Views:

Manage Internet Access gateways and corporate network locations to monitor, analyze, and control web activities on known locations, such as the corporate headquarters, a branch office, or company VPN.

In addition to the Cloud Gateway, Internet Access also provides a flexible option to deploy one or more local on-premises gateways in your organization's network as a hybrid protection solution.
The Gateways tab in the Internet Access Configuration screen allows you to manage Internet Access Cloud and On-Premises Gateways to identify your corporate network locations.
  • Internet Access Cloud Gateway: Specify the externally-facing IP addresses of your organization's internet gateways and register the IP addresses to the Internet Access Cloud Gateway.
  • Internet Access On-Premises Gateway: Deploy a Service Gateway virtual appliance and enable the Zero Trust Internet Access On-Premises Gateway service to indicate the corporate locations managed by each server.
Tip
Tip
  • Trend Vision One can inspect HTTPS/HTTP traffic forwarded to an Internet Access Gateway (such as the Cloud Gateway) from corporate network locations to determine whether users are allowed to visit cloud apps or external URLs based on applied secure access rules.
  • The Internet Access Cloud Gateway also controls HTTPS/HTTP traffic when users are accessing from outside your corporate locations, such as users connecting to public Wi-Fi networks or working from home.
The following table outlines the actions and information available in the Cloud Gateway section on the Gateways tab.
Action
Description
Add a corporate network location to the Internet Access Cloud Gateway
Click Add Corporate Location to specify one or more IP addresses from a known location.
View corporate network location details
View basic information about a corporate network location, such as:
  • IP address: The public IP addresses of your organization's internet gateways
  • IP verification: Whether all configured IP addresses for the corporate network location are verified
    • Verified: HTTPS/HTTP requests are transmitted to the Cloud Gateway from all configured IP addresses
    • Partially verified: HTTPS/HTTP requests are transmitted to the Cloud Gateway from some of the configured IP addresses
    • Pending: There is no HTTPS/HTTP request from a configured IP address transmitted to the Cloud Gateway
  • Time zone: The time zone of the corporate network location
  • User authentication: Users are always required to authenticate themselves when their HTTP/HTTPS requests are forwarded to the cloud gateway.
Manage corporate network locations
  • To change the basic information about a corporate network location, click edit-icon_001.png of the corresponding location.
  • To delete a corporate network location from the Internet Access Cloud Gateway, click trash-icon.png of the corresponding location.
The following table outlines the actions and information available in the On-Premises Gateways section on the Gateways tab.
Action
Description
Deploy an Internet Access On-Premises Gateway
Click Deploy New On-Premises Gateway and deploy an on-premises gateway in Service Gateway Management.
View Internet Access On-Premises Gateway details
View basic information about an on-premises gateway, such as:
  • Service Gateway: The host name or FQDN of the Service Gateway virtual appliance enabled with the Zero Trust Internet Access On-Premises Gateway service
  • Status: The status of the Zero Trust Internet Access On-Premises Gateway service on the corresponding Service Gateway virtual appliance
    • Healthy: The service communicates with Internet Access at an expected frequency over a certain period of time.
    • Unhealthy: The communication between the service and Internet Access has been interrupted for more than 15 minutes.
    • Disabled: The Zero Trust Internet Access On-Premises Gateway service is disabled or uninstalled, or the corresponding Service Gateway has been deleted from Service Gateway Management.
  • Service version: The version of the Zero Trust Internet Access On-Premises Gateway service
  • IP address: The public IP address of the corresponding Service Gateway virtual appliance
  • Port: The port number used by the corresponding Service Gateway virtual appliance
  • Time zone: The time zone of the corresponding Service Gateway virtual appliance
  • Enforce authentication: Whether user authentication is required when HTTP/HTTPS requests are forwarded to the On-Premises Gateway
    Important
    Important
    This is a pre-release sub-feature and is not part of the existing features of an official commercial or general release. Please review the Pre-release sub-feature disclaimer before using the sub-feature.
    • ON (default): User authentication is always required, whether HTTP/HTTPS requests are forwarded through client access or traffic forwarding.
    • Client Access only: User authentication is required only when HTTP/HTTPS requests are forwarded through client access.
    Users are always required to authenticate themselves when the traffic is forwarded via client access. Unlike client access, user authentication is configurable when the traffic is forwarded via traffic forwarding (using PAC files, proxy chaining, or port forwarding).
    Disable user authentication for traffic forwarding, for example, if you want the gateway to enforce internet access rules on devices that directly connect to the gateway and have no specific users.
  • Last communication: The most recent time when the Zero Trust Internet Access On-Premises Gateway service communicated with Internet Access
Manage Internet Access On-Premises Gateways
  • To change the basic information about an Internet Access On-Premises Gateway, click edit-icon_001.png of the corresponding gateway.
  • To disable an Internet Access On-Premises Gateway, toggle the Zero Trust Internet Access On-Premises Gateway service off on the associated Service Gateway virtual appliance in Service Gateway Management.
  • To view details about a Service Gateway virtual appliance enabled with the Zero Trust Internet Access On-Premises Gateway service, click onprem-details.jpg.
  • To update the Zero Trust Internet Access On-Premises Gateway service status to the latest version, click onprem-upgrade.jpg and update the service in Service Gateway Management.
Configure unusual status notifications
Send alerts when the status of Internet Access On-Premises Gateway changes to "Unhealthy", or when the on-premises gateway that serves as the authentication proxy for single sign-on is disconnected from your on-premises Active Directory server.
Click Configure Unusual Status Notifications, and then configure alert settings for Internet Access On-Premises Gateway status in the Notifications app.