Secure Tunnel Settings

Prev Next

Complete the following fields to configure secure tunnel settings for Gateway appliances:

  • Client Hostname/IP. This hostname is only used to advise clients where to find this appliance. Use only fully qualified domain names or IPv4 / IPv6 address.

NOTE

You must renew the appliance certificate after changing the client hostname or client connections will fail.

NOTE

For an AppGate Gateway to allow clients to create tunnels using either IPv4 or IPv6, the Gateway must be configured with a single FQDN that has both an IPv4 A record and IPv6 AAAA record for that FQDN in public DNS.

  • Local Client Tunneling - Load Balancing Weighting Factor. This weighting factor can be set independently of the external one.

NOTE

Before changing the weighting factor please refer to the detailed explanation in the manual.

  • Connect via Local Network. When a client is on the local LAN it will connect using the local client hostname/IP(s) instead of the external one.

  • Client Tunneling - Allowed Destinations. List the destinations the Gateway will allow (firewall rule) for secure tunnel traffic.

  • Client Tunnel DTLS/QUIC Port. For a Gateway appliance, this is used for DTLS protocol tunneling between Gateway and client, default 443.