Pairing Fudo Enterprise with Fudo Shareaccess¶
Note
There are few requirements that must be met before pairing Fudo Enterprise with Fudo ShareAccess can be finished:
A user with a role that has permissions to manage Fudo ShareAccess and an email identical to that of the Organization owner must exist in the Fudo Enterprise configuration.
NTP configuration is required. Please go to Settings > System configuration and set up NTP server or refer to Date and Time section.
DNS configuration is required. Please go to Settings > Network configuration and set up DNS or refer to DNS Configuration section.
To establish a tunnel between Fudo Enterprise and Fudo ShareAccess, outbound traffic on port 65522 must be allowed to any destination.
Note
To enable Fudo Enterprise communication with the Fudo ShareAccess platform, make sure the following outbound connections are allowed:
api.shareaccess.comon port443– required for API communication over HTTPS.
connect.shareaccess.comon port65522– required to establish a tunnel between Fudo ShareAccess and Fudo Enterprise.
acme-v02.api.letsencrypt.orgon port443- required for certificate issuance and renewal.
Log in to Fudo Enterprise instance Admin Panel.
Create user:
Select User Management > Users and then click Add user.
Enter user name.
Click Save.
In the Role tab, click Assign Role and select a role that has permissions to manage Fudo ShareAccess.
In the User Data tab, in the User info field enter:
user’s full name,
user’s email address (provide the same email address as for your Fudo ShareAccess account),
user’s organizational unit,
user’s phone number.
Click Save.
Go back to the Settings tab, and in the Authentication section select desired authentication type from the Add authentication method drop-down list. This will be used to authenticate user against Fudo Enterprise User Access Gateway.
Click Save and close.
Create an account in Fudo ShareAccess:
Go to the Fudo ShareAccess website.
Click Sign In.
Provide the same email address as the user created in Fudo Enterprise.
Provide password for created account.
Note
To create an account you have to agree to our Terms and Conditions and Privacy Policy.
Click Get started.
Please check your email for a confirmation message and follow the provided link to verify your account.
After verifying your email, log in using the email and password you provided during registration to proceed with account setup.
Open a third-party authenticator app, such as Google Authenticator or Authy, on your mobile device and scan the QR code displayed on the screen.
Enter the 6-digit code from the authenticator app.
Click Next.
Secure your backup codes displayed in the modal window. Use the Copy all button to copy the codes and save them in a secure location, or click Download to download the codes as a
.txtfile. Please note that these codes will not be displayed again.
Warning
If you lose your backup codes, you will no longer be able to access your account. In such cases, please contact Fudo Support immediately for assistance.
Click I have saved my backup codes to confirm the backup and complete the configuration process.
In the Fudo Enterprise Admin Panel, start the pairing setup:
Select Settings > Fudo ShareAccess.
In the drop-down list, select the Bind IP address. This address is used as the source address for connections to Fudo ShareAccess.
Verify that the NTP server status is OK. System time must be synchronized using NTP.
Verify that the firewall allows outbound connections to
api.shareaccess.comon port443by clicking Check connection.Verify that the firewall allows outbound connections to
acme-v02.api.letsencrypt.orgon port443by clicking Check connection.
Note
When all requirements are met and both outbound connections are verified, the pairing key fields will be displayed and you can continue with the pairing process.
Copy the Pairing Key from Fudo Enterprise:
Add Gateway in Fudo ShareAccess:
Select Connect Region. The Connect Node reviews your connections and routes them to this Gateway. Latency is measured from your current network to the Connect node. Sync could take up to 5 min.
Europe East – ~30 ms latency,
Asia Central – ~128 ms latency.
Click Refresh latency to update the measured latency values.
Log in to Fudo ShareAccess, expand the User Drop-down menu in the upper-right corner and select Manage organizations > Your Organization Name to access the organization settings.
In the left-hand menu, select Gateways.
Click Add Gateway.
Paste the Fudo Enterprise pairing key that was copied earlier in the manual.
Click Save Gateway.
Next, copy the Fudo Pairing Key displayed below.
Go back to Fudo Enterprise Admin Panel and paste the Fudo Pairing Key in the ShareAccess pairing key field.
Click Check user to verify that the user with Fudo ShareAccess privileges, created in the previous steps, exists and has permission to use Fudo ShareAccess.
Check if firewall allows outbound connection to
eu-ovh-connect.shareaccess.comon port65522by clicking Check connection.
Click Join to Fudo shareaccess.
Wait until the Fudo Enterprise instance displays information about the organization name, owner, status of the connection, license, and a list of users from Fudo ShareAccess.
Note
This process may take up to a minute. If the information does not appear, please contact support at support@shareaccess.com.
Go back to Fudo ShareAccess and click Finish.
After successful pairing, the Fudo Unique Identifier will be displayed on the Gateways list.
Troubleshooting the connection¶
If the connection between Fudo Enterprise and Fudo ShareAccess is not working as expected, you can diagnose and resolve the most common issues directly from the Fudo Enterprise Admin Panel, without contacting support.
Select Settings > Fudo ShareAccess.
In the upper-right corner, click Need Help?.
The Need Help? panel offers the following actions:
Restart Tunnels – restarts the SSH tunnel used to establish connections. This action does not affect the configuration or stored data and is recommended as the first troubleshooting step. Outbound firewall access to
eu-ovh-connect.shareaccess.commust be allowed. The panel displays the current tunnel status and a Go to Logs link. Click Restart tunnels to restart the tunnel.
Note
Any active sessions in Fudo ShareAccess will be immediately disconnected.
Sync with Fudo ShareAccess – restarts synchronization with Fudo ShareAccess. Outbound firewall access to
api.shareaccess.commust be allowed. The panel displays the synchronization status, the time of the next synchronization, and a Go to Logs link. Click Restart sync service to restart synchronization.TLS certificate – restarts TLS certificate generation and renewal. Outbound firewall access to
acme-v02.api.letsencrypt.orgmust be allowed. The panel displays the certificate status and its validity date. Click Restart TLS service to restart the service.Contact Fudo Support – if you need further assistance, click Open support portal to reach out to the support team.
Force Unpair – click the expand arrow to reveal the Unpair Fudo ShareAccess button. This action removes the entire configuration and requires you to set everything up again from scratch. Your license and account remain intact.
Warning
Use Force Unpair only as a last resort. It removes the complete pairing configuration between Fudo Enterprise and Fudo ShareAccess.
Related topics: