# Getting Started

The Getting Started section introduces GoodAccess as a product and takes you through the necessary steps to get started.

{% content-ref url="/pages/fi04p4gmp16p3igTnhEd" %}
[1. What is GoodAccess?](/getting-started/1.-what-is-goodaccess)
{% endcontent-ref %}

{% content-ref url="/pages/UaYz97bWLCisON83YAzf" %}
[2. Architecture Overview](/getting-started/2.-architecture-overview)
{% endcontent-ref %}

{% content-ref url="/pages/SI7xsUAVHigpQYtSTqFg" %}
[3. Sign up for Free Trial](/getting-started/3.-sign-up-for-free-trial)
{% endcontent-ref %}

{% content-ref url="/pages/ICYOJKtc5t9JcLYlO2zZ" %}
[4. Download App & Connect](/getting-started/4.-download-app-and-connect)
{% endcontent-ref %}


# 1. What is GoodAccess?

Discover what GoodAccess is, how it works, and what makes it unique. Learn about its features, benefits, and why it's a top choice for secure remote access.

GoodAccess is a cybersecurity platform (SASE/SSE) that empowers enterprises to easily implement Zero Trust Architecture (ZTA) in their infrastructure, regardless of its complexity or scale.

By leveraging a low‑code/no‑code approach, GoodAccess delivers a hardware-free, rapid deployment solution within hours or days, allowing companies to enhance their security without the need for in‑house IT experts.

Our platform ensures seamless integration with modern SaaS/cloud applications as well as legacy systems, protecting critical assets for remote and hybrid workforces. GoodAccess serves businesses across diverse industries, particularly those adopting multi-cloud and SaaS environments.

## What does GoodAccess do?

GoodAccess protects the customer’s infrastructure under one zero-trust umbrella, regardless of how complex, heterogeneous, or widespread it is. It is a good fit for companies supporting full‑remote or hybrid modes of work using both company‑issued and employees’ own devices. The low‑code/no‑code, cloud‑based SASE platform allows businesses to create and manage zero trust architecture easily.

In today’s cybersecurity landscape, this is an essential part of any organization’s security, and a highly effective enabler of regulatory compliance.

The GoodAccess platform combines several latest technologies to tackle the most pressing cybersecurity challenges of today.

* **Remote access and BYOD** - Device security enforcement with device inventory and posture checks.
* **Multi-factor authentication (MFA)** - Unified MFA solution for all critical systems, including legacy applications.
* **Identity-based access control (IAM/FWaaS)** - Zero‑Trust Architecture enabling control of all access by identity (SSO/SCIM).
* **Network encryption and segmentation** - Segmentation at maximum granularity radically reduces the attack surface.
* **Full control and visibility** - Security logs and reports from across the entire organization with SIEM integration.

## What makes GoodAccess unique?

GoodAccess stands out by its usability‑first design. It is an all‑SaaS, zero‑hardware platform that fits any infrastructure to deliver network‑based Zero‑Trust Architecture (SDP) without the need for an IT expert on staff.

Our key uniquenesses include:

* **Simplicity** - Low-code/no-code/no-hardware platform for organizations of all sizes.
* **Market-leading deployment time** - GoodAccess only takes hours or days to deploy.
* **Infrastructure-agnostic** - Deployable over any existing infrastructure.
* **Easy management** - No certified IT experts needed.
* **Zero Trust on network layer** - Allows for simple integration of legacy applications.
* **Based in the EU** - Ideal cybersecurity provider for NIS2 compliance.


# 2. Architecture Overview

The architecture overview outlines the GoodAccess product, its operation, and related entities.

GoodAccess provides you with a Zero Trust Network Access (ZTNA) platform that allows you to create a secure Software-Defined Perimeter (SDP) around your enterprise systems (servers, applications, resources, networks) that can run anywhere (cloud, on-premises, public internet), and provides you with a simple way to control and monitor the secure access of your team members (employees) to your company systems.

Simply put, GoodAccess securely connects your remote team Members with your corporate Systems while providing additional security features (Secure Shield) to cover the whole security landscape of your company.

## Team

A Team (i.e. Secure Perimeter) is a top-level entity that is managed by the Admin from the Control Panel. It comprises all company assets that must be covered by the secure SDP, including:

* Members
* Gateways
* Systems
* Configuration

## Member

A Member is a member of the company team, usually management, an employee, a colleague. The Member receives secure access to enterprise Systems specified by the Admin.

