Secure Gateway Server

On-Demand Webinars: Expert insights on Cybersecurity & Client Management

GET ACCESS

How to secure communication of mobile/roaming users using Secure Gateway Server?

This document explains the steps involved in securing the communication of roaming users using Secure Gateway Server. Secure Gateway Server can be used when roaming agents (on the mobile devices and desktops) access the server through the internet. It prevents the exposure of the server directly to the internet by serving as an intermediate server between the product server and roaming agents.This ensures that the product server is secure from risks and threats of vulnerable attacks.

For a step by step demonstration video on how to configure secure gateway server, click here.

Note: The Secure Gateway Server should be installed on a different machine than the one where the Endpoint Central Server, Distribution Server, or Failover Server is installed. However, it can be installed on the same machine as the agent.

 

 

How Secure Gateway works?

Secure Gateway Server is a component that will be exposed to the internet. The Secure Gateway Server acts as an intermediate server between the managed roaming agents and the central server. All communications from the roaming agents will be navigated through the Secure Gateway. When the agent tries to contact the central server, Secure Gateway server receives all the communications and redirects to the central server.

 Endpoint Central Secure Gateway Server Architecture

 

Note: Map your Secure Gateway's public IP address and product server's private IP address to a common FQDN in your respective DNS. For example, if your FQDN is "product.server.com", map this to both your Secure Gateway and central server IP address. By this mapping, the WAN agents of roaming users will access the central server via Secure Gateway (using internet) and the agents within the LAN network will directly reach central server, hence leading to quicker resolution.

 

Software requirements for Secure Gateway Server

You can install Secure Gateway Server on any of these Windows operating system versions:

  • Windows 10
  • Windows 11
  • Windows Server 2016
  • Windows Server 2019
  • Windows Server 2022

 

Hardware requirements for Secure Gateway Server

The hardware requirements for Secure Gateway Server include the following :

 
 
1 to 5000 computers
 
 
5001 to 9000 computers
 
 
9001 to 15000 computers
 
 
15001 to 18000 computers
 
 
18001 to 25000 computers
 
 
Above 25000 computers

 

To introduce Secure Gateway based communication to Endpoint Central, follow the steps given below:

  • Steps to Modify Endpoint Central Settings
  • Steps to Install and configure Secure Gateway
  • Infrastructure recommendations

 

Steps to Modify Endpoint Central Settings

  1. Enter Secure Gateway IP address instead of Central server IP address under Endpoint Central server details while adding remote office. This is to ensure the WAN agents and Distribution Server communicate through the Secure Gateway.
  2. Enable secured communication(HTTPS) under DS/WAN agent to Central server communication.
  3. Configure NAT settings using the Secure Gateway's public FQDN/IP address.  
      • On the product console, click on Admin tab > Server Settings >NAT Settings        
      • Choose to Manage Devices Via the Internet
      • Add the FQDN of the Secure Gateway Server against the Public FQDN under NAT settings as shown below

Endpoint Central Secure Gateway Server NAT Settings

 

Steps to Install and configure Secure Gateway

  1. Download and install Secure Gateway on a machine in Demilitarized zone.
  2. Enter the following details under Setting up the Secure Gateway window, which will open after the installation process.

    • Endpoint Central Server Name: Specify the FQDN/DNS/IP address of the Endpoint Central server. Or specify virtual IP address if Failover server is used.
    • Endpoint Central Https Port: Specify the port number that the mobile devices use to contact the Endpoint Central server (eg: 8383). It is recommended to use the same port 8383(HTTPS) for Central Server in secured mode.
    • Endpoint Central Notification Server port: 8027 (to perform on-demand operations), this will be pre-filled automatically
    • Web Socket Port : 8443(HTTPS), this will be pre-filled automatically.
    • Username & Password: Enter Endpoint Central user's credentials with administrative privilege.

 

Infrastructure recommendations

Ensure that you follow the steps given below:

  1. Secure Gateway's public IP address with the port 8383(https) should be provided to the Central server for accessibility verification.
  2. Using a public IP address is recommended for configuring non-AD machines.
  3. Configure Secure Gateway in such a way, that it should be reachable via public IP/FQDN address configured in NAT settings. You can also configure the Edge Device/Router in such a way that all the request that are sent to the Public IP/FQDN address gets redirected to the Endpoint Central Secure Gateway.
  4. It is mandatory to use HTTPS communication

Ports

Ports Purpose Type Connection
8040 Used for Agent-Server commmunication HTTP In bound to server
8041 Used for communication between agent and Endpoint Central MSP server HTTPS In bound to server
8058 For accessing PGSQL database in case of remote DB access TCP In bound to server
8057 Used to complete on-demand tasks like inventory scanning, patch scanning, remote control, remote shutdown and moving agents from one remote office to another TCP In bound to server
8047 For remote desktop sharing & associated tools TCP SSL In bound to server
8047 For voice and video calls UDP In bound to server
8048 Used for remote desktop sharing & associated tools TCP In bound to server
135 Used for remote administration and sharing of files and printer TCP Outbound
8045 Used for communication between agent and distribution server HTTPS In bound to distribution server

Note

  • The ports mentioned above are default ports that are used by the Endpoint Central MSP application. However you can opt to have port numbers of your choice.
  • If there is a firewall between Endpoint Central MSP server and the distribution server, all the ports listed above should be opened in the firewall. If you are not using a distribution server, you can just open the ports used by the Endpoint Central MSP server.

Remote Desktop & Mobile Device Management Software for MSPs trusted by

Back to Top