Skip to main content

Allow External Devices to Connect to the FileWave Server and Boosters

Use this procedure when devices outside your organization's network need to reach your FileWave Server or selected Boosters. Coordinate public DNS and firewall changes with the network administrator. If FileWave hosts your Server, use the supplied Server address and contact FileWave Technical Support for hosted Server connectivity issues; configure only the Boosters and network rules your organization manages.

If you have multiple Boosters, not all have to be opened up externally. We recommend roughly one Booster for around every 2000 Clients. If you'd like to create additional Boosters and keep your existing Boosters internal, you can find information about setting up a new Booster here: Booster installation

DNS Settings

In order for devices to connect on an external network, the FileWave Server and Boosters will first need to be set up with a Fully Qualified Domain Name (FQDN) that can be resolved outside the network.

Names that resolve only on your private network, such as internal .local or .corp names, will not resolve through public DNS. Private IP addresses are not directly reachable over the public Internet. Use a publicly resolvable FQDN for this workflow. Do not simply rename an existing FileWave Server: a hostname change can break Client and MDM communication and may require MDM re-enrollment. Plan the change using Root Trusted Certificate.

You can confirm your internal DNS settings by running the following commands on a computer inside your network.

Replace 'myserver.domain' with your Server/Booster FQDN.

This will use your devices current DNS settings

nslookup myserver.domain

Then run the command doing an external lookup (on a device outside of the network).

nslookup myserver.domain 8.8.8.8

If nslookup doesn't resolve to the correct IP (or not at all), you will need to make DNS changes...best to contact your Network Administrator to get this set up.

Inside, then an Outside Example:

$ nslookup server.filewave.com
Server:		192.168.1.1
Address:	192.168.1.1#53

Non-authoritative answer:
Name:	preview.filewave.com
Address: 10.1.10.45

$ nslookup server.filewave.com 8.8.8.8
Server:		8.8.8.8
Address:	8.8.8.8#53

Non-authoritative answer:
Name:	preview.filewave.com
Address: 52.38.32.242

In this example, the same Server name returns the private address 10.1.10.45 internally and the public address 52.38.32.242 through the external resolver. These illustrate separate internal and external DNS answers; use your own expected addresses. Correct DNS resolution alone does not prove that the firewall permits FileWave traffic.

Network Ports

Once DNS is correct, have the network administrator configure the required firewall rules. Review FileWave Server Ports as well as FileWave Booster Ports. Match each rule to its source, destination, protocol, and traffic direction; a Booster-only rule set does not cover every Server or MDM connection. Allow only the services needed for your deployment, not every port in the reference.

Testing the Network for External Communication

Once the changes are in place on the network, you will want to test the connection to be sure devices can communicate with the server. 

First, download our Port Tester on a computer connected to an external network. You can find the Port Tester here: https://supportresources.filewave.com. 

Once it's installed, input the Server/Booster's FQDN in the Hostname field. You can toggle the switch next to the port numbers to autofill the ports for the Server or Booster or input them yourself. 

Select Go and investigate failures for the required connections. Successful test results confirm only the connections tested, not the complete management workflow. After applying any Client preference changes below, confirm that a managed test device on the external network checks in, reports inventory, and downloads its intended Fileset. If ports are reachable but FileWave still fails, follow Network Proxy, Content Filter, and SSL Inspection Troubleshooting with the network administrator.

Connecting your Clients to the External Boosters

If you don't already have your Clients pointing to the Boosters you selected to make available outside the network, you will need to create a Superprefs Fileset to deploy these changes.

You can learn more about creating and deploying Superprefs here: Creating a Superprefs Fileset