Cookies on this website

We use cookies to ensure that we give you the best experience on our website. If you click 'Accept all cookies' we'll assume that you are happy to receive all cookies and you won't see this message again. If you click 'Reject all non-essential cookies' only necessary cookies providing core functionality such as security, network management, and accessibility will be enabled. Click 'Find out more' for information on how to change your cookie settings.

Configuring FileZilla for Two Factor Authentication

FileZilla is a popular tool for SFTP file transfers and can be used to transfer files to/from BMRC with additional configuration as follows.

FileZilla can be downloaded from https://filezilla-project.org/download.php?show_all=1

  1. Open FileZilla from the Menu Bar select Edit -> Settings. In the Connection settings tab, set your timeout value to 600 seconds (ten minutes). Then click OK to save your settings.
    FileZilla's Settings window showing the Connections tab with the time out value set to 600 seconds
  2. From FileZilla's main window, click the Site Manager button (underneath the File menu) to display the Site Manager window.
    FileZilla's Site Manager window
  3. Click New Site to configure your connection to the BMRC cluster and copy the details shown above, namely:
    Protocol: SFTP
    Host: cluster2.bmrc.ox.ac.uk
    Port: 22
    Logon Type: Interactive
    User: [Enter your username]

    NB If connecting to another BMRC server, adjust the Site Name and Host settings as needed.
  4. Now select the Transfer Settings tab, enable Limit number of simultaneous connections and set to 1.
    FileZilla - Site Manager - Transfer Settings window showing Limit number of simultaneous connections set to 1.
  5. Now click OK to save this configuration. Back at the main window, click the down-arrow next to the Site Manager button and select BMRC Cluster. This will begin the login process.
  6. If FileZilla warns you about an Unknown host key, tick the box marked Always trust this host, add this key to the cache and click OK. (Please contact BMRC if you wish to confirm the key identity further.)
  7. FileZilla will now prompt you to enter your First Factor i.e. your password:
    FileZilla's password window prompting for First Factor i.e. password
  8. After entering your password and clicking OK, FileZilla will then prompt you to enter your second factor code:
    FileZilla's login window prompting for a second factor code
  9. After entering your second factor code and clicking OK, FileZilla should now be connected. The left hand size of the FileZilla window will be showing files on your local computer. The right hand side will be showing files on the BMRC Cluster (or whatever remote site you have configured). Remember that on the BMRC cluster, all data should be stored in your group area under /well/<group>/users/<username>/ - so you may need to navigate to the appropriate location in the right hand window before dragging and dropping files between the two systems.

 

Data Transfers Via Globus

BMRC is able to facilitate both incoming and outgoing data transfers via Globus, a popular, secure third party platform for transferring data. Globus is our preferred option when transferring data to/from your research partners who do not have a regular BMRC account, whether they are elsewhere within the University of Oxford or outside the University.

Prerequisites

In order to request a data transfer via Globus, the BMRC user must in the first instance email us with details of the data to be transferred, cc'ing both to their PI for authorisation and to their external collaborator (the intended sender or recipient of the data).

The external collaborator will need :

1) Either: Access to an institutional Globus server. Please ask your institution's IT services whether there is an institutional licence and whether it provides a suitable location for your data to be received or transmitted from.

2) Or: The Globus Connect Personal software installed onto their institutional or personal computer.

 

Installing Globus Connect Personal

NB Installing Globus Connect Personal is not needed if you are using an institutional Globus account.

To install Globus Connect Personal:

  1. Visit the Globus Connect Personal website and download the appropriate client for your operating system. Clients are available for Windows, Mac and Linux. Follow the installation instructions in order to complete the installation.
  2. During the installation process, you will be asked to login via the Globus website. You can login with an organisational account, a Google account, an ORCiD ID account or it is possible to create a Globus ID with a username and password. University of Oxford users can now use their SSO to login.
    The image show the Globus Personal Connect login webpage. If you have an organisational login, you can search for your organisation. Alternatively you can sign in with a Google account or ORCID iD account.
  3. Once logged in, you will be asked to provide consent to the use of Globus Connect Personal and provide a name for the computer on which you are installing the software. Choose a name that is meaningful to you and click Allow to continue.
    An image of the Globus Connect Personal website showing the initial consent form for connecting your computer. The image shows that this will allow Globus to view your identity, view information about linked entities, create collections in the Globus Transfer Service and view Identity Details. During the registration, you are asked to provide a label by which to identify your computer. Buttons show Allow and Deny.
  4. The Globus Connect Personal software on your laptop will now ask you to complete the setup by choosing a name for the data collection on your laptop.
    The image shows an application window which appears when setting up the Globus Connect Personal Software for the first time. You are asked to provide details of a Globus Collection, with Owner Identity (your email address) and to input a name and description for the new collection. There is a option box for High Assurance, if your computer will store sensitive information such as Protected Health Information of Controlled Unclassified information. There is a save button at the bottom of the window.
    In general, you can use your laptop name as the Collection name. For transfers to/from BMRC, the High Assurance button should be left unticked.
  5. Finally, the application should notify you that it has been successfully installed and that the Globus Connect Personal application is now running. Mac and Windows users should find a notification icon in the tray or menubar. Linux users may see a notification icon or the running application window.

