Forum Discussion
ARAIMBAULT
Sep 27, 2024Copper Contributor
AAD application proxy : access from external issue
Hello, I have published an application with SAML SSO. from internal, it works fine. When I connect to https://myapp, all is ok. I have set up an external Url : https://myapp.my_custom_external...
- Oct 01, 2024
Ok it works now
I ve got a fortigate, with webfilter or other security profile, it does not work, i had to open Internet services.Like this :
thanks for help.
ARAIMBAULT
Sep 30, 2024Copper Contributor
I cannot change custom domain to msappproxy.net domain, i have to create another application.
I will test.
Yes proxy agent is online.
ARAIMBAULT
Sep 30, 2024Copper Contributor
I have tested with an msappproxy.net domain.
I get error AADSTS50011 and if i update application registration, i get a timeout.
So, it's the same.
I get error AADSTS50011 and if i update application registration, i get a timeout.
So, it's the same.
- ARAIMBAULTOct 01, 2024Copper Contributor
Ok it works now
I ve got a fortigate, with webfilter or other security profile, it does not work, i had to open Internet services.Like this :
thanks for help.
- ARAIMBAULTSep 30, 2024Copper ContributorI have tested, it is a firewall issue.
Web filter issue to for precision.
I followed this page but it miss some websites : https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-configure-connectors
have you got the new prerequisites?
thanks. - ARAIMBAULTSep 30, 2024Copper Contributor
Sorry, i have recheck and i can see thios error.
- ARAIMBAULTSep 30, 2024Copper ContributorI have tested with DNS resolution for the external URL, timeout too.
There is no error message in agent log.
Seems that MS entra can't connect to agent, even when agent can connect to MS entra. - ARAIMBAULTSep 30, 2024Copper Contributor
HEllo,
My firewall has an IP, supposed 10.11.12.13. this is the connector external IP BUT port 443 is redirected to vpnssl webpage. Could it be an explanation? - JamesscarrSep 30, 2024Copper ContributorThat makes sense, seems like your app needs that external DNS name. It might be worth checking your internal DNS record to see what the target destination is. if it is different from what you set in Entra, it might be worth changing the one in Entra to match the on-prem one. It might be worth changing the timeout in the Entra ID app to long timeout.
Also, have you checked the event logs on your server hosting the agent?