NetStacksNetStacks

SFTP File Browser

Browse, upload, download, rename, and edit files on remote devices with the integrated SFTP file browser, with drag-and-drop, a tree view, and live transfer progress.

Overview

The SFTP File Browser gives you a graphical file manager for remote devices, docked beside your terminal. Instead of memorizing scp or interactive sftp commands, you get a tree view with drag-and-drop uploads, right-click context menus, inline rename, a built-in text editor, and a live transfer panel with real bytes-on-the-wire progress.

Key Capabilities

  • Tree-view browsing -- expand and collapse directories inline, with a path bar to jump to any location and a refresh button to reload
  • Upload and download -- drag files onto the panel to upload, or download files via double-click / right-click; native OS file drops are supported
  • File operations -- create folders, rename, delete files and directories, and copy a remote path to the clipboard
  • In-place editing -- open recognized text and config files in an integrated editor and save changes back over SFTP
  • Multiple connections -- keep several device SFTP sessions open at once and switch between them with a connection selector in the panel header
  • Device-aware start paths -- opens to the correct filesystem location for the device type (for example flash:/ on Cisco IOS, bootflash:/ on NX-OS)
Feature availability

The SFTP File Browser is gated behind the local_sftp capability. The SFTP control appears only when an SSH terminal tab is focused and the feature is enabled in your build. SFTP is for SSH sessions only -- it is not available for Telnet or serial sessions.

SFTP subsystem required

SFTP requires the remote host to expose the SSH SFTP subsystem. Most Linux/Unix servers and many modern network OSes support it, but some older or hardened network devices have limited or no SFTP support.

How It Works

Opening the SFTP browser for a session establishes a dedicated SFTP connection to the same device the terminal is connected to. The agent opens a fresh SSH connection using the session's host, port, username, and authentication method, then requests the sftp subsystem over that connection.

SFTP uses its own SSH connection

The SFTP transfer channel is a separate SSH connection from your interactive terminal, authenticated independently with the same session credentials. It is not multiplexed onto the existing terminal transport, so the device must permit an additional SSH login for the file transfer to start.

Connection Lifecycle

  1. Connect & authenticate -- the agent connects to host:port and authenticates with the session's password or private key, negotiating a broad set of KEX, cipher, and MAC algorithms for compatibility with legacy gear
  2. Request the SFTP subsystem -- a session channel is opened and the sftp subsystem is requested over it
  3. Resolve the start directory -- the browser opens to the resolved start path (see below); the remote home directory is determined from the server's working directory
  4. List, transfer, and edit -- directory listings, uploads, downloads, mkdir, rename, and delete are issued over the SFTP channel; transfer progress reflects real bytes sent/received

Start-Path Resolution Order

The directory the browser opens to is chosen in this priority order:

  1. Per-session override -- the SFTP Starting Directory set in Session Settings, if present
  2. Device-type default -- a built-in default keyed on the detected CLI flavor (see the table in the next section)
  3. Remote home directory -- falls back to the server-reported working directory, or / if unknown

Opening the SFTP Panel

There is no keyboard shortcut for SFTP. Open it from one of the in-app controls while connected to a device over SSH:

  • Status bar button -- with an SSH terminal focused, click the SFTP button in the status bar (it shows a folder icon and a count of active connections, e.g. SFTP (2))
  • Tab context menu -- right-click the session tab and choose Open File Browser. When a browser is already open for that session, the same item reads Close File Browser
Several devices at once

Each session you open SFTP for adds a connection to the panel. Use the connection selector in the panel header to switch the active device. Close a single connection with the close (X) button next to the selector.

Navigating the Tree

  • Click a folder's arrow (or double-click the folder) to expand or collapse it in place
  • Type a path into the path bar at the top of the panel and press Enter to re-root the tree at that location
  • Click the refresh button in the path bar to reload the current root
  • Right-click a file, folder, or empty space to open the context menu for that target

Device Start Paths

When no per-session override is set, NetStacks selects a starting directory based on the session's detected CLI flavor:

CLI FlavorStart PathTypical Contents
Cisco IOS / IOS-XEflash:/IOS images, configs, VLAN data
Cisco IOS-XRharddisk:/IOS-XR images, packages, configs
Cisco NX-OSbootflash:/NX-OS images, scripts, backups
Juniper Junos/var/Logs, temp storage, core dumps
Arista EOSflash:/EOS images, startup-config, extensions
Palo Alto/Root filesystem
Fortinet/Root filesystem
Other / unknownHome directoryFalls back to the remote home dir, then /

