LetsEncrypt validation behind firewall

Get help with troubleshooting issues
Post Reply
johnrollins
Posts: 25
Joined: Fri Nov 11, 2016 4:36 pm

LetsEncrypt validation behind firewall

Post by johnrollins » Wed Jan 18, 2017 9:33 am

Hi,

We run a hosted service for our clients where the firewall restricts access to all ip addresses except those provided by the client. In order to use the letsencrypt ssl certificate I assume I need to open the firewall for a particular ip address? I currently get an 805 error trying to set it up. Can you tell me what ip address I should allow in and if it needs to be permanently open for the auto renewal?

Thanks,
John

User avatar
admin
Site Admin
Posts: 1649
Joined: Wed Sep 05, 2012 6:38 am

Re: LetsEncrypt validation behind firewall

Post by admin » Wed Jan 18, 2017 11:28 am

Hello,

Port 80 must be allowed in order for the SSL certificate generation tool to work properly and your domain name must be accessible from external sources, more information about this can be found here : http://www.terminalserviceplus.com/docs ... te-manager
Olivier
TSplus support team administrator
Image

johnrollins
Posts: 25
Joined: Fri Nov 11, 2016 4:36 pm

Re: LetsEncrypt validation behind firewall

Post by johnrollins » Wed Jan 18, 2017 11:50 am

Thanks, I understand that port 80 must be accessible.

Is there a way of setting up tsplus so that letsencrypt can validate, but users wanting to use the web portal have to use port 443? If this is possible I can open port 80 completely but prevent access on other ports? My clients will not allow me to have an open web site for connections to the application.

Thanks,
John

User avatar
admin
Site Admin
Posts: 1649
Joined: Wed Sep 05, 2012 6:38 am

Re: LetsEncrypt validation behind firewall

Post by admin » Wed Jan 18, 2017 7:36 pm

Hello,

Yes, you will be able to connect remotely by allowing 80 and 443 only. Connection will be available by using the web client HTML5 and RemoteApp.
Olivier
TSplus support team administrator
Image

Post Reply