Navigation

    • Register
    • Login
    • Search
    • Recent
    • Popular

    WAN Remote Access Issue

    Support
    2
    33
    3739
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      daymickcorr @theopenem_admin last edited by

      @theopenem_admin
      With the reverse proxy I cannot host directly the web server externally because i cannot validate let's encrypt certificates with the infrastructure, so I have to use self signed certificates and expose directly the servers with no middleware, I don't feel safe doing this because on the self signed certificates the certificate authority is private not public, so you can mitm the public toec clients .

      Also watchguard, sonicwall etc all use reverse proxies now

      1 Reply Last reply Reply Quote 0
      • D
        daymickcorr @theopenem_admin last edited by

        @theopenem_admin I was going through logs and on toec before having com communications error I have ApiRequest - The Request Was Unauthorized Provision/ComConnectionTest/ the request does not appear on approval requests even with all approvals disabled I have the same issue

        1 Reply Last reply Reply Quote 0
        • D
          daymickcorr @theopenem_admin last edited by

          @theopenem_admin Ok for toec the com api seems to refuse to allow toec, because of an authentification issue caused by the reverse proxy.
          what kind of security is used on the rest api of the com server for it to need to have a specific origin ?

          1 Reply Last reply Reply Quote 0
          • T
            theopenem_admin last edited by

            Can you put your toec-api log into debug mode?

            In your toec api web.config, about 2/3 down find level value="INFO", change it to DEBUG.

            Have your external client try to checkin and post the log

            D 2 Replies Last reply Reply Quote 0
            • D
              daymickcorr @theopenem_admin last edited by

              @theopenem_admin
              This is way more information thank you, it's really appreciated

              ClientApi.log

              Also I had an issue with a .net core rest api where it would not support reverse proxies
              I had used this information to add the support and it worked, maybe you could see some useful information

              https://docs.microsoft.com/en-us/aspnet/core/host-and-deploy/linux-nginx?view=aspnetcore-5.0#configure-nginx

              https://docs.microsoft.com/en-us/aspnet/core/host-and-deploy/proxy-load-balancer?view=aspnetcore-5.0

              1 Reply Last reply Reply Quote 0
              • T
                theopenem_admin last edited by

                Your log indicates a certificate error. Did you install the Toems certs on the com server?

                D 1 Reply Last reply Reply Quote 0
                • D
                  daymickcorr @theopenem_admin last edited by

                  @theopenem_admin yes I can upload the certs if you want
                  I have generated the certificates with the public name set for the com server I don't know if this changes something

                  D 1 Reply Last reply Reply Quote 0
                  • T
                    theopenem_admin last edited by

                    Can you provide a screenshot showing the toems ca is installed in the root certificate authority?

                    D 7 Replies Last reply Reply Quote 0
                    • D
                      daymickcorr @daymickcorr last edited by

                      @daymickcorr 917c089e-b914-4b83-9771-e2cc693bd355-image.png

                      1 Reply Last reply Reply Quote 0
                      • D
                        daymickcorr @theopenem_admin last edited by

                        @theopenem_admin
                        Ok I installed the bad intermediate certificate, sorry I'll update soon about remotely

                        1 Reply Last reply Reply Quote 0
                        • D
                          daymickcorr @theopenem_admin last edited by

                          @theopenem_admin
                          Remotely has had a strange issue the installation failed on the client
                          When I try to run the deployment command manually I get this application cannot be executed on your pc and the installer weighs 0 bytes.

                          I'm going to check on the remotely side I saw that there was a cors setting, How would i redeploy the remotely ?

                          1 Reply Last reply Reply Quote 0
                          • D
                            daymickcorr @theopenem_admin last edited by

                            @theopenem_admin FrontEnd.log

                            Ok the app server contains the remotely files and the folder does not sync with the com server

                            1 Reply Last reply Reply Quote 0
                            • D
                              daymickcorr @theopenem_admin last edited by

                              @theopenem_admin
                              It's strange it tells me back that the certificates are invalid and it is giving me again the authorization issue, i'm reinstalling the certificates on both app and com server

                              1 Reply Last reply Reply Quote 0
                              • D
                                daymickcorr @theopenem_admin last edited by

                                @theopenem_admin

                                on the toec api i'm recieving these error messages

                                4fe1b914-c623-4391-9fae-878464388e23-image.png

                                1 Reply Last reply Reply Quote 0
                                • D
                                  daymickcorr @theopenem_admin last edited by

                                  @theopenem_admin
                                  2def5e7c-c885-415b-a4df-ba296dae641f-image.png

                                  I've added a rule to rewrite the hostname in the reverse proxy i'm still getting the same issue

                                  what certificate does the toec client need intermediate ?

                                  1 Reply Last reply Reply Quote 0
                                  • D
                                    daymickcorr @theopenem_admin last edited by

                                    @theopenem_admin
                                    9708ffa6-276a-4e48-a41d-f270ed6ec51f-image.png

                                    1 Reply Last reply Reply Quote 0
                                    • D
                                      daymickcorr @theopenem_admin last edited by

                                      @theopenem_admin
                                      It seems like ProvisionAuth.cs In toec api validates the uri it also looks like it for intercom.
                                      I'm pretty sure that why i'm not getting pushed remotely correctly, i asked the reverse proxy to change the uri for what the toec api is waiting for but the toec api is not accepting the change, like if it was not reading my new http header, i'm pretty sure those 2 controllers needs to have reverse proxy support added

                                      1 Reply Last reply Reply Quote 0