## Admin

The Admin is a member of the company, usually CEO, CTO, CISO, IT Admin. The Admin's goal is to manage and monitor the company SDP using GoodAccess' intuitive ZTNA controls.

## Gateway

The Gateway is a cloud-based server dedicated only to one team or company and serves as an entrance into the company's secure SDP where all the company's Systems are running. The Gateway's primary tasks include:&#x20;

* Member authentication and authorization (firewall-based Zero Trust Network Access Control)
* Monitoring and surveillance
* Secure Shield - Threat Blocker, Anomaly Detection,  Security Policies, etc. &#x20;

## Client Application

The Client Application (i.e. Agent) is an application running on a Member's device that allows them to access Systems (servers, applications, resources) within the company's secure SDP via the Gateway.&#x20;

## System

The System is any network entity that is accessible by a Member of the company's Team. Systems are defined by the protocol (TCP / UDP), IP address, and port, and can run in the cloud, on premises, or elsewhere on the public Internet. &#x20;

## Cloud/Branch Connector

The Cloud/Branch Connector allows the Admin to connect a private network (cloud or on premises) to the GoodAccess Gateway using the IKEv2 or IPsec protocol. This allows the Admin to define Systems from the connected subnet to allow secure remote access to these Systems for other Members. &#x20;


# 3. Sign up for Free Trial

Sign up for a 14-day Free Trial and all the features of GoodAccess.

We believe in a "play & learn" approach, which is why GoodAccess offers you a 14-day free trial that allows you to **try all of GoodAccess' features** to get a full picture of what the GoodAccess ZTNA platform is all about before subscribing to a paid plan. No credit card is required for the trial.

At the end of the free trial period, you can choose a plan that fits you best. Your configuration from the trial will carry over if your plan will support it.

## Get started by signing up for a Free Trial:

{% embed url="<https://app.goodaccess.com/free-trial/>" %}
GoodAccess Free Trial Sign Up
{% endembed %}

{% hint style="info" %}
Please see our [pricing](https://www.goodaccess.com/pricing) for more information on available plans.
{% endhint %}


# 4. Download App & Connect

Now let's download the GoodAccess Client Application (the Agent) and test the connection to your dedicated GoodAccess Gateway.

The GoodAccess Client Application (i.e. Agent) enables access to Systems (servers, applications, resources) running within your secure Software-Defined Perimeter (SDP).&#x20;

The Agent is essentially a connector to your GoodAccess dedicated Gateway. You received a Gateway in the [previous step](/getting-started/3.-sign-up-for-free-trial) by signing up for the free trial.

## Download & Install

{% hint style="info" %}
**Supported operating systems:**

* Windows [versions officially supported by the vendor](https://endoflife.date/windows)
* macOS 14.6+
* iOS 18.6+
* Android 10+
* ChromeOS
* Linux
  {% endhint %}

Download and install the [GoodAccess Client Application](https://www.goodaccess.com/download).

{% embed url="<https://www.goodaccess.com/download>" %}
GoodAccess Download page
{% endembed %}

## Login

The Client Application (the Agent) supports two kinds of authentication:

* GoodAccess identity
* Third-party identity provider's SSO (Google Workspace, Okta, Azure AD, and more)

### GoodAccess Identity

Logging in with the GoodAccess identity requires entering your **GoodAccess Login Credentials:**

* Team Name
* Username
* Password

{% hint style="info" %}
**How to get GoodAccess Login Credentials?**

* Each team Member gets their own **GoodAccess Login Credentials** after they complete their invitation request.&#x20;
  {% endhint %}

### Third-party identity provider's SSO

Logging in with a third-party identity provider requires the administrator to configure [single sign-on](/configuration-guides/features/sso-scim) in the Control Panel.&#x20;

## Test connection

After successful login, click on the connect button and [test the connection](https://www.google.com/search?q=what+is+my+ip). Your public IP address should be the same as the IP address of your dedicated GoodAccess Gateway.

<div><figure><img src="/files/rOe4n4b0xp7kmJqwKdIm" alt=""><figcaption></figcaption></figure> <figure><img src="/files/CdScIRXRhLATHeLa7F85" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
**If you are experiencing any connection problems:**

* check our [Troubleshooting](/faq-and-troubleshooting/troubleshooting)
* or [contact our technical support](https://www.goodaccess.com/contact)
  {% endhint %}

## Not sure about the next step?&#x20;

Get in touch with our [Solution Architect](https://www.goodaccess.com/contact) who can help you to implement GoodAccess for your specific use case in minutes. This service is completely free.&#x20;


# Features

These configuration guides will teach you how to set up each Feature and get the maximum security out of GoodAccess.

