Transferring Data to/from BMRC
Configuring FileZilla for Two Factor Authentication
FileZilla is a popular tool for SFTP file transfers and can be used to transfer files to/from BMRC with additional configuration as follows.
FileZilla can be downloaded from https://filezilla-project.org/download.php?show_all=1
- Open FileZilla from the Menu Bar select Edit -> Settings. In the Connection settings tab, set your timeout value to 600 seconds (ten minutes). Then click OK to save your settings.

- From FileZilla's main window, click the Site Manager button (underneath the File menu) to display the Site Manager window.

- Click New Site to configure your connection to the BMRC cluster and copy the details shown above, namely:
Protocol: SFTP
Host: cluster2.bmrc.ox.ac.uk
Port: 22
Logon Type: Interactive
User: [Enter your username]
NB If connecting to another BMRC server, adjust the Site Name and Host settings as needed. - Now select the Transfer Settings tab, enable Limit number of simultaneous connections and set to 1.

- Now click OK to save this configuration. Back at the main window, click the down-arrow next to the Site Manager button and select BMRC Cluster. This will begin the login process.
- If FileZilla warns you about an Unknown host key, tick the box marked Always trust this host, add this key to the cache and click OK. (Please contact BMRC if you wish to confirm the key identity further.)
- FileZilla will now prompt you to enter your First Factor i.e. your password:

- After entering your password and clicking OK, FileZilla will then prompt you to enter your second factor code:

- After entering your second factor code and clicking OK, FileZilla should now be connected. The left hand size of the FileZilla window will be showing files on your local computer. The right hand side will be showing files on the BMRC Cluster (or whatever remote site you have configured). Remember that on the BMRC cluster, all data should be stored in your group area under /well/<group>/users/<username>/ - so you may need to navigate to the appropriate location in the right hand window before dragging and dropping files between the two systems.
Data Transfers Via Globus
BMRC is able to facilitate both incoming and outgoing data transfers via Globus, a popular, secure third party platform for transferring data. Globus is our preferred option when transferring data to/from your research partners who do not have a regular BMRC account, whether they are elsewhere within the University of Oxford or outside the University.
Prerequisites
In order to request a data transfer via Globus, the BMRC user must in the first instance email us with details of the data to be transferred, cc'ing both to their PI for authorisation and to their external collaborator (the intended sender or recipient of the data).
The external collaborator will need :
1) Either: Access to an institutional Globus server. Please ask your institution's IT services whether there is an institutional licence and whether it provides a suitable location for your data to be received or transmitted from.
2) Or: The Globus Connect Personal software installed onto their institutional or personal computer.
Installing Globus Connect Personal
NB Installing Globus Connect Personal is not needed if you are using an institutional Globus account.
To install Globus Connect Personal:
- Visit the Globus Connect Personal website and download the appropriate client for your operating system. Clients are available for Windows, Mac and Linux. Follow the installation instructions in order to complete the installation.
- During the installation process, you will be asked to login via the Globus website. You can login with an organisational account, a Google account, an ORCiD ID account or it is possible to create a Globus ID with a username and password. University of Oxford users can now use their SSO to login.

- Once logged in, you will be asked to provide consent to the use of Globus Connect Personal and provide a name for the computer on which you are installing the software. Choose a name that is meaningful to you and click Allow to continue.

- The Globus Connect Personal software on your laptop will now ask you to complete the setup by choosing a name for the data collection on your laptop.

In general, you can use your laptop name as the Collection name. For transfers to/from BMRC, the High Assurance button should be left unticked. - Finally, the application should notify you that it has been successfully installed and that the Globus Connect Personal application is now running. Mac and Windows users should find a notification icon in the tray or menubar. Linux users may see a notification icon or the running application window.
Using Globus for Data Transfers To/From BMRC
In order to carry out a data transfer to/from BMRC, you will need to have logged in to an institutional Globus account or configured Globus Connect Personal on your own computer following the steps above. On request, BMRC will enable the ability to create a Globus Guest Collection, which can be shared with external collaborators. Users with regular BMRC cluster accounts will need to request that Globus access is enabled.
Once the above is in place, you can carry out a data transfer by following these steps.
- Login to the Globus website using the same credentials used previously (whether an institutional login, Google login, ORCiD ID or Globus ID).
- Once logged in, in the file manager collections search box search for bmrc#upload23. Then click continue to activate the endpoint.

- When activating the endpoint, you will be asked to input the credentials for your BMRC account. You must enter your 2FA code, as this will be enabled for your account, as well as your username and password. You may periodically need to reactivate if you do not use the endpoint.

- The file manager window can be vertically split into two halves by selecting the two-pane view in the "Panels" section in the top right of the webpage . You will see the contents of the BMRC folder and the bmrc#upload23 endpoint on the left side of the screen. You should now search for the collection name you registered for your own computer. If you click in the endpoint search box you will be taken to a new window where you can either search by name or click the Your Collections tab to show your own collections.

- After selecting your collection, you will return to the file manager window, with the BMRC endpoint showing on the left and your own endpoint showing on the right. To transfer files in either direction:
- Navigate to find the files the need to transfer (either in the BMRC endpoint or your own endpoint).
- Click the checkbox next to your files or folders to select them for transfer.
- Click the Transfer & Timer Options button to show advanced options and make sure to select Encrypt Transfer (NB if encryption is not enabled, the transfer will fail, but this should be enabled by default for bmrc#upload23).
- Finally click the Start button on the appropriate side of the window to begin the transfer.