Using Globus for Data Transfers To/From BMRC

In order to carry out a data transfer to/from BMRC, you will need to have logged in to an institutional Globus account or configured Globus Connect Personal on your own computer following the steps above. On request, BMRC will enable the ability to create a Globus Guest Collection, which can be shared with external collaborators. Users with regular BMRC cluster accounts will need to request that Globus access is enabled.

Once the above is in place, you can carry out a data transfer by following these steps.

  1. Login to the Globus website using the same credentials used previously (whether an institutional login, Google login, ORCiD ID or Globus ID).
  2. Once logged in, in the file manager collections search box search for bmrc#upload23. Then click continue to activate the endpoint.
    The file manager in the Globus web app with the bmrc#upload23 collection selected.
  3. When activating the endpoint, you will be asked to input the credentials for your BMRC account. You must enter your 2FA code, as this will be enabled for your account, as well as your username and password. You may periodically need to reactivate if you do not use the endpoint.
    Image of the form to login to the BMRC Globus endpoint.
  4. The file manager window can be vertically split into two halves by selecting the two-pane view in the "Panels" section in the top right of the webpage . You will see the contents of the BMRC folder and the bmrc#upload23 endpoint on the left side of the screen. You should now search for the collection name you registered for your own computer. If you click in the endpoint search box you will be taken to a new window where you can either search by name or click the Your Collections tab to show your own collections.
    The image shows the Globus File Manager webpage. The page is split vertically. The left hand column shown the bmrc#upload2 endpoint and the files visible there. The right hand side shows the user's own endpoint (normally the user's own computer) and the files visible there. The image highlights that one can select files or folders in one location for transfer to the other location. Above each location and start button is shown to start the transfer. In the centre of the screen, a &quot;Transfer and Timer Options&quot; button allows one to configure additional options
  5. After selecting your collection, you will return to the file manager window, with the BMRC endpoint showing on the left and your own endpoint showing on the right. To transfer files in either direction:
    1. Navigate to find the files the need to transfer (either in the BMRC endpoint or your own endpoint).
    2. Click the checkbox next to your files or folders to select them for transfer.
    3. Click the Transfer & Timer Options button to show advanced options and make sure to select Encrypt Transfer (NB if encryption is not enabled, the transfer will fail, but this should be enabled by default for bmrc#upload23).
    4. Finally click the Start button on the appropriate side of the window to begin the transfer.
      The image shows configurable options for a Globus data transfer within a webpage. The image highlights the need to select the option to encrypt transfers. It is also possible to schedule a transfer to start at a particular time and also to schedule repeating transfers.
  6. Once your transfer has started, you can monitor it from the Activity page (see the menu on the left side of the screen).
  7. Once the transfer is in progress, you can logout from the Globus website and the transfer will continue in the background. Please log back in later to confirm that your transfer has completed successfully.
  8. In the event that your endpoint activation expires before the transfer has completed, you can simply re-activate the endpoint and the transfer should then automatically resume.

Creating and Sharing a Globus Guest Collection 

It is now possible to create a Globus Guest Collection and share folders from BMRC with your collaborators yourself rather than BMRC having to create a Globus-only BMRC account for your collaborators. If you have not done this before, you will need to contact BMRC to have the capability enabled for your account. Once this is done, please follow the instructions below to create a collection and share folders.

  1. Login to https://www.globus.org/ as before. You can use your University of Oxford SSO, an ORCiD ID, a Google account, or a Globus ID.
    The image show the Globus Personal Connect login webpage. If you have an organisational login, you can search for your organisation. Alternatively you can sign in with a Google account or ORCID iD account.

  1. Make sure the file manager is selected. In Panels in the top right corner select the two-pane view if you will be transferring between two Globus collections. Search for bmrc#upload23 in the Collection search box on the left. Click continue below.
    The file manager in the Globus web app with the bmrc#upload23 collection selected.

  1. Click on the link to link your BMRC identity.
     Webpage showing link to link a Globus identity.

  1. Login using your BMRC account.
    Image of the form to login to the BMRC Globus endpoint.

  1. You should see your home directory on BMRC.
    A BMRC home directory in the Globus web app file manager.

  1. Go to the collections page. Unselect “Recent Tasks” and search for bmrc#upload23. Click on the collection to bring up the overview.
    How to search for the bmrc#upload23 collection on the collections tab in the Globus web app.

  1. Click on the collections tab.
    Where to find the collections tab in the Globus web app for the bmrc#upload23 collection.

