Okta Access Gateway Fails to Connect when Using iPrism Webtool
Last Updated:
Overview
When using the iPrism Webtool proxy, connections fail without errors.
Applies To
- Okta Access Gateway (OAG)
- iPrism
Cause
The Access Gateway TCP connection on port 443 can be blocked by the proxy.
Solution
Add an IP exception in iPrism Webtool:
- Go to Users & Networks > Exceptions > Add.
- Exception Type: No Filter.
- Source IP start and Source IP end: This is the range of the Okta Access Gateway (OAG) nodes.
- Destination IP start and Destination IP end: yum.oag.okta.com, Okta IDP, and admin/worker nodes as ha key is synced over https.
- Specific Ports: 443, and check the TCP and UDP boxes.
