- CheckMates
- :
- Products
- :
- Harmony
- :
- Endpoint
- :
- Re: Harmony Connect On-premise natting and block G...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Harmony Connect On-premise natting and block Gaia Portal access
Hello,
I have harmony connect on-premise version which I need to give to the people who are roaming and they need to connect to on-premise server over Internet.
I know that my server needs to be natted so that agents will communicate over internet however when I do that since EPM server listen on port 443 even my Gaia portal even exposes over internet.
Since being a mgmt server I do not have option to set the different URI for GAIA access and wondering how do I do that?
TIA
Blason R
Blason R
CCSA,CCSE,CCCS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It can be configured via clish: set web ssl-port 4434 (or whatever the desired port is).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Nope - that is not possible and I already tried that.
Agent goes offline since they connect on port 443.
Blason R
CCSA,CCSE,CCCS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thats odd. I set mgmt web UI on port 4434 many times before and worked just fine.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes It works with only SMS server but definitely not with EPM server. have you tried with EPM or pure mgmt server?
Blason R
CCSA,CCSE,CCCS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As a matter of fact, yes, on R81.10, no issues.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hmmm - Not sure why it didnt work with me then. I am on R81 and is having EPM server only.
I verified the apache2 config files and internally everything is diverted to localhost:4434 and multiple vhosts.
Let me give a try again though
Blason R
CCSA,CCSE,CCCS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not sure mate, sorry. I had to delete that lab to make some space for Palo Alto lab, but definitely worked fine in R81.10. Cant recall jumbo on it back then, but Im sure that makes no difference.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you read this already: https://support.checkpoint.com/results/sk/sk178064
