Gatekeepers
Gatekeepers help customers control vendor access to customer assets. Customers use Gatekeepers to configure available applications, manage access, and set schedules for remote connections. To provide support, vendors connect to a customer's Gatekeeper instead of connecting directly to customer infrastructure.
Gatekeepers include built-in services that support common remote support tasks. Customers can also host custom applications on a Gatekeeper.
Gatekeepers are always associated with a customer. System Administrators and permitted Internal Users cannot create a Gatekeeper until the customer exists. To create a customer, see Customer Management.
Requirements
To create and install Gatekeepers, you must meet the following requirements:
System Administrators can view and manage all Gatekeepers.
Before you add a Gatekeeper, create the customer that will be associated with it. The first Gatekeeper is created as part of the New Customer workflow.
Internal Users can perform Gatekeeper tasks only when their assigned role includes the permissions required for those tasks. Gatekeeper-related permissions include:
-
CREATE_GK -
DELETE_GK -
EDIT_GK -
ENABLE_GK_ACCESS -
VIEW_GK -
CONNECT
The actions available in the user interface depend on the Internal User's assigned permissions.
Customers cannot create Gatekeepers. A customer's vendor (A CPAM System Administrator or Permitted User) must create and share the Gatekeeper before the customer can install and register it.
Request your vendor to assign at least one Gatekeeper Admin user in your organization. Other Gatekeeper user roles cannot add, edit, disable, or delete Gatekeeper users.
Manage Gatekeepers as a System Administrator or Permitted Internal User
System Administrators can perform all the procedures in this section. Internal Users can perform only the procedures allowed by their assigned permissions.
On the Customers menu, click Gatekeepers List to open the Gatekeeper list.
Use the Gatekeeper list to complete the following tasks:
-
View Gatekeepers.
-
Search for Gatekeepers by customer name or Gatekeeper name.
-
Filter Gatekeepers by access status.
-
View customer and Gatekeeper details.
-
View session status and access status.
The Gatekeeper list includes the following columns:
|
Column |
Description |
|---|---|
|
Gatekeeper |
Shows Gatekeeper details. |
|
Customer |
Shows the customer associated with the Gatekeeper. A customer can appear more than once when the customer has more than one Gatekeeper. For more information about customers, see Customer Management. |
|
Status |
Shows the Gatekeeper session status:
|
|
Connect |
Starts a connection to the Gatekeeper. For more information, see Sessions. |
When access is Disabled, you can click Connect to open the Gatekeeper contact information. Use this information to contact someone at the Gatekeeper site and ask them to enable access.
Gatekeepers are created when you create a customer. The New Customer form prompts you to add the first Gatekeeper for the customer.
To add another Gatekeeper to an existing customer:
-
On the Customers menu, click Customers List.
-
Click the customer name.
The customer details page opens.
-
In the Gatekeepers section, click Add.
The New Gatekeeper form opens.
-
Complete the form.
-
Click Save.
The Gatekeeper appears in the Gatekeepers section.
The New Gatekeeper form includes the following fields:
|
Section |
Field or option |
Description |
Required |
|---|---|---|---|
|
Gatekeeper information |
Gatekeeper name |
Specifies the Gatekeeper name. |
Yes |
|
Gatekeeper group |
Assigns the Gatekeeper to a Gatekeeper group. |
Yes |
|
|
Gatekeeper description |
Specifies the Gatekeeper description. |
No |
|
|
Department |
Adds the Gatekeeper to a department. If the customer is already part of a department, this option must match the customer's department. |
No |
|
|
Selects the distribution of the customer's Gatekeeper. |
Yes |
||
|
Host this Gatekeeper on an existing Gateway |
Adds the customer's Gatekeeper to an existing Gateway. |
No |
|
|
Gatekeeper admin user |
Create Gatekeeper Admin User |
Creates a customer-side administrator user for access management and history access options. |
No, but recommended |
You can open Gatekeeper details from the Gatekeeper list or the Customer Details page.
To view a Gatekeeper from the Gatekeeper list:
-
On the Customers menu, click Gatekeepers List.
-
Locate the Gatekeeper.
Use search to find the Gatekeeper by customer name or Gatekeeper name.
-
Click the Gatekeeper name.
The Gatekeeper details page opens.
To view a Gatekeeper from the customer details page:
-
On the Customers menu, click Customers List.
-
Click the customer name.
-
In the Gatekeepers section, click the Gatekeeper name.
The Gatekeeper details page opens.
The Gatekeeper details page includes the following tabs:
Gatekeeper Details displays Gatekeeper configuration, registration, status, access, host, notification, and note information.
|
Section |
Description |
|---|---|
|
Gatekeeper Information |
Displays the Gatekeeper name, status, description, Gatekeeper group, department, primary contact, contact phone number, and contact email address. |
|
Registration Information |
Displays the Gatekeeper registration code and the Reset Code action. |
|
Gatekeeper Stats |
Displays Gatekeeper system details, including release, Java release, available JVM memory, local host name, platform profile, tunnel method, date last connected, available disk space, and local IP address. |
|
Pre-Connection Notification |
Displays notifications that users see before they connect to the Gatekeeper. You can add a pre-connection notification from this section. |
|
Notes |
Displays notes associated with the Gatekeeper. |
|
Access |
Displays the Gatekeeper access expiration setting. |
|
Hosts |
Displays the total number of hosts and provides the Add action. |
Gatekeeper users are CPAM accounts that customers can use to view access history, manage access permissions, set access schedules, and receive connection notifications.
