Navigation

    • Register
    • Login
    • Search
    • Recent
    • Popular

    WAN Remote Access Issue

    Support
    2
    33
    3739
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      daymickcorr last edited by

      Hi,

      I keep having an error message :
      Could Not Enable Remote Access For This Com Server. The Remotely Module Has Not Been Installed.

      Remotely is installed with the com server but I receieve this error message if the com server is setup with something else than a local fqdn.

      i`m trying to install it on the dmz com server which has an external fqdn setup.

      When i setup the com server with the local fqdn it works I have no issues

      1 Reply Last reply Reply Quote 0
      • T
        theopenem_admin last edited by

        Is it installed directly on the com server in the DMZ?

        D 1 Reply Last reply Reply Quote 0
        • D
          daymickcorr @theopenem_admin last edited by

          @theopenem_admin

          Hi thanks for taking the time to answer back!

          I have tried on both I have the same issue on both

          1 Reply Last reply Reply Quote 0
          • T
            theopenem_admin last edited by

            Can you post any screenshots of your com server settings and remotely settings?

            D 2 Replies Last reply Reply Quote 0
            • D
              daymickcorr @theopenem_admin last edited by

              This post is deleted!
              1 Reply Last reply Reply Quote 0
              • D
                daymickcorr @theopenem_admin last edited by

                @theopenem_admin Screenshot from 2021-09-21 21-10-26.png Screenshot from 2021-09-21 21-09-59.png

                1 Reply Last reply Reply Quote 0
                • T
                  theopenem_admin last edited by

                  Is there a reason the remote access url is not filled in?

                  D 2 Replies Last reply Reply Quote 0
                  • D
                    daymickcorr @theopenem_admin last edited by

                    @theopenem_admin

                    It does not change the result

                    What allows to enable the remote access server is to change the com url to a local fqdn

                    I can add it if you wish

                    You see the error message Could Not Enable Remote Access for the Com Server ...?
                    Remotely is installed and i'm able to activate it but not with the pubilc domain

                    1 Reply Last reply Reply Quote 0
                    • D
                      daymickcorr @theopenem_admin last edited by

                      @theopenem_admin
                      e48d0a43-258c-4404-9d46-fb4797f13b45-image.png

                      1 Reply Last reply Reply Quote 0
                      • T
                        theopenem_admin last edited by

                        Is that your reverse proxy address or the address for that com server?

                        D 2 Replies Last reply Reply Quote 0
                        • D
                          daymickcorr @theopenem_admin last edited by

                          @theopenem_admin
                          reverse proxy

                          1 Reply Last reply Reply Quote 0
                          • D
                            daymickcorr @theopenem_admin last edited by

                            @theopenem_admin yes

                            1 Reply Last reply Reply Quote 0
                            • T
                              theopenem_admin last edited by

                              And your reverse proxy is forwarding to that server on port 444?

                              D 1 Reply Last reply Reply Quote 0
                              • D
                                daymickcorr @theopenem_admin last edited by

                                @theopenem_admin
                                no
                                the reverse proxy sends to http://local.fqdn:8000
                                remotely and com web services receive remote transactions as if they were local

                                the reverse proxy interacts with the web server and then sends back the info to the client

                                1 Reply Last reply Reply Quote 0
                                • T
                                  theopenem_admin last edited by

                                  It seems the proxy is the issue then. I would try this:

                                  For the remotely url, put in http://local.fqdn:8000, then initialize remote access. After it's done change the url to the proxy but don't initialize it again.

                                  It's all I can come up with at the moment, not sure if it would work. I would need to run some tests with a reverse proxy, which I haven't done yet.

                                  D 4 Replies Last reply Reply Quote 0
                                  • D
                                    daymickcorr @theopenem_admin last edited by

                                    @theopenem_admin

                                    I have done this

                                    change com to local fqdn
                                    enable remote acess
                                    change com to public fqdn
                                    change remote access url to public fqdn
                                    intiliaize remote acess
                                    enable remote access server from com cluster

                                    the entry was added, after configuration.

                                    toec tells me it cannot reach com, but app is able to reach com on public name.
                                    with internal com and public remotely, toec tells me remotely cannot be validated

                                    The reverse proxy I use is haproxy.

                                    can you explain to me what is happening ? what the theopenem is trying to do to interact with each other.

                                    I have tried inspecting with fiddler and on IIS observation I don't have any interactions and in the logs I have nothing. The documentation is not helping me

                                    I use the reverse proxy so that all my hosted web servers goes out through 443 redirections are based on urls also the reverse proxy takes care of creating, assigning, renewing and distributing ssl certificates, I can also modify each transaction add monitoring authentication etc

                                    1 Reply Last reply Reply Quote 0
                                    • D
                                      daymickcorr @theopenem_admin last edited by

                                      @theopenem_admin
                                      With the reverse proxy I cannot host directly the web server externally because i cannot validate let's encrypt certificates with the infrastructure, so I have to use self signed certificates and expose directly the servers with no middleware, I don't feel safe doing this because on the self signed certificates the certificate authority is private not public, so you can mitm the public toec clients .

                                      Also watchguard, sonicwall etc all use reverse proxies now

                                      1 Reply Last reply Reply Quote 0
                                      • D
                                        daymickcorr @theopenem_admin last edited by

                                        @theopenem_admin I was going through logs and on toec before having com communications error I have ApiRequest - The Request Was Unauthorized Provision/ComConnectionTest/ the request does not appear on approval requests even with all approvals disabled I have the same issue

                                        1 Reply Last reply Reply Quote 0
                                        • D
                                          daymickcorr @theopenem_admin last edited by

                                          @theopenem_admin Ok for toec the com api seems to refuse to allow toec, because of an authentification issue caused by the reverse proxy.
                                          what kind of security is used on the rest api of the com server for it to need to have a specific origin ?

                                          1 Reply Last reply Reply Quote 0
                                          • T
                                            theopenem_admin last edited by

                                            Can you put your toec-api log into debug mode?

                                            In your toec api web.config, about 2/3 down find level value="INFO", change it to DEBUG.

                                            Have your external client try to checkin and post the log

                                            D 2 Replies Last reply Reply Quote 0