{% content-ref url="/pages/Z59Es37TZdBLRP86yKoH" %}
[Zero Trust Access Control](/configuration-guides/features/zero-trust-access-control)
{% endcontent-ref %}

{% content-ref url="/pages/CNyPPTOc3bBP2m0ZsTYa" %}
[API Integration](/configuration-guides/features/api-integration)
{% endcontent-ref %}

{% content-ref url="/pages/iXsoxzJG3SJ6gLl0uJP3" %}
[SIEM Integration](/configuration-guides/features/siem-integration)
{% endcontent-ref %}

{% content-ref url="/pages/sIQu2h18uOUNmbriVlXM" %}
[SSO/SCIM](/configuration-guides/features/sso-scim)
{% endcontent-ref %}

{% content-ref url="/pages/sCOunC2dFkTcbAXHdia4" %}
[MFA](/configuration-guides/features/mfa)
{% endcontent-ref %}

{% content-ref url="/pages/SzGUhUlFTe1Dtr5UaZ8O" %}
[Passkeys](/configuration-guides/features/passkeys)
{% endcontent-ref %}

{% content-ref url="/pages/QyB9wQYpoUOgW0id5ecQ" %}
[MSI deployment](/configuration-guides/features/msi-deployment)
{% endcontent-ref %}

{% content-ref url="/pages/45MKl48tUbjdZ2U6rPrK" %}
[Threat Blocker](/configuration-guides/features/threat-blocker)
{% endcontent-ref %}

{% content-ref url="/pages/JqthvozfYMDX6k1fl2Qa" %}
[Custom Domain Blocking](/configuration-guides/features/custom-domain-blocking)
{% endcontent-ref %}

{% content-ref url="/pages/VWChy6hsMpBomJ7MZwhY" %}
[DNS Management](/configuration-guides/features/dns-management)
{% endcontent-ref %}

{% content-ref url="/pages/VP8Ah1zghXJ35nbyaXY6" %}
[Split Tunneling](/configuration-guides/features/split-tunneling)
{% endcontent-ref %}

{% content-ref url="/pages/ncBK4eZpFTF97t6DEvi5" %}
[Port Forwarding](/configuration-guides/features/port-forwarding)
{% endcontent-ref %}


# Zero Trust Access Control

Take control of your network security with Zero Trust Access Control.

Zero Trust Access Control is a fundamental component of Zero Trust Network Access (ZTNA), which challenges the traditional notion of trust in network security. Unlike traditional perimeter-based security models that implicitly trust users and devices once they gain access to the network, Zero Trust Access Control operates on the principle of "never trust, always verify."

In a Zero Trust Access Control model, every access attempt is treated as potentially unauthorized until proven otherwise. This approach minimizes the risk of lateral movement and unauthorized access by enforcing strict authentication, authorization, and continuous monitoring mechanisms.

At GoodAccess, we embrace the Zero Trust philosophy and implement it through our comprehensive Zero Trust Access Control solution. It utilizes four key features:

{% content-ref url="/pages/K8U8ZwRNHRkOTLOz1Xcb" %}
[Access Cards](/configuration-guides/features/zero-trust-access-control/access-cards)
{% endcontent-ref %}

{% content-ref url="/pages/BzhkpPi6ZhAFTSdROQqw" %}
[Device Posture Check](/configuration-guides/features/zero-trust-access-control/device-posture-check)
{% endcontent-ref %}

{% content-ref url="/pages/j5TIvejpb7cZKG4hcwJc" %}
[Device Approval](/configuration-guides/features/zero-trust-access-control/device-approval)
{% endcontent-ref %}

{% content-ref url="/pages/18gDAkWLaG22xQTwpcOE" %}
[Geo Restrictions](/configuration-guides/features/zero-trust-access-control/geo-restrictions)
{% endcontent-ref %}


# Access Cards

Increase your organization's security with Access Cards. Define who can access your Systems and Clouds & Branches and when. Enforce granular, time-based restrictions to ensure secure, tailored access.