  1. Click on “Add Guest Collection”.
    Where to click to add a Globus Guest Collection in the view of a collection in the Globus web app.

  1. If you get the error message below, click on “Register a Credential”.
    What to do if you need to register a credential when attempting to create a Globus Guest Collection.

  1. Then click on “Open in File Manager” and login as before. If you have recently logged in to BMRC you might not have to do these two steps.
    Where to open the file manager after registering a credential when creating a Globus Guest Collection.

  1. If you had to login again, go back to the collection and click “Add Guest Collection” again. Fill in the path to the directory you would like to share. NB. Any writes to this directory will be done as your BMRC account, so be careful to specify the correct path. Fill in the display name and select whether you would like activity notifications. Under “view more fields” there is an option to set an expiration limit, although this can also be set per user when you share the collection.
    How to configure settings when creating a Globus Guest Collection.

  1. Click on the permissions tab and then “Add Permissions – Share With”.
    Where to click to share a Globus Guest Collection.
    .

  1. Search for the Globus username or email of the person you would like to share the collection with. Select the “write” permission if needed. Click “Add Permission”.
    How to configure settings when sharing a Globus Guest Collection.

  1. The collection is now shared.
    An example of what a shared Globus Guest Collection looks like.

Globus CLI instructions

Firstly, you will need to create a new directory or point to an existing directory for the installation of the client, e.g. ~/opt.

wget https://downloads.globus.org/globus-connect-personal/linux/stable/globusconnectpersonal-latest.tgz
mkdir ~/opt
tar -C ~/opt -xf globusconnectpersonal-latest.tgz

Run Globus Connect Personal to create your personal endpoint and start it.

~/opt/globusconnectpersonal-3.2.6/globusconnectpersonal

Globus will ask you to authenticate at a URL it gives you and paste an authentication code.
Globus will ask you for the endpoint name and tell you the local endpoint ID e.g.

registered new endpoint, id: 69f0bf64-2540-11f0-9c4a-0ed8719d94b5

~/opt/globusconnectpersonal-3.2.6/globusconnectpersonal -start &

Install the Globus CLI and login to your personal endpoint.

python3 -m venv globus-cli
. globus-cli/bin/activate
pip install --upgrade pip
pip install globus-cli

globus login --no-local-server

Globus will ask you to authenticate.

globus ls 69f0bf64-2540-11f0-9c4a-0ed8719d94b5

Replace the endpoint ID with your one. This should give you the contents of your home directory.

Next find and login to the bmrc#upload23 endpoint.

globus endpoint search bmrc#upload23

This will give you the details of the BMRC endpoint.

globus login --no-local-server --gcs 5d24c0ec-7e44-45f4-a268-de69a6c4d3a5

or if that does not work

globus login --no-local-server --gcs 5d24c0ec-7e44-45f4-a268-de69a6c4d3a5:aeb6664a-81df-11eb-b798-f57b2d55370d

Globus will ask you to authenticate and login to the BMRC endpoint.

Globus will need your consent to access your folders on BMRC.

globus session consent --no-local-server 'urn:globus:auth:scope:transfer.api.globus.org:all[*https://auth.globus.org/scopes/aeb6664a-81df-11eb-b798-f57b2d55370d/data_access]'

Globus will ask you to authenticate.

globus ls aeb6664a-81df-11eb-b798-f57b2d55370d

This will show you the contents of your home directory on BMRC.

To do the transfer of a small test file, for example:

globus transfer aeb6664a-81df-11eb-b798-f57b2d55370d:/~/transfer-test.txt 69f0bf64-2540-11f0-9c4a-0ed8719d94b5:/~/transfer-test.txt

Replace the second endpoint ID with the one for your instance of Globus Connect Personal.

  • You should also look at the additional arguments and examples given on https://docs.globus.org/cli/reference/transfer/ .
  • The bmrc#upload23 collection requires encryption for transfers. It might be implicitly done (because Globus knows it is needed) but for your own peace of mind you might want to use the --encrypt argument.
  • You may also want --recursive and --preserve-timestamp and you should consider the appropriate --sync level and the use of --external-checksum if you already have checksums of the files.
  • If you didn't take a note of the globusconnectpersonal endpoint ID when you configured it then you can find it by logging into globus with the same account you used when you created it (globus login --no-local-server and choosing the same identity) and the using the command globus endpoint search --filter-scope administered-by-me.
  • The BMRC collection id is aeb6664a-81df-11eb-b798-f57b2d55370d, which you can find using the command globus endpoint search bmrc#upload23, where bmrc#upload23 is the name we gave when we configured it. The BMRC endpoint id is 5d24c0ec-7e44-45f4-a268-de69a6c4d3a5, but globus-cli commands seem to sometimes use endpoint to mean either endpoint or collection and sometimes specifically the endpoint.

On this page