All Apps and Add-ons

iOS Splunk MobileApp - what TCP port(s) (or other) need to be allowed through my VPN

MBenz123
Engager

Trying to get Splunk Mobile App to work via VPN on iPad. I have to open needed TCP/IP communications via VPN first. I haven't been able to find any related documentation.

0 Karma

rgantly_splunk
Splunk Employee
Splunk Employee

In the documentation we only described how to connect the the Splunk Mobile Server in the DMZ, so that the users don’t have to connect using VPN.

You do not need to configure any special settings to connect via VPN to the Mobile Access Server from the Splunk Mobile App. Install and configure the Splunk Mobile Access server as described in the docs.

If the mobile server runs on an internal IP address, for example, https://10.0.1.109, then:
1. Connect to your network with your VPN client.
2. When you are logged on your network, in the Splunk Mobile App host field, enter 10.0.1.109. You don't need to enter the port number if the default (443) was used during installation.

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

The app will connect via https TCP/443 to the mobile server. Then that server needs connectivity back to the splunk related servers. The server only uses read only REST calls, and you can define which port it uses for connectivity.

You can find the official documentation at:

Splunk Mobile Documentation

To secure the server from unwarranted attacks:

Configure the firewall to only allow inbound HTTPS connections. For example, if the mobile server runs on https://, then configure the firewall to only accept HTTPS request from the internet to access the mobile server on port 443 (the default port used by secure http).

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...