Configure server settings
Make a server available in the DMZ to serve as proxy server (Windows Server 2012 or higher). This does not need to be a member of the same domain as Cortado Server. Log in to the proxy server as administrator.
- Open the Cortado Management console. Select Control Panel→ Global Settings→ Proxy and then Configure (arrow in illus.).
- Select Outbound proxy server if you use a proxy server for outbound connections (left in illus.) (recommended for environments with high security levels).
- Select the type of proxy server and enter the server address.
- Depending on the type, you can additionally set a user name and password under Use authentication (left in illus.).
- Select Inbound proxy server, to register your Proxy-Server for incoming connections (right in illus.).
- Enter the server address of the proxy server incl. the port.
- Close the window with click on OK.
Note! The Cortado server generates a server certificate (SSL) and a client certificate for the proxy server. These are derived from the root certificate of the Cortado server. If you use your own root certificate, or one you have purchased, it must be imported beforehand (with its private key) into the certificate store of the Cortado server.If you want to use a server certificate (SSL) that was purchased from an official certification authority: Import the purchased server certificate (SSL) into the Cortado server certificate store, and also into the proxy server, in Certificates (Local Computer)→ Personal→ Certificates. You can find an overview of the distribution of root and server certificates in the section Distribution of certificates.
- Now click on Download proxy certificates, to download the .zip file with the certificates (root, server and client certificates).
Note! You use the .zip file, even if you want to use a purchased server certificate for the proxy server.
- Assign a password to secure the certificates. You will need to enter this password later in the proxy server.
- Save the .zip file. The certificates contained therein must later be imported into the proxy server. Copy the .zip file to a directory on the proxy server.
Note! The client certificate for the proxy server is valid for one year. Download a new one before the certificate expires. Proceed as described in our guide How to extend the client certificate of the proxy server . Then run the Configuration Assistant on the proxy server again. Upload the new client certificate there.