The following roles are available for Gatekeeper users:
|
Role |
Description |
|---|---|
|
Admin |
Gatekeeper Admin users can set access schedules, view audit reports, add credentials, and create other Gatekeeper users. They are also responsible for installing and registering the Gatekeeper. |
|
Read Only |
Read-only users can log in to view history and toggle Gatekeeper access. They cannot create other Gatekeeper users or modify permissions. |
|
Email Only |
Email Only users receive connection notifications only. |
To add a Gatekeeper user:
-
Open the Gatekeeper details page.
-
Click Add Gatekeeper User.
-
Complete the user information.
New users receive an email with account activation instructions.
To modify a Gatekeeper user, go to the Users section on the Gatekeeper details page and click Edit. From the Edit Gatekeeper User page, you can modify the user's name, phone numbers, role, and access. You can also disable and delete the Gatekeeper user.
A Gatekeeper user can have access to several Gatekeepers when the Gatekeepers are associated with the same customer.
Always set a Gatekeeper Admin user. Other user roles cannot add, edit, disable, or delete Gatekeeper users.
You can use the Gatekeeper details page to edit, delete, or move Gatekeepers.
Edit Gatekeeper Settings
To edit Gatekeeper settings:
-
Open the Gatekeeper details page.
-
Click Edit.
-
Modify the Gatekeeper name, description, department, contact information, pre-connection message, Gatekeeper group, or default credential pool.
-
Click Save.
Delete a Gatekeeper
To delete a Gatekeeper:
-
Open the Gatekeeper edit page.
-
Click Delete Gatekeeper.
A confirmation pop-up specific to your browser opens.
Move a Gatekeeper
You can move one Gatekeeper or all Gatekeepers from one customer to another customer.
To move one Gatekeeper:
-
Open the source customer.
-
Open the Gatekeeper edit page.
-
Click Move Gatekeeper.
-
Choose a destination customer.
-
Review the page that shows the number of Gatekeepers and the source and destination customers.
-
Click Move.
-
Click Confirm.
The View All Customers page opens.
To Move All Gatekeepers:
-
Open the source customer.
-
Click Move Gatekeepers.
-
Choose a destination customer.
-
Review the page that shows the number of Gatekeepers and the source and destination customers.
-
Click Move.
-
Click Confirm.
The View All Customers page opens.
CPAM Gatekeepers have built-in services and customizable services that vendors can use to provide support for their customers. Gatekeeper services are features and applications hosted directly on the Gatekeeper. These services grant vendors granular access to customer assets and help customers monitor and log activity within those services.
To view services for a Gatekeeper:
-
Open the Gatekeeper details page.
-
Click Edit Services.
The Linux Gatekeeper Desktop Sharing service (rssDS2) operates on port 5918 and must be manually enabled with a script. The service requires an X11 display environment. The script is available in the following locations of the Gatekeeper installation folder:
-
RHEL-based distributions (CentOS/AlmaLinux):
sudo scripts/setup-display-rss.sh --with-epel -
Ubuntu distributions:
sudo scripts/setup-display-rss.sh
All CPAM Gatekeepers have the following built-in services:
Every Gatekeeper connection made by a vendor to a customer's server is monitored by the CPAM server. Monitoring enables customers to view and audit vendor activity in their assets and Gatekeeper-hosted applications.
For information about creating a session and the session types available with your CPAM license, see Sessions.
For information about session history generated by your CPAM server, see History.
Use a Gatekeeper as a Customer
As a Customer, you can install and register a Gatekeeper after your vendor creates and shares it with you. You cannot create a Gatekeeper yourself.
Gatekeeper users can manage access your assets without providing direct access to other parts of your infrastructure. Depending on their assigned role, they can:
-
Install and register the Gatekeeper.
-
Enable or disable Gatekeeper access.
-
Set access schedules.
-
Configure available applications and credentials.
-
View access history and audit reports.
-
Receive connection notifications.
A Gatekeeper Admin user is responsible for installing and registering the shared Gatekeeper. Use the registration information supplied with the Gatekeeper to connect it to the server.
If the Gatekeeper list shows Not Registered, the registration code has not yet been entered on the Gatekeeper in the customer network.
Gatekeeper Admin users can set access schedules. Read Only users can view history and toggle Gatekeeper access, but they cannot modify permissions or manage other Gatekeeper users.
Every Gatekeeper connection to the customer's server is monitored. Customers can use this history to view and audit activity in their assets and Gatekeeper-hosted applications.
For information about session history generated by the server, see History.