Cannot connect to remote comuters

avatar
kstevens
Disabled

We just purchased Wayk Now and cannot connect to remote computers. We are using a Fortinet Firewall and open port 4489 each way on the firewall but we still cannot connect. My Firewall tech watched traffic from my IP trying to connect and he noticed it was trying to open some UDP ports. Can you help me by telling me what ports on the firewall need to be opened to allow remote control out to different networks?

All Comments (14)

avatar

Hello

When making a direct connection (either by IP address or hostname), TCP/4489 is indeed used.

The connection to Wayk Den uses secure WebSockets, which should appear similar to HTTPS traffic.

Connections via Wayk Den use UDP - similar to WebRTC peer-to-peer connections, the port changes every time. It sounds like this is where things are not working for you.

Just to be clear - your client shows the status as "Ready" in the bottom-left corner? And you are trying to connect to another Wayk ID (not an IP address or hostname)?

Thanks,

Richard Markievicz

avatar

Yes, they provided me the source ID and I placed it into my target ID and could not connect

avatar

Hello

Ok, so as I said in my previous post, the current peer-to-peer connection is UDP based and works a lot like WebRTC. This is great for NAT traversal but can be a problem in firewalled or otherwise restricted networks, because the inbound UDP port is random and changes every time.

We have been working on a solution to this that should simply authorizing the Wayk Now traffic. Basically, we have added an option to use a TCP relay server, which once enabled, only requires opening a single inbound TCP port on the firewall.

This feature is part of the 3.1 release of Wayk Now, which is in testing right now but a release should be imminent (within the next week).

If you can wait a few more days for this, I think it would be the best solution as it will require minimal reconfiguration of your firewall.

Thanks,

Richard Markievicz

avatar

OK, perfect, can Would you be able to notify me when it is released?

avatar

Hello,

I will notify you back in this thread once it is available!

Thanks for your patience,

Richard Markievicz

avatar

Awesome, thanks

avatar

Hello


The 3.1 release is now available for download, and includes the option of using a TCP relay server.


The setting can be found under the "Connectivity" section - you need to enable "Prioritize relay servers for peer-to-peer connections". Note you only need to enable the setting on one "side" of the connection (you do not have to instruct the remote user to change anything).


We would welcome any further questions or feedback you have on this!


Thank you for your patience.

Richard Markievicz

avatar

Hello


So basically we have the same problem...
The Clients shows "Ready" but I'm unable to connect to an external Computer using the Den ID.
Also I'm unable to connect from an external Computer to an internal using the Den ID.

Locally works fine with the Hostname or IP, but not with the Den ID...


I've checked the Firewall and I didn't found any blocked outgoing traffic from that machine...
I tried "Prioritize relay servers for peer-to-peer connections" and opened the outgoing ports 4492, 443... (still unable to connect)

To mention: we also use a proxy
I will send you (Richard) the LogFile...
Hope you can find something...

Best Regards
Hans

avatar

Hi Hans,

You can send your logs to support@devolutions.net, we will take a look at it.

Best regards,

Marc-André Moreau

avatar

Hi Hans

Thanks for sending the logs over. Can we know the details of your proxy?

Thanks,

Richard Markievicz

avatar

Hi Richard

We use Zscaler...
Let me know if you need more information.


Best regards,
Hans

avatar

Hello Hans

I expect that the relay connection is getting blocked as well. It uses TCP/8080, and won't look like a known protocol.

It is strange that we don't seem to be detecting your proxy in the app. You use the Windows client, right?

How are your proxy settings configured in your environment? I'd like to find out why we don't detect them...

Thanks again,

Richard Markievicz

avatar

Hi Richard




Yes, do we use Windows.




It's a Cloud Proxy - the browser traffic get routed to a zscaler server... We use GPOs to configure the Proxy in the Windows settings...
Let me know if you need more information or help detecting the proxy...




That was it, thank you very much! I opened the outgoing port even though i didn't see it getting blocked on the FW...
Thank you very much for the awesome updates in 3.1 - Wayk Now is becoming a pleasure!

Best regards
Hans

avatar

Hi Hans

Great stuff! We are really glad to hear it. Please be forthcoming with any further questions or comments.

Thanks again,

Richard Markievicz