What is this?

This knowledgebase contains questions and answers about PRTG Network Monitor and network monitoring in general.

Learn more

PRTG Network Monitor

Intuitive to Use. Easy to manage.
More than 500,000 users rely on Paessler PRTG every day. Find out how you can reduce cost, increase QoS and ease planning, as well.

Free Download

Top Tags


View all Tags

Fix Security risk for public maps

Votes:

0


Want this feature implemented, too? Please upvote by clicking Thumbs up!

User story

Enhance Security for public maps (Fix Security risk for public maps)

Details of a user story

Most large organizations have some kind of NOC (display screens) for monitoring purposes. Within these NOCs they have PRTG MAPS displaying sensors and data for critical infrastructure. MAPS displayed within these NOCs (on a private corporate network) are set public access - Reason being we do not want to authenticate daily to view the map. Setting MAPS to public access results in a huge security risk if the organization also uses the PRTG mobile app.

In order to use the mobile app, one needs to open port 443 on the corporate firewall. Opening port 443 to your PRTG server exposes all your "public access" maps directly onto the internet for the whole world to see. Yes, the public URL makes use of a secret key which is difficult to guess, but the problem remains that the map can be accessed from the internet without authentication (if the URL is known).

My request is simple (yet difficult to achieve - I know).

Acceptance criteria

Option1: Please assign two different port numbers for Web services (eg 443) and another port number to the mobile app (eg 444). This way we can allow 444 through the corporate firewall and block 443 (web services) which will protect our public maps from being accessible on the internet.

Option2: Assign a custom port number to public maps.

Status

Open

firewall port security

Created on Jan 30, 2023 7:37:56 AM

Last change on Feb 2, 2023 8:39:04 AM by  Himanshu Bhatt [Paessler Support]



Replies

Nobody has replied yet


Disclaimer: The information in the Paessler Knowledge Base comes without warranty of any kind. Use at your own risk. Before applying any instructions please exercise proper system administrator housekeeping. You must make sure that a proper backup of all your data is available.