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

Access Cards offer a powerful, flexible way to manage and secure access to your organization’s Systems and Clouds & Branches. As a core component of Zero Trust Access Control, Access Cards allow you to define not only **who** can access your resources but also **when** they are allowed to do so. This capability enhances security by ensuring that access is granted only during a set time period—whether it’s standard business hours, temporary project periods, or any custom schedule that meets your organization’s needs. For instance, you can implement Privileged Access Management (PAM) by issuing temporary Access Cards that grant administrators access to critical systems only when needed, with access automatically revoked after a predefined period (e.g., 24 hours). Similarly, you can enforce strict business-hour access policies to ensure users can access your systems only during approved operating times, thereby reducing off-hours vulnerabilities.

Unlike traditional access management, Access Cards automatically control FWaaS (Firewall-as-a-Service) in the background. This means there’s no need to manually configure firewall rules for identity-based access control—everything is handled automatically. This simplifies access control and makes it easy to implement even for non-technical users, similar to physical perimeter security.

{% hint style="info" %}
By default, Access Cards are disabled and all Members have unrestricted access to all the defined Systems and Clouds & Branches.
{% endhint %}

<figure><img src="/files/8d7epMejiBC44DhMOIlP" alt="Access Cards section of the GoodAccess Control Panel."><figcaption><p>Access Cards section of the GoodAccess Control Panel</p></figcaption></figure>

## Real-World Use Cases

Below are practical examples that show how Access Cards can simplify access management and enhance security in various scenarios.

#### 1. Privileged Access Management (PAM) for Admin Accounts

Your company needs to grant administrative access to critical systems only when necessary. By default, no one has access to an admin interface. When an administrator requires access, you create an Access Card valid for a limited time (e.g., 24 hours). Once expired, access is automatically revoked—keeping your critical systems secure.

**Key Benefits:**

* **Minimized Attack Surface:** No default admin access reduces the risk of unauthorized entry.
* **Full Visibility & Auditability:** All administrative actions are logged, providing a clear audit trail.
* **Automated Expiry:** Access is automatically revoked after the set time period, eliminating the need for manual intervention.

#### 2. Temporary Employee or Contractor Access

Your company hires temporary employees or contractors who need access to internal systems for a limited time. Instead of manually revoking their access later, you create an Access Card with a set expiration date. Once the expiration time is reached, the Access Card is automatically disabled, ensuring they can no longer access the assigned systems.

**Key Benefits:**

* **Reduced Administrative Overhead:** Automatic expiration means you don’t need to manually revoke access.
* **Enhanced Security:** Ensures that temporary access doesn’t persist longer than required.
* **Time-Bound Access:** Access is precisely limited to the necessary duration.

#### 3. Restricting Access to Business Hours

Your organization operates between 9 AM and 5 PM. To prevent unauthorized system access outside of working hours, you configure an Access Card with specific time slot restrictions. This ensures employees can only access your systems during designated working hours, reducing security risks from off-hours access.

**Key Benefits:**

* **Enhanced Security:** Limits system access to times when your organization is operational.
* **Reduced Risk:** Minimizes the potential for off-hours breaches or unauthorized access.
* **Policy Compliance:** Supports organizational policies and regulatory requirements.

#### 4. Role-Based Access for Different Teams

Different teams within your organization require different access levels. For example, the IT team needs access to infrastructure systems, while the sales team only requires CRM access. With Access Cards, you can define granular access by assigning separate cards to each team, following the principle of least privilege—ensuring employees only have access to what they need.

**Key Benefits:**

* **Granular Control:** Provides precise access permissions based on role requirements.
* **Improved Security:** Reduces exposure by ensuring users only access what they need.
* **Simplified Management:** Makes it easier to update or revoke access as team needs evolve.

#### 5. Emergency Access for Incident Response Teams

Your cybersecurity team needs immediate access to sensitive systems during a security incident. Instead of permanently granting broad access, you issue a temporary Access Card that is valid only for the duration of the incident. Once the situation is resolved, access is automatically revoked when the card expires.

**Key Benefits:**

* **Immediate Availability:** Quickly grants access when it’s most needed.
* **Limited Exposure:** Temporary access minimizes prolonged security risks.
* **Comprehensive Audit Trail:** All actions taken during the incident are logged for review.

#### 6. Secure Access for Remote Workers

Your workforce is distributed across multiple time zones, and you need to align access permissions with employees’ working hours. With Access Cards, you can define access windows based on each user’s local time zone, ensuring they can securely connect without exposing systems to unnecessary risk.