Overriding the Start Path Per Session

For SSH sessions you can pin a specific starting directory in Session Settings under SFTP Starting Directory. Leave it empty to use the device-type default. Examples of valid values:

sftp-start-path-overridestext
# Per-session "SFTP Starting Directory" examples
/var/log        # jump straight to logs on a Linux/Junos host
disk0:/         # a non-default Cisco flash device
bootflash:/     # NX-OS boot flash
/home/admin     # a specific user directory

Common Workflows

Workflow 1: Open SFTP for an Active Session

  1. Connect to a device over SSH in the terminal.
  2. Click the SFTP button in the status bar, or right-click the tab and choose Open File Browser.
  3. The panel opens and re-roots to the device-appropriate start path (for example flash:/ on a Cisco IOS switch).
  4. Expand folders inline, or type a path in the path bar and press Enter to jump anywhere on the device.

Workflow 2: Upload a File to a Device

  1. In the tree, navigate to (or expand) the destination directory.
  2. Drag files from your desktop onto the panel, or click Upload in the action bar / right-click a folder and choose Upload Here.
  3. The transfer panel shows live upload progress with speed and a cancel button. Uploads run one file at a time.
  4. When complete, the target directory refreshes and the new file appears.
Check free space first

Before uploading large firmware images, verify available storage on the device from the terminal -- for example dir flash: or show file systems on Cisco, or df -h on Linux.

Workflow 3: Download a Device File

  1. Navigate to the file you need.
  2. Double-click a non-text file to download it, or right-click and choose Download.
  3. The file streams over the SFTP channel and is saved through your browser/OS download flow.
  4. Watch the transfer panel for progress on large files.

Workflow 4: Rename, Delete, and Copy Path

  1. Rename -- right-click an entry > Rename, edit the name inline, and press Enter.
  2. Delete -- right-click > Delete and confirm. Deleting a directory removes everything inside it.
  3. Copy Path -- right-click > Copy Path to copy the full remote path to your clipboard (handy for terminal commands).
  4. New Folder -- use the action bar button or right-click a folder / empty space > New Folder.

Editing Files In-Place

Double-clicking a file that NetStacks recognizes as text opens it in an integrated editor instead of downloading it. You can also right-click a recognized file and choose Open in Editor. Edit and save, and the changes are written back over SFTP.

What Counts as a Text File?

A file opens in the editor when it has a known text/config extension, or when it has no extension and is under 64 KB. Recognized extensions include common config and script formats:

sftp-editor-text-typestext
# Text/config extensions opened in the editor
.conf  .cfg  .txt  .log  .xml  .json  .yaml  .yml
.sh    .py   .rb   .pl   .js   .ts    .css   .html  .htm
.ini   .toml .env  .csv  .md   .rst   .bat   .ps1
.rules .service .timer .socket .network .netdev

# Files with NO extension open in the editor if they are <= 64 KB
# (anything larger, or with an unrecognized extension, downloads instead)
Edit a switch config directly

On devices that expose their config filesystem over SFTP, files like a .cfg backup or a Python EEM script open straight in the editor -- make a quick change and save without a download / re-upload round-trip.

Reference & Examples

SFTP Panel Operations

sftp-operationstext
# Operations available in the SFTP panel

Browse:      Expand/collapse folders in the tree, or use the path bar
Re-root:     Type a path in the path bar + Enter
Refresh:     Refresh button in the path bar (reloads current root)
Upload:      Drag-and-drop, "Upload" action button, or "Upload Here"
Download:    Double-click a binary file, or right-click > Download
Open:        Double-click a text file, or right-click > Open in Editor
New Folder:  Action-bar button or right-click > New Folder
Rename:      Right-click > Rename (inline edit)
Delete:      Right-click > Delete (files and directories, with confirm)
Copy Path:   Right-click > Copy Path (full remote path to clipboard)

Example: flash:/ Listing on a Cisco IOS Switch

cisco-flash-listingtext
# SFTP tree rooted at flash:/ on a Cisco IOS-XE switch

Name                            Size
cat9k_iosxe.17.09.04.SPA.bin    945.2 MB
cat9k_iosxe.17.06.05.SPA.bin    812.7 MB
startup-config                  28.4 KB
running-config                  28.4 KB
vlan.dat                        3.1 KB
dc1-core/                       (folder)

Example: /var/log/ Listing on a Linux Server

linux-var-log-listingtext
# SFTP tree rooted at /var/log/ on a Linux host

Name           Size
syslog         12.4 MB
auth.log       3.2 MB
kern.log       1.8 MB
dpkg.log       456.0 KB
nginx/         (folder)
journal/       (folder)

