Remote Access Gateway

Documentation

Everything below assumes a profile bundle already issued to you. The gateway does not hand out access on its own and has no self-service enrolment.

Getting a profile

Profiles are generated per device by the administrator and delivered out of band. A bundle contains the client configuration, the device certificate and a short-lived enrolment token. The token expires 24 hours after issue.

Installing the bundle

  1. Unpack the bundle into the client configuration directory.
  2. Import the device certificate into the system keychain, not the browser store.
  3. Start the client once while on a trusted network to complete enrolment.
  4. Verify the session indicator turns green before opening a desktop.

Troubleshooting

SymptomLikely causeAction
Handshake fails immediately Client build older than 4.2 Upgrade the client, then re-enrol
Profile rejected Clock skew above 60 s Sync time via NTP and retry
Session drops after 30 min Idle reclaim Expected behaviour, reconnect
Both devices lose access Profile copied to a second machine Request a new bundle per device
Print jobs stuck Print relay degraded Queue drains hourly, no action

Limits

Note: the gateway logs connection metadata only. Session contents are recorded solely for desktop sessions and only when the recorder is enabled for your profile.