**Key Benefits:**

* **Time Zone Flexibility:** Customizes access windows based on local time.
* **Enhanced Security:** Restricts access to approved time periods, reducing risk.
* **Consistent Policy Enforcement:** Ensures uniform remote access practices across your organization.

#### 7. Seasonal or Part-Time Employee Access

Your company hires seasonal workers who need access to internal sales and inventory systems only during peak seasons. By issuing Access Cards with pre-defined expiration dates, access is automatically revoked at season’s end, preventing former employees from accessing the systems.

**Key Benefits:**

* **Automated Revocation:** Ensures access ends when it’s no longer needed.
* **Cost-Effective Management:** Simplifies temporary access without additional manual processes.
* **Increased Security:** Prevents unauthorized access after the designated period.

#### 8. Guest Access for External Auditors or Partners

Your company occasionally collaborates with external auditors or business partners who need access to specific systems for a limited time. Instead of permanently granting access, you assign an Access Card with strict time and system access limitations. Once their assessment or project is complete, the Access Card expires, immediately disabling their access.

**Key Benefits:**

* **Controlled Exposure:** Limits the extent and duration of external access.
* **Improved Security:** Prevents permanent access by external parties.
* **Clear Audit Trails:** All guest access is logged for compliance and monitoring.

## Configuration guide

[Log in to the GoodAccess **Control Panel**, and go to **Access Control** > **Access Cards**.](https://app.goodaccess.com/access-cards/)

Click **+ Add Access Card**, and give the Access Card a name (e.g., Developers, Marketing, Sales, etc.).

### Step 1 - Members & Groups

Click **+ Add** to assign individual Members or Groups who should access your protected Systems and Clouds & Branches.

Click **Continue**.

<figure><img src="/files/3GYM9BARZOzRyOXMheqm" alt="Step 1 of the Access Cards setup wizard."><figcaption><p>Members &#x26; Groups</p></figcaption></figure>

### Step 2 - Systems & Branches

Click **+ Add** to select which Systems and Clouds & Branches the chosen Members can access.

Click **Continue**.

<figure><img src="/files/Uy1kDXKtZLmLDpHobK8A" alt="Step 2 of the Access Cards setup wizard."><figcaption><p>Systems &#x26; Branches</p></figcaption></figure>

### Step 3 (optional) - Time Management

* **Timezone** - Select the time zone in which you want to set your time restrictions.
* **Temporary access** - Set an expiration date and time for the Access Card. Once expired, it is automatically disabled, cutting off access immediately.
* **Time slot restrictions** - Define specific access time slots (e.g., business hours). Access outside these hours is restricted.

Click **Submit** to create the Access Card.

{% hint style="info" %}
The Access Control rules will take effect immediately for all active Gateways.
{% endhint %}

<figure><img src="/files/Aq1xWcddFgqusj1u2hOB" alt="Step 3 of the Access Cards setup wizard."><figcaption><p>Time Management</p></figcaption></figure>

### Enabling Access Cards

{% hint style="danger" %}
**Please note:** Enabling Access Cards without any settings will prevent all Members from accessing your Systems and Clouds & Branches!
{% endhint %}

Check **Enable Access Cards**, and click **Yes, enable!**.

You have now successfully set up an Access Control rule that determines who can access what—and when.

## Not sure about the configuration?

Get in touch with our [Solution Architect](https://www.goodaccess.com/contact) who can help you understand how to effectively secure your organization with the Access Cards and help you configure it. This service is completely free.


# Device Posture Check

Secure your network perimeter effectively with Device Posture Check, which assesses device security based on customizable policy restrictions in real-time.

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

The Device Posture Check is a sophisticated security measure integrated into our Client Application, designed to assess the security posture of devices seeking access to the network perimeter in real-time. It employs a comprehensive set of policy restrictions that can be customized to align with organizational security requirements.

