Managing a Legacy Corente Client Account

Note

From this release, you cannot add new accounts for legacy versions of the Corente Client. However, you can still edit legacy Corente Client accounts.

Legacy Corente Client accounts are managed using the Client Administration category in the domain directory. When you open the Clients subcategory, the domain directory lists each Client account you have configured. When you open a Client account, all the Client Groups of which it is a member will be displayed. For more information about Client Groups, see Add a Client Group.

When you select Clients, all Corente Client accounts that have been configured in this domain will be displayed in a table to the right of the domain directory. This table displays:

  • Client: the Client account name

  • Version: the version of the software that the user has downloaded

  • Target: the target software version that has been set for the user by the SCP Operator

  • Created: the date that the Client account was created

  • Expires (Days): number of days until the Client account expires. A value of Never indicates that No Expiration has been set for the Client account.

  • First Contact: the first time the account contacted the SCP for activation

  • Last Contact: the last time that the account connected and contacted the SCP

  • Visible IP: the Visible IP address of the Corente Client

You can view the current status of each Corente Client at a glance in either the domain directory or the Clients table, by viewing the Corente Client's icon.

Icon Status Meaning

Download icon

Download

This account has been added by an administrator, but has not yet downloaded the Corente Client personality file.

Downloaded icon

Downloaded

The Corente Client personality file has been downloaded, but the computer has not yet established a secure tunnel to the SCP.

Active icon

Active

The computer has established a secure tunnel to the SCP and is currently active on the Corente Services network.

Disconnected icon

Disconnected

The computer has established a secure tunnel to the SCP at least once, but does not currently have a SCP connection. The Corente Client may not be in use.

Upgrade Pending icon

Upgrade Pending

When a purple triangle appears on the icon, the Corente Client is scheduled for a software upgrade.

You can Edit or Delete any existing Corente Client account. Once saved with the Save button in the App Net Manager tool bar, any changes made to an existing Corente Client will be distributed automatically and immediately if that Corente Client is currently connected. If the Corente Client is currently disconnected, the changes will be applied the next time the Corente Client contacts the SCP. If you delete a Corente Client currently in use, that Corente Clients session will be terminated.

To edit a legacy Corente Client account, right-click on the Client name in the domain directory.

The following settings are available:

  • Name: Enter the alphanumeric identifier for the Corente Client account. You may use up to 50 alphanumeric characters. Hyphens and underscores are allowed, but do not use tabs, spaces, or punctuation marks when creating this name. This name must be unique from any Location names in your domain.

  • Email: Enter the email address of the Corente Client user. The user will receive an email message shortly after you complete this screen, notifying them that you have set up this account. The email will also contain the URL where the user can obtain the Corente Client Software. If you have already downloaded the software, make sure you notify the user so that the user can obtain the software package from you rather than by using this hyperlink.

  • Password: Create an alphanumeric password for this Corente Client account. This password must contain at least one uppercase, one lowercase, and one numeric character. This password will not be sent in the automatic email message; for security purposes, you must supply the password to the user yourself. You should remind the user to change this password as soon as possible in order to maintain security for your domain.

  • Confirm Password: Re-enter the password you created in the Password field to avoid any mistakes.

  • Notes: If you would like to add additional information to keep track of this Client account, enter your notes here. You can enter up to 250 characters.

  • Access Settings: The options in the Access Settings section allow you to select how this client account will use the Corente Client to connect to your Corente Services network.

    • Allow access to local Network: Select this option if you would like to allow the Corente Client to contact and be contacted by machines on its own LAN while it is connected to its Location partner. You should not select this option if this machine will be accessible by untrusted devices. When this option is not selected, while the software is in use, the Corente Client will only be able to contact and be contacted by machines via the Location partner. This option will be unselected by default.

    • Backhaul All Traffic: Select this option if you would like all traffic (both traffic destined for the Location partner and traffic destined for other places, such as the Internet) to travel inside the secure tunnel and be routed to the Location partner. The Location partner receives all of the traffic and then routes it appropriately. By default, this option will be selected. When this option is not selected, no traffic will be backhauled. This means that the Corente Client:

      • Is unable to use any WINS or DNS servers whose addresses have been served to it by a DHCP server over the domain (either by the Location gateway’s DHCP server or by an external DHCP server).

      • Is able to access only the computers on the LAN of the Location to which it is connected.

      • Is unable to access the partners of its Location partner. The partners and computers behind those partners will be visible to the Corente Client user in Gateway Viewer, but will be inaccessible.

  • Authentication Type: This section enables you to select the method that this Corente Client will use to authenticate to its Location partners. In addition to all of these methods, all Corente Clients are authenticated with digital certificates.

    • Password: Select this option and this Corente Client will authenticate with the user name and password that you supply on this screen. The password can be changed later by the user.

    • External: Select this option and this Corente Client will authenticate to its Location partner with either RADIUS or LDAP, depending on the type of external authentication that has been enabled on the Location gateway (see Configuring External Authentication). The user must supply the user name and password that you have entered on this screen to obtain the personality file for this client, but must use the user name and password for the RADIUS/LDAP server to connect to the client's Location partner.

      Note

      If no External Authentication server has been enabled on the Location gateway, the Corente Client will be unable to connect to the Location when its Authentication Type is External.

    • No Authentication: Select this option and this Corente Client will not be required to authenticate with any other method but digital certificates. The user must supply the user name and password that you have entered on this screen to obtain the personality file for this client, but a user name and password will not be required when starting the software.

  • Client Expiration: If you would like to create a temporary Client account for a user, you can use the Client Expiration feature to specify the length of time (in days) that the Client will be permitted to connect to its partners. When the subscription period has ended, the Client will immediately be disconnected by the SCP when the user attempts to start up the Client software and connect to partners. An expired Client account will remain listed in App Net Manager so that you are able to modify the Client Expiration settings and renew the Client subscription, easily rendering the Client account usable again.

    • No Expiration: When this option is selected, the subscription for this Client will not expire. The Client will be permitted to connect to its partners until you delete this Client account or change the Client Expiration settings. By default, this option will be selected.

    • Expires In: When this option is selected, the Client subscription will endure for the time period that is specified in the adjacent field. When the end of the time period approaches, the Client user will be notified of the impending expiration during initial Client startup. (The user can also view the length of time until client expiration at any time by placing their cursor over the Client system tray icon to view the 'tool tip'.) When the time period has ended, this Client will no longer be permitted to connect to its assigned partners until you change the Client Expiration settings. The default time period is 30 days.

    • Expired: When this option is selected, the subscription for this Client has expired. The Client will not be permitted to connect to its assigned partners unless you renew the subscription by selecting either the No Expiration or Expires In option and save your changes.

  • Client Group Assignments: Corente Clients are combined into groups to make partner administration easier. Client Groups are created using the Client Groups feature, as described in Add a Client Group.

    To include a Corente Client in a group, select the checkbox beside the group name. You may add a Corente Client to as many groups as you would like. A Client Group may contain up to 100 Corente Clients.

    If a Corente Client is member of multiple groups or partnered with multiple Location partners, when the user signs onto the service, they are asked to select a Location for that session. Corente Clients can connect to only one Location at a time.

    Note

    Corente Clients cannot be partnered with each other. Additionally, Corente Clients can only partner with Locations that are reachable on TCP or UDP port 551. This means that a client cannot connect to any Location behind firewall or proxy server unless that device has been modified appropriately.