- Once your transfer has started, you can monitor it from the Activity page (see the menu on the left side of the screen).
- Once the transfer is in progress, you can logout from the Globus website and the transfer will continue in the background. Please log back in later to confirm that your transfer has completed successfully.
- In the event that your endpoint activation expires before the transfer has completed, you can simply re-activate the endpoint and the transfer should then automatically resume.
Creating and Sharing a Globus Guest Collection
It is now possible to create a Globus Guest Collection and share folders from BMRC with your collaborators yourself rather than BMRC having to create a Globus-only BMRC account for your collaborators. If you have not done this before, you will need to contact BMRC to have the capability enabled for your account. Once this is done, please follow the instructions below to create a collection and share folders.
-
Login to https://www.globus.org/ as before. You can use your University of Oxford SSO, an ORCiD ID, a Google account, or a Globus ID.

-
Make sure the file manager is selected. In Panels in the top right corner select the two-pane view if you will be transferring between two Globus collections. Search for bmrc#upload23 in the Collection search box on the left. Click continue below.

-
Click on the link to link your BMRC identity.

-
Login using your BMRC account.

-
You should see your home directory on BMRC.

-
Go to the collections page. Unselect “Recent Tasks” and search for bmrc#upload23. Click on the collection to bring up the overview.

-
Click on the collections tab.

-
Click on “Add Guest Collection”.

-
If you get the error message below, click on “Register a Credential”.

-
Then click on “Open in File Manager” and login as before. If you have recently logged in to BMRC you might not have to do these two steps.

-
If you had to login again, go back to the collection and click “Add Guest Collection” again. Fill in the path to the directory you would like to share. NB. Any writes to this directory will be done as your BMRC account, so be careful to specify the correct path. Fill in the display name and select whether you would like activity notifications. Under “view more fields” there is an option to set an expiration limit, although this can also be set per user when you share the collection.

-
Click on the permissions tab and then “Add Permissions – Share With”.
.
-
Search for the Globus username or email of the person you would like to share the collection with. Select the “write” permission if needed. Click “Add Permission”.

-
The collection is now shared.

Globus CLI instructions
Firstly, you will need to create a new directory or point to an existing directory for the installation of the client, e.g. ~/opt.
wget https://downloads.globus.org/globus-connect-personal/linux/stable/globusconnectpersonal-latest.tgz
mkdir ~/opt
tar -C ~/opt -xf globusconnectpersonal-latest.tgz
Run Globus Connect Personal to create your personal endpoint and start it.
~/opt/globusconnectpersonal-3.2.6/globusconnectpersonal
Globus will ask you to authenticate at a URL it gives you and paste an authentication code.
Globus will ask you for the endpoint name and tell you the local endpoint ID e.g.
registered new endpoint, id: 69f0bf64-2540-11f0-9c4a-0ed8719d94b5
~/opt/globusconnectpersonal-3.2.6/globusconnectpersonal -start &
Install the Globus CLI and login to your personal endpoint.
python3 -m venv globus-cli
. globus-cli/bin/activate
pip install --upgrade pip
pip install globus-cli
globus login --no-local-server
Globus will ask you to authenticate.
globus ls 69f0bf64-2540-11f0-9c4a-0ed8719d94b5
Replace the endpoint ID with your one. This should give you the contents of your home directory.
Next find and login to the bmrc#upload23 endpoint.
globus endpoint search bmrc#upload23
This will give you the details of the BMRC endpoint.
globus login --no-local-server --gcs 5d24c0ec-7e44-45f4-a268-de69a6c4d3a5
or if that does not work
globus login --no-local-server --gcs 5d24c0ec-7e44-45f4-a268-de69a6c4d3a5:aeb6664a-81df-11eb-b798-f57b2d55370d
Globus will ask you to authenticate and login to the BMRC endpoint.
Globus will need your consent to access your folders on BMRC.
globus session consent --no-local-server 'urn:globus:auth:scope:transfer.api.globus.org:all[*https://auth.globus.org/scopes/aeb6664a-81df-11eb-b798-f57b2d55370d/data_access]'
Globus will ask you to authenticate.
globus ls aeb6664a-81df-11eb-b798-f57b2d55370d
This will show you the contents of your home directory on BMRC.
To do the transfer of a small test file, for example:
globus transfer aeb6664a-81df-11eb-b798-f57b2d55370d:/~/transfer-test.txt 69f0bf64-2540-11f0-9c4a-0ed8719d94b5:/~/transfer-test.txt
Replace the second endpoint ID with the one for your instance of Globus Connect Personal.
- You should also look at the additional arguments and examples given on https://docs.globus.org/cli/reference/transfer/ .
- The bmrc#upload23 collection requires encryption for transfers. It might be implicitly done (because Globus knows it is needed) but for your own peace of mind you might want to use the --encrypt argument.
- You may also want --recursive and --preserve-timestamp and you should consider the appropriate --sync level and the use of --external-checksum if you already have checksums of the files.
- If you didn't take a note of the globusconnectpersonal endpoint ID when you configured it then you can find it by logging into globus with the same account you used when you created it (globus login --no-local-server and choosing the same identity) and the using the command globus endpoint search --filter-scope administered-by-me.
- The BMRC collection id is aeb6664a-81df-11eb-b798-f57b2d55370d, which you can find using the command globus endpoint search bmrc#upload23, where bmrc#upload23 is the name we gave when we configured it. The BMRC endpoint id is 5d24c0ec-7e44-45f4-a268-de69a6c4d3a5, but globus-cli commands seem to sometimes use endpoint to mean either endpoint or collection and sometimes specifically the endpoint.