## How it works

1. **Device Assessment**: When a user starts a Client Application, or when a device attempts to connect to the perimeter, the Device Posture Check feature conducts a comprehensive assessment of the device's security posture based on the specified policy restrictions. This assessment is then automatically repeated every 5 minutes, ensuring continuous compliance with your security policies.
2. **Policy Evaluation**: The feature evaluates the device's compliance with each policy restriction, determining whether it meets the required security standards.&#x20;
3. **Access Control**: Based on the results of the posture check, the device is either granted or denied access to the perimeter.
4. **Real-time Policy Enforcement**: The Device Posture Check feature is continuously monitoring for changes in policy restrictions. If new policies are applied or if existing ones are modified, devices that no longer meet the updated criteria are promptly disconnected from the perimeter.
5. **Centralized Monitoring**: Administrators have overview of all devices from Control Panel, with detailed insights into the posture checks perfomed on each device, including historical data.

## Available policy restrictions

{% tabs %}
{% tab title="Windows" %}

* [Supported OS versions only](#user-content-fn-1)[^1]
* [Supported Client App versions only](#user-content-fn-2)[^2]
* [Disk encryption enabled](#user-content-fn-3)[^3]
* [Lock screen with authentication](#user-content-fn-4)[^4]
* [Running Antivirus](#user-content-fn-5)[^5]
* [Updated Antivirus](#user-content-fn-6)[^6]
* [Firewall enabled](#user-content-fn-7)[^7]
* [SMBv1 disabled](#user-content-fn-8)[^8]
* [Part of a domain](#user-content-fn-9)[^9]
* [Registry key](#user-content-fn-10)[^10]
* [File in specific location](#user-content-fn-11)[^11]
* [Running service](#user-content-fn-12)[^12]
* [Running process](#user-content-fn-13)[^13]
  {% endtab %}

{% tab title="Linux" %}

* Kernel Version
* [Supported Client App versions only](#user-content-fn-2)[^2]
* [Lock screen with authentication](#user-content-fn-4)[^4]
* [Firewall enabled](#user-content-fn-7)[^7]
* [Disk encryption enabled](#user-content-fn-14)[^14]
* [Allowed Distributions](#user-content-fn-15)[^15]
* [File in specific location](#user-content-fn-11)[^11]
* [Running service](#user-content-fn-12)[^12]
* [Running process](#user-content-fn-13)[^13]
  {% endtab %}

{% tab title="macOS" %}

* OS Version / [Supported OS versions only](#user-content-fn-1)[^1]
* [Supported Client App versions only](#user-content-fn-2)[^2]
* [Lock screen with authentication](#user-content-fn-4)[^4]
* [Firewall enabled](#user-content-fn-7)[^7]
* [Disk encryption enabled](#user-content-fn-16)[^16]
* [File in specific location](#user-content-fn-11)[^11]
* [Running service](#user-content-fn-12)[^12]
* [Running process](#user-content-fn-13)[^13]
  {% endtab %}

{% tab title="iPadOS" %}

* [Supported OS versions only](#user-content-fn-1)[^1]
* [Supported Client App versions only](#user-content-fn-2)[^2]
* [Lock screen with authentication](#user-content-fn-4)[^4]
  {% endtab %}

{% tab title="iOS" %}

* [Supported OS versions only](#user-content-fn-1)[^1]
* [Supported Client App versions only](#user-content-fn-2)[^2]
* [Lock screen with authentication](#user-content-fn-4)[^4]
  {% endtab %}

{% tab title="Android" %}

* [Supported OS versions only](#user-content-fn-1)[^1]
* [Supported Client App versions only](#user-content-fn-2)[^2]
* [Rooted device is not allowed](#user-content-fn-17)[^17]
* [Debug mode off](#user-content-fn-18)[^18]
* [Emulator not allowed](#user-content-fn-19)[^19]
* [Biometrics enabled](#user-content-fn-20)[^20]
* [Trusted Execution Environment (TEE) available](#user-content-fn-21)[^21]
* [Strongbox available](#user-content-fn-22)[^22]
* [Lock screen with authentication](#user-content-fn-4)[^4]
  {% endtab %}
  {% endtabs %}

## Real-World Use Cases

Below are practical examples that show how Device Posture Check can enhance security and ensure compliance in various scenarios.

#### 1. Ensuring Compliance for Corporate & BYOD Devices&#x20;

Whether your organization relies on corporate devices, allows Bring Your Own Device (BYOD), or both, the Device Posture Check continuously assesses every device attempting to access your network perimeter.

**Key Benefits:**

* **Reduced Risk:** Only compliant devices are allowed to access your network perimeter, minimizing potential vulnerabilities.
* **Cost Efficiency:** By securely enabling BYOD, your organization can reduce hardware costs while maintaining strict security standards.
* **Seamless Integration:** Both corporate and personal devices are managed under a unified security framework, simplifying overall administration.

