It all depends on the flow of the expected traffic. i.e. If the SFTP client is initiating the connection. Then no issue, it's what Firewalls' were built for. Simply put a firewall rule and port forwards/nat in place to limit the port and hosts. Something like the below.
You could also pop the client in it's own DMZ as well. Just need to be very specific with Source and Destination hosts.
https://documentation.meraki.com/MX/NAT_and_Port_Forwarding/Active_and_Passive_FTP_Overview_and_Conf...
Cheers,
Ivan
Cheers,
Ivan Jukić,
Meraki APJC
If you found this post helpful, please give it kudos. If it solved your problem, click "accept as solution" so that others can benefit from it.