optional 6,7 Optional 6,7 Digital certificates Strong encryption (AES-256) Data sanitization (wiping) Optional 6,7 Optional 6,7 Streaming repository encryption (EFS) Optional 6,7 Optional 6,7 PGP encrypt/decrypt Optional 3 Optional 3 DMZ Security SMB Enterprise Secure DMZ Gateway outbound /proxy Optional 8 Optional 8 Multi-platform DMZ Gateway support (Windows, RedHat, SuSE, Linux, and Solaris 32-bit or 64-bit operating systems) Not Available Optional 8 Authentication SMB Enterprise Native (proprietary) authentication (EFT Server-managed authentication) Active Directory (AD) authentication ODBC (database) authentication NTLM authentication LDAP authentication Not Available RADIUS authentication Not Available RSA SecurID authentication Not Available 1800-290-5054 (USA & Canada); 1-210-308-8267 (worldwide) 4 of 8
Administration SMB Enterprise Windows graphical user interface (administration interface) Command line COM API administration interface Limited Remote administration using administration interface or COM API Silent (unattended installs) Active-passive clustering Active-Active NLB clustering Secure remote administration (SSL) Windows Explorer-like file system view Multiple administrator support Root folder point to SAN or NAS E-mail notifications Administrator password complexity options Administrator login security options Administrator IP address white/black list Active Directory administrator login Optional 6,7 Optional 6,7 Windows administrator account login Optional 6,7 Optional 6,7 Delegated (role-based) administrator accounts, per Site, with granular permissions Not Available Auditing and Reporting SMB Enterprise Flat file logging Real-time user monitoring with kick user Monitor transactions in real time Optional 7 Optional 7 Database-driven auditing of all Server transactions Optional 7 Optional 7 Connection to SQL database Optional 7 Optional 7 Dozens of pre-built reports included Optional 7 Optional 7 Edit (customize) report layout and database query Optional 7 Optional 7 Filter parameters prior to query Optional 7 Optional 7 Output report to PDF Optional 7 Optional 7 View server, host, and site statistics Optional 7 Optional 7 Administrator action logging Not Available Optional 7 Connection to Oracle database Not Available Optional 7 1800-290-5054 (USA & Canada); 1-210-308-8267 (worldwide) 5 of 8
Integration and Workflow SMB Enterprise Run programs via FTP "SITE" commands Clone (copy) Event Rules Multipart transfers Automatic restart of incomplete file transfers Web Services Interface Not Available Select from numerous pre-defined timers Not Available Create custom (run days) calendars Not Available Create holiday calendars (non run days) Not Available Import and export calendars Not Available Event Triggers SMB Enterprise User login, connection, disconnection, failed User login/logout User account created User password change File upload/download success File upload/download success verified (XCRC) File upload/download failed File renamed, deleted, moved Folder created, deleted, moved Log rotated Quota limit reached Account locked out or IP address banned Service/Site started/stopped Recurring timer (scheduled) event Not Available Monitor folder for changes (hot folder) Not Available Event Actions SMB Enterprise Send custom e-mail notifications Launch external processes with parameters Context variables pass-through to actions Run multiple actions on trigger IF conditional statements Compound conditional statements Logical Operators (AND, OR, and NOT) Failed action conditional logic Generate and e-mail reports (PDF, HTML) Optional 7 Optional 7 ELSE conditional statements Not Available Offload (copy/move) files using built-in client (PUT) Not Available Download files using built-in client (GET) Not Available Offload/download through DMZ Gateway, Proxy, or Socks (PUT and GET) Not Available Clean-up old data Not Available AS2 send Action Not Available Optional 9 1800-290-5054 (USA & Canada); 1-210-308-8267 (worldwide) 6 of 8
Event Actions, continued SMB Enterprise OpenPGP Action Not Available Backup server configuration to folder Not Available Write to Windows Event Log (WEL) Not Available Run actions via Web Services (WS) invocation Not Available Advanced Workflow Actions 10 SMB Enterprise Compress files (zip, cab, lha, jar, tar) Not Available Optional 10 File operations (move, rename, concat, delete, etc.) Not Available Optional 10 Online actions (POP3, HTTP/S, FTP, SFTP, Ping, Web Services) Not Available Optional 10 Web 2.0 social media actions (Send IM, Twitter) Not Available Optional 10 System actions (print, registry, process, log event) Not Available Optional 10 Database actions (Execute stored procedure, query) Not Available Optional 10 Service actions (start, stop, install, uninstall, etc.) Not Available Optional 10 Text actions (format, find, replace, trim, insert, etc.) Not Available Optional 10 Excel actions (create, edit, delete cells, sheets, books) Not Available Optional 10 Terminal actions (connect, send text, get text, etc.) Not Available Optional 10 Execute external (scripts, execute dll function, DDE) Not Available Optional 10 Cryptographic actions (encrypt, decrypt, gen key, sign, verify) Not Available Optional 10 XML actions (read, merge, transform, eval, etc.) Not Available Optional 10 AD Actions (query, edit, create, and delete objects) Not Available Optional 10 Network actions (connect, map drive, MSMQ) Not Available Optional 10 SNMP (get, set, walk, send trap, get bulk, etc.) Not Available Optional 10 Integrate with Sharepoint Server Not Available Optional 10 Resource Management SMB Enterprise Automated file maintenance Centralized account management Settings Templates (set once and apply to many) Permission groups User and group permissions for Server access User home directory as root Set storage limit (disk quota) Set bandwidth limit (transfer quota) Set max connection limit Set max connection per IP limit Set max connections for same user account name Set max concurrent socket connections Set max uploads per session Set max downloads per session Create virtual folders and map to UNC Provide anonymous access 1800-290-5054 (USA & Canada); 1-210-308-8267 (worldwide) 7 of 8
Ad Hoc File Transfer 4 SMB Enterprise Specify recipient e-mail address using a web form Optional 4 Optional 4 Specify multiple To, Cc, and Bcc addresses Optional 4 Optional 4 Batch send (send multiple files) Optional 4 Optional 4 Configure automatic clean-up of ad hoc accounts Optional 4 Optional 4 Notify sender upon recipient pick-up Optional 4 Optional 4 Authentication send options (single link, separate login) Optional 4 Optional 4 Black and white list for destination domains Optional 4 Optional 4 AD and LDAP integration (limit use to authorized users) Optional 4 Optional 4 Configurable target folder permissions Optional 4 Optional 4 Customizable web pages Optional 4 Optional 4 Define default permissions for the temporary users' home folders Optional 4 Optional 4 1800-290-5054 (USA & Canada); 1-210-308-8267 (worldwide) 8 of 8