#### 2. Regulatory Compliance and Audit Readiness

When your organization must adhere to industry regulations (e.g., GDPR, HIPAA, PCI-DSS, SOC2, NIS2), Device Posture Check supports your compliance efforts by continuously enforcing and logging security policies, helping you meet stringent regulatory requirements.

**Key Benefits:**

* **Regulatory Adherence:** Ensures all devices meet industry-specific security standards.
* **Audit Readiness:** Comprehensive logs facilitate the process of compliance reporting and audits.
* **Reduced Risk of Non-Compliance:** Only compliant devices are granted access, lowering the risk of regulatory breaches.

#### 3. Securing Third-Party and Guest Access

When your organization collaborates with external partners or hosts guest users, Device Posture Check ensures that every connecting device—from vendors to auditors—meets your security standards before accessing your network.

**Key Benefits:**

* **Controlled External Access:** Only devices that pass the security check can connect, reducing exposure to external threats.
* **Enhanced Auditability:** Detailed logs provide a clear record of compliance for external devices.
* **Minimized Risk:** Protects your network by ensuring that external access is strictly regulated.

#### 4. Securing Access to Sensitive Data

When access to sensitive data or intellectual property is at stake, Device Posture Check ensures that only devices with robust security postures can connect to critical systems.

**Key Benefits:**

* **Enhanced Data Protection:** Only devices meeting stringent security criteria can access sensitive resources.
* **Risk Mitigation:** Reduces the potential for data breaches by blocking non-compliant devices.
* **Granular Control:** Allows for customized security requirements tailored to high-risk data environments.

#### 5.  Adaptive Security in Dynamic Environments

As your organization's security policies evolve, the Device Posture Check continuously evaluates connected devices and enforces updated criteria in real time. This adaptive approach is essential in a dynamic threat landscape.

**Key Benefits:**

* **Continuous Security:** Automatically adapts to policy changes, ensuring ongoing compliance.
* **Instant Enforcement:** Non-compliant devices are immediately disconnected upon policy updates.
* **Operational Flexibility:** Supports rapid updates to security policies without manual intervention.

## Configuration guide

{% hint style="info" %}
A default security policy, recommended by GoodAccess, is automatically enabled. This policy is designed to only log device posture checks and does not prevent access to the perimeter. It cannot be deleted but can be disabled using the provided switch button.
{% endhint %}

[Log in to the GoodAccess **Control Panel**, and go to **Access Control** > **Device Posture Check**.](https://app.goodaccess.com/device-posture-check/)

Click **+ Add Policy**.

<figure><img src="/files/dLfXpwGfXXZG60gE4xC2" alt="Device Posture Check section of the GoodAccess Control Panel."><figcaption><p>Device Posture Check section of the GoodAccess Control Panel</p></figcaption></figure>

### Step 1 - General Settings

* **Name** - Give the policy a name
* **Description** - Optionally write a description
* **On failure action** - Choose the action to take if a device fails the posture check:
  * Make a log entry
  * Deny access & make a log entry
* **On failure message** - Choose the message to display if a device fails the posture check:
  * Default message
  * Custom message
* **Enable email notification** - Optionally notify the Team Owner or all Admins via email if a device fails the posture check.

Click **Continue**.

<figure><img src="/files/C3n2twu9EGqu0MyCO8z2" alt="Step 1 of the Device Posture Check setup wizard."><figcaption><p>General Settings</p></figcaption></figure>

### Step 2 - OS Restrictions

Choose the operating system(s) included in this restriction. For each selected OS, specify the [policy restrictions](#available-policy-restrictions).

Click **Continue**.

<figure><img src="/files/BqX6OCpzaERxfWXmINQF" alt="Step 2 of the Device Posture Check setup wizard."><figcaption><p>OS Restrictions</p></figcaption></figure>

### Step 3 - Members & Groups

Click **+ Add** to assign individual Members or Groups to apply these restrictions to, or select the option to apply them to all Members of your Team automatically.

Click **Continue**.

<figure><img src="/files/Xji2ULUVJTTEF2rNVvaQ" alt="Step 3 of the Device Posture Check setup wizard."><figcaption><p>Members &#x26; Groups</p></figcaption></figure>

### Step 4 - Summary

Make sure to thoroughly review all configured Device Posture Check policy settings and make any necessary adjustments to prevent unintended limitation of access to the perimeter.

