How do I configure an existing agent to negotiate a firewall?
If you do not specify that the monitored host is behind a firewall when you install the agent, it defaults to use the CALL.AGAIN architecture. There are two ways you can set it up to negotiate a firewall, as follows:
CALL.TUNNEL - Only one fixed port is used, and it must be open in both directions. This is the default if you specify that there is a firewall during agent installation, and is the recommended setting if you have a firewall.
CALL.BACK - Two fixed ports are used, and both must be open in both directions.
If you don't yet have the agent installed, specify that it is protected by a firewall during the installation and it will use CALL.TUNNEL.
Otherwise, you can change this setting in Quest Agent Manager Configuration. To do this, open in your browser:
http://<servername>:<port>/ where <servername> is your monitored host and <port> is the QAM port (usually 3566).
1) When prompted, login as user "quest" with password "quest" (default QAM user)
2) Click on "Quest Agent Manager Configuration".
3) Click on "Click here for the Global Configuration".
4) Change the SERVER.ARCH parameter to CALL.TUNNEL or CALL.BACK.
- With CALL.TUNNEL, the "PORTS" field must be blank.
- With CALL.BACK, you must specify the second port to use in the "PORTS" field. (e.g., 3567)
5) Click on "Save Changes" button.