Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
morris
Collaborator

Centrally managing trac_client_1.ttm

Hi Guys,

In the Remote Access VPN Clients for Windows Administration Guide there is a chapter, where you can control the Gateways trac_client_1.ttm file from the Management:

Centrally Managing the Configuration File

 

Is this still working? I am in my lab and and after policy install the trac_client_1.ttm on the Gateway is still the same even though I made changes in the file on the Management. I've edited  $MDS_FWDIR/conf/fwrl.conf  according to the guide.

I've also removed the file on the Gateway to check, but its not recreated.

0 Kudos
3 Replies
Shyyyy
Explorer

Should work,
Make sure you followed the exact steps in the link you've sent.
also look at the following sk55502

0 Kudos
morris
Collaborator

Weird....in your posted SK is mentionmed to write the changes above the line "% SEGMENT DBLOAD" .

In all other documents is below the line "% SEGMENT FILTERLOAD" mentioned.

But.....this is basically the same:


% SEGMENT FILTERLOAD
NAME = conf/trac_client_1.ttm; DST = conf/trac_client_1.ttm;

[...]
NAME = conf/rule_adtr.C; DST = conf/rule_adtr.C;
% SEGMENT DBLOAD
NAME = db, objects; FUNC = database_load; COMPRESS = minizip;
[...]

0 Kudos
jorgeluiznim
Advisor

Hi @morris ,

Yes, central management via fwrl.conf still works, but there are a few common reasons why the file fails to update or recreate on the Security Gateway:

    1. Source file must exist on Management first: The fwrl.conf rule only instructs the policy installation process to copy a file—it does not generate it. If you removed the file from the Gateway and trac_client_1.ttm does not exist in the Management's conf/ directory, the transfer will fail silently and the file will not be created on the Gateway.
      • Fix: Copy a valid trac_client_1.ttm into $FWDIR/conf/ (or $MDS_FWDIR/conf/) on the Management Server before installing policy.

 

    1. MDS vs. CMA Scope: If the target Gateway is managed by a specific Domain Management Server (CMA), editing $MDS_FWDIR/conf/fwrl.conf won't apply to it. You must:
      • Switch context: mdsenv <CMA_NAME>
      • Place trac_client_1.ttm in $FWDIR/conf/ of that CMA.
      • Edit $FWDIR/conf/fwrl.conf inside that CMA.

 

    1. Syntax and Permissions:
      • Make sure the line under % SEGMENT FILTERLOAD retains exact syntax:
        NAME = conf/trac_client_1.ttm; DST = conf/trac_client_1.ttm;
      • Check read permissions on the Management server (chmod 644 trac_client_1.ttm).

 

  1. Note for Harmony Endpoint Clients:
    Remember that fwrl.conf pushes the file to the Security Gateway ($FWDIR/conf/trac_client_1.ttm). Endpoints only receive the updated .ttm when they re-connect/update the VPN site. Furthermore, any settings configured directly in the SmartEndpoint / Infinity Portal policy will override .ttm parameters on Harmony Endpoint clients.

Hope this helps!
Jorge Dias Junior

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events