[RESOLVED] Client workstation unreachable on VLAN

Questions about WAPT Packaging / Requests and help regarding Wapt packages.
Forum Rules
Community Forum Rules
* English support on www.reddit.com/r/wapt
* French community support is available on this forum
* Please prefix the topic title with [RESOLVED] if it is resolved.
* Please do not edit a topic that is tagged [RESOLVED]. Open a new topic referencing the old one.
* Specify the installed WAPT version, full version, and build number (2.2.1.11957 / 2.2.2.12337 / etc.) as well as the Enterprise/Discovery edition.
* Versions 1.8.2 and earlier are no longer supported. The only questions accepted regarding version 1.8.2 are related to upgrading to a supported version (2.1, 2.2, etc.).
* Specify the server OS (Linux/Windows) and version (Debian Buster/Bullseye - CentOS 7 - Windows Server 2012/2016/2019).
* Specify the OS of the administration/package creation machine and the machine with the problematic agent, if applicable (Windows 7/10/11/Debian 11/etc.).
* Avoid asking multiple questions when opening a topic, otherwise it may be ignored. If there are multiple topics, open separate topics, preferably one after the other and not all at the same time (i.e., do not spam the forum).
* Include code snippets, screenshots, and other images directly in the post. Links to Pastebin, Bitly, and other third-party sites will be systematically removed.
* As with any community forum, support is provided voluntarily by members. If you require commercial support, you can contact Tranquil IT's sales department at 02.40.97.57.55
Locked
jcurnill
Messages: 11
Registration: January 10, 2023 - 3:31 PM

January 10, 2023 - 3:36 PM

Hello,
our firewall, which manages the different VLANs, is a pfSense. Only the workstations on the VLAN where the WAPT server is installed are reachable. The others are disconnected. The client installs correctly, no problem, the workstation appears correctly on the server's interface, but nothing works. Even with DNS, I've allowed the server's IP address on all interfaces using both TCP and UDP. Do you have any advice (port number to open?)?
Sincerely
User avatar
dcardon
WAPT Expert
Messages: 1932
Registration: June 18, 2014 - 09:58
Location: Saint Sébastien sur Loire
Contact :

January 10, 2023 - 5:51 PM

WAPT version, etc. (see forum rules)?
As mentioned in the documentation, the WAPT client only uses port 443 to connect to the server, and then creates a WebSocket on port 443 as well. The server doesn't need to see the client machines. We need to check why the WebSocket isn't mounting.
Regards,
Denis
Denis Cardon - Tranquil IT
Share your experiences on WAPT! Send us your blog and article URLs in the "Your Opinion of the forum, and we'll feature them on the WAPT
jcurnill
Messages: 11
Registration: January 10, 2023 - 3:31 PM

January 11, 2023 - 08:03

Hello,
thank you for your reply. Our server is running Windows Server 2019, WAPT version 2.2.3.12481. How can I determine the source of the WebSocket error? Regards
User avatar
sfonteneau
WAPT Expert
Messages: 2318
Registered: July 10, 2014 - 11:52 PM
Contact :

January 11, 2023 - 08:47

Do you have HTTPS certificate verification enabled?
jcurnill
Messages: 11
Registration: January 10, 2023 - 3:31 PM

January 16, 2023 - 11:22

Hello,
how do I activate this verification?
Installing the client is no problem; I can access the WAPT Enterprise console from my workstation on the administrative VLAN, even though the server is on the pedagogical VLAN. But nothing works; workstations outside the pedagogical VLAN are disconnected.
Thanks in advance.
User avatar
dcardon
WAPT Expert
Messages: 1932
Registration: June 18, 2014 - 09:58
Location: Saint Sébastien sur Loire
Contact :

January 17, 2023 - 2:25 PM

Good morning,

If you launch the agent in debug mode, do you get more explicit messages?

In a command prompt with high rights:

Code: Select all

cd c:\program files (x86)\wapt\
runwaptservice.bat -l debug
You should have this if everything goes well:

Code: Select all

2023-01-17 14:21:00,817 [wapttasks SocketIOClient 14556] INFO Connecting Socketio to https://srvwapt.mydomain.lan:443
2023-01-17 14:21:00,818 [waptws SocketIOClient 14556] INFO Attempting WebSocket connection to wss://srvwapt.mydomain.lan:443/socket.io/?transport=websocket&EIO=3
2023-01-17 14:21:00,837 [waptws SocketIOClient 14556] INFO WebSocket connection accepted with {'sid': '3b85cbfe59844c649e30d9ac3b901fae', 'upgrades': [], 'pingTimeout': 60000, 'pingInterval': 25000}
2023-01-17 14:21:00,838 [waptws SocketIOClient 14556] INFO Engine.IO connection established
2023-01-17 14:21:00,842 [waptws Thread-3 5324] INFO Sending packet PING data None
2023-01-17 14:21:00,844 [wapttasks SocketIOClient 14556] INFO WS read loop for 120s
2023-01-17 14:21:00,844 [waptws Thread-5 8772] INFO Received packet MESSAGE data 0
2023-01-17 14:21:00,850 [waptws Thread-6 12212] INFO Namespace / is connected
2023-01-17 14:21:00,851 [waptws Thread-5 8772] INFO Received packet PONG data None
Let's see what error message you get at that point.

Sincerely,

Denis
Denis Cardon - Tranquil IT
Share your experiences on WAPT! Send us your blog and article URLs in the "Your Opinion of the forum, and we'll feature them on the WAPT
jcurnill
Messages: 11
Registration: January 10, 2023 - 3:31 PM

January 18, 2023 - 10:59

Hello, after multiple attempts it finally worked. Probably a problem between my PC firewall and my pfSense. Thank you for your help.
User avatar
dcardon
WAPT Expert
Messages: 1932
Registration: June 18, 2014 - 09:58
Location: Saint Sébastien sur Loire
Contact :

January 18, 2023 - 6:05 PM

Thank you for your feedback, I'm marking the topic as resolved.
Regards,
Denis
Denis Cardon - Tranquil IT
Share your experiences on WAPT! Send us your blog and article URLs in the "Your Opinion of the forum, and we'll feature them on the WAPT
Locked