<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Common Okta Access Gateway Questions During Initial Deployment

Access Gateway
All Engines
Okta Classic Engine
Okta Identity Engine

Overview

Administrators often have questions regarding Domain Name System (DNS) resolution, cookie domains, hostnames, and Secure Shell (SSH) access during the initial deployment of Okta Access Gateway (OAG). Review the frequently asked questions and answers to understand the configuration requirements and resolve common deployment issues.

Applies To

  • Okta Classic Engine
  • Okta Identity Engine (OIE)
  • Okta Access Gateway (OAG)
  • Initial Setup

Solution

Why does the admin need to resolve to the admin or standalone node server IP address?

This resolution serves as the main configuration for the Admin Console application.

 

How is the cookie domain and hostname configured during setup?

Review the following image showing the setup screen with the Single Sign-On (SSO) Cookie Domain and Access Gateway Hostname fields.

  • SSO Cookie Domain: Enter the domain of the Okta Access Gateway hostname.
  • Access Gateway Hostname: Enter the cluster name. Okta Access Gateway appends admin to the hostname to create the URL used to access the Admin Console.

Identify the SSO Cookie Domain and Access Gateway Hostname fields in the setup wizard interface.

Setup Wizard

Verify the setup completion and observe the redirected URL when navigating to https://admin.

Setup Complete

 

Is it necessary to access the Admin Console by ensuring the admin resolves to the IP address?

Yes, Okta Access Gateway serves applications using the host header attribute. Okta Access Gateway receives access requests on a single IP address over port 443 (HTTPS), and the host header attribute distinguishes the applications.

Test the host header requirement by executing the following curl commands to observe the difference in server response.

  • Execute the following command to observe a 400 error because the host header is undefined, causing the server to send the requested IP address:
    curl -v -k https://<ip address of server>
  • Execute the following command to observe a 302 redirect to the Admin application:
    curl -v -k https://<ip address of server> -H 'Host:admin'

 

Why does a permission denied error occur when accessing the SSH management console with default credentials?

For new installations of Okta Access Gateway versions 2025.3.0 and later, Okta Access Gateway restricts Secure Shell (SSH) management console and Admin Console access to private networks. Administrators cannot access these interfaces using the public IP address of the appliance. Attach a private interface to the appliance if one is absent. Use a jump box to connect using a private IP address when operating outside the local network.

 

Related References

Loading
Common Okta Access Gateway Questions During Initial Deployment | Okta Support