Useful Filesystem Paths by Device Type

device-sftp-pathstext
# Common SFTP destinations by platform

# Cisco IOS / IOS-XE
flash:/                      # main storage (images, configs)
bootflash:/                  # boot images on some platforms

# Cisco IOS-XR
harddisk:/                   # default start path for IOS-XR

# Cisco NX-OS
bootflash:/                  # NX-OS images and scripts
bootflash:/scripts/          # Python / TCL scripts

# Juniper Junos
/var/log/                    # system and process logs
/var/tmp/                    # temp files, core dumps

# Arista EOS
flash:/                      # EOS images, startup-config
/mnt/flash/                  # alternative flash mount

# Linux / Unix
/etc/                        # configuration files
/var/log/                    # log files
/home/USER/                  # a user's home directory
Equivalent command-line SFTP

The panel performs the same operations you would run by hand. For reference, the CLI equivalents look like this:

cli-equivalents.shbash
# Equivalent operations from a shell, for reference

# Upload a firmware image to a switch
sftp [email protected]
sftp> cd flash:/
sftp> put cat9k_iosxe.17.09.04.SPA.bin

# Download a log file from a Linux host
sftp [email protected]
sftp> get /var/log/syslog ./syslog

Q&A

Q: How do I open the SFTP file browser?
A: With an SSH terminal focused, click the SFTP button in the status bar, or right-click the session tab and choose Open File Browser. There is no keyboard shortcut for it.
Q: Does SFTP reuse my terminal's SSH connection?
A: No. The SFTP browser opens a separate SSH connection to the same device, authenticated independently with the same session credentials, and requests the sftp subsystem over it. The device must allow an additional SSH login.
Q: Is there a maximum file size?
A: NetStacks does not impose a fixed upload limit -- the practical limits are the device's free storage and the stability of the SSH connection. For very large transfers (firmware images), keep an eye on the live progress in the transfer panel.
Q: Can I edit a file without downloading it?
A: Yes. Double-click (or right-click > Open in Editor) a recognized text or config file to open it in the integrated editor and save changes back over SFTP. Files that are not recognized as text download instead.
Q: Which files open in the editor vs. download?
A: Files with a known text/config extension (such as .conf, .cfg, .yaml, .json, .py, .sh, .log, .ini, .toml) open in the editor. Extensionless files open in the editor if they are 64 KB or smaller; everything else downloads.
Q: Can I work with several devices at once?
A: Yes. Open SFTP for each session; the panel keeps all connections and you switch the active device with the selector in the panel header. The status bar button shows the active connection count.
Q: How do I change the directory the browser opens to?
A: For SSH sessions, set SFTP Starting Directory in Session Settings (for example /var/log or disk0:/). Leave it empty to auto-detect from the device type. You can also re-root any time using the path bar.
Q: Can I transfer files directly between two devices?
A: Not directly in the panel -- transfers are between your local machine and one device. To move a file between devices, download from one and upload to the other, or use scp between the devices from a terminal session.

Troubleshooting

SFTP Button Doesn't Appear

  • The control only shows when an SSH terminal tab is focused -- it is hidden for Telnet and serial sessions.
  • SFTP is gated behind the local_sftp capability; if your build does not enable it, the button and menu item are not shown.

SFTP Subsystem Not Available

  • The remote host must expose the SSH SFTP subsystem. Some older or hardened network devices do not.
  • On Linux/Unix servers, ensure sshd_config includes a Subsystem sftp ... line (for example Subsystem sftp /usr/lib/openssh/sftp-server or internal-sftp).
  • Confirm your account is permitted to use the SFTP subsystem.

Authentication or Connection Fails

  • Because SFTP opens its own SSH connection, verify the device allows an additional concurrent SSH login for your user.
  • Confirm the session credentials (password or key) are correct and that key-based auth is permitted if you use a key.
  • Check device session limits (vty / max-sessions) that might reject a second login while the terminal is connected.

Permission Denied

  • Verify the remote user has read/write access to the target directory.
  • On network devices, some filesystems are read-only or restricted to privileged accounts.

Transfer Timeout or Failure

  • Large transfers can fail if the connection drops -- check network stability between your machine and the device.
  • The SFTP connection uses an inactivity timeout; for long-running transfers keep traffic flowing and avoid idling the link.
  • If a transfer fails partway, a partial file may remain on the device -- delete it before retrying.

Large File Upload Failures

  • Confirm free storage before uploading (dir flash:, show file systems, or df -h).
  • For firmware upgrades, ensure there is room for both the existing and the new image during the upload.