<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008G7Uy7SAFOkta Classic EngineAdministrationAnswered2024-03-25T21:58:51.000Z2017-11-18T12:26:22.000Z2017-11-18T12:26:22.000Z
internal okta ad agent
I want to install the okta AD agent on a non DMZ machien and just open up the needed ports to have the agent connected. When testing the AD agent on our DMZ, it worked fine, when installed on an internal server, it errors out almost instantly, because of not being able to reach OKTA, I presume? 

 

What are the needed ports that need to be opened and to what address? I don't want to open the ports the whole internet.

  • Hi Ben, 

     

    In order for the AD agent to connect to Okta you will need to open port 443 for outbound traffic. This allows the agent to poll our services and then perform actions such as delegated authentication, imports and real time syncs. 

    If you wish to configure this to, only, the okta services then please review our list of IP's found here: 

     

    Okta Firewall Whitelisting:- https://support.okta.com/help/Documentation/Knowledge_Article/Configuring-Firewall-Whitelisting-89944588

     

    Hope this information is helpful, if you still encounter issues with connecting the agent to Okta I would recommned opening a support ticket so we can provide more in depth troubleshooting. 

     

    Thanks,
    Expand Post
This question is closed.
Loading
internal okta ad agent