Click **Submit**.

<figure><img src="/files/3nQiaeBZyE87HwmxccyV" alt="Step 4 of the Device Posture Check setup wizard."><figcaption><p>Summary</p></figcaption></figure>

You have now successfully set up your Device Posture Check policy.

## Not sure about the configuration?

Get in touch with our [Solution Architect](https://www.goodaccess.com/contact) who can help you understand how to effectively secure your organization with the Device Posture Check and help you configure it. This service is completely free.

[^1]: This rule requires the user to use an operating system officially supported by the vendor.

[^2]: This rule requires the user to use only supported versions of the GoodAccess Client Application.

[^3]: The device must have disk encryption enabled. We detect only BitLocker, which is the native encryption tool for OS Windows.

[^4]: This rule requires the user to authenticate themselves before using the device.

[^5]: The device must have an antivirus program running.

[^6]: If the device has an antivirus program running, you may also require it to be up to date. This ensures that the antivirus protection has the latest virus definition database and can effectively recognize current threats.

[^7]: The device must have the firewall enabled.

[^8]: The device must have SMBv1 protocol disabled. SMBv1 is outdated and insecure, and disabling it helps protect against known vulnerabilities and enforces the use of safer alternatives like SMBv2 or SMBv3. Available from app version 4.6.10.

[^9]: The device must be part of the specified domain.

[^10]: The device is required to have a predefined registry key and value within the system registry. The path to the registry should not start with "Computer\\" but with one of the following paths: HKEY\_LOCAL\_MACHINE, HKEY\_CLASSES\_ROOT, HKEY\_CURRENT\_USER, HKEY\_USERS or HKEY\_CURRENT\_CONFIG.

[^11]: This rule requires the device to have a specified file located in a specified path on the system.

[^12]: This rule requires that there is an active service with the given name running on the device.

[^13]: This rule requires that there is an active process with the given name running on the device.

[^14]: The device must have disk encryption enabled.

[^15]: Debian GNU/Linux, Ubuntu, Linux Mint, CentOS Stream, Red Hat Enterprise Linux, Fedora Linux, Rocky Linux

[^16]: The device must have disk encryption enabled. We detect only FileVault, which is the native encryption tool for macOS.

[^17]: If a device is "rooted" the user gains full access to the system and can make extensive modifications and changes that would otherwise be unavailable.

[^18]: The device must have debug mode disabled. By disabling debug mode, you protect your data and prevent potential attacks.

[^19]: The device must not be using an emulator.

[^20]: Biometric authentication must be enabled on the device. Enabling biometric authentication enhances your device's security.

[^21]: The user has to use a device with TEE available.

[^22]: The user has to use a device with Strongbox available.


# Device Approval

Enhance security by controling which devices gain access to your secure perimeter.

{% hint style="danger" %}
To ensure full functionality of this feature, no one with a GoodAccess application version of **4.4.0** or earlier will be able to log in!
{% endhint %}

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

You may set up Device Approval in [Control Panel > Access Control > Device Approval](< https://app.goodaccess.com/device-approval/>).

The Device Approval feature ensures that no new devices can access your secure perimeter unless manually approved by an Admin. When a new device attempts to connect, it will be placed in a pending queue. Only after Admin approval will the device gain access to the perimeter.

To set up Device Approval, check **Enable Device Approval**, and click **Save changes**.


# Geo Restrictions

Strengthen protection by allowing or denying connections from specific countries.

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

You may set up Geo Restrictions in [Control Panel > Access Control > Geo Restrictions](https://app.goodaccess.com/geo-restrictions/).

The Geo Restrictions feature allows you to control the geographical locations from which your Team Members can access GoodAccess. By preventing unauthorized access from specific regions, this feature helps protect your Team from potential risks.

To set up Geo Restrictions, add **Countries** and **Members/Groups** to your restrictions, check **Enable Geo Restrictions**, and click **Save changes**.


# API Integration

This guide will show you how to obtain an API token within the GoodAccess Control Panel for accessing the API and performing authorized operations.

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

For more detailed API integration documentation, we recommend visiting the [Postman Documentation](https://documenter.getpostman.com/view/29070402/2sA3sAiTwM) or downloading the collection and importing it into Postman.

## Obtaining API token

[Log in to the GoodAccess **Control Panel**, and go to **Settings** > **API Integration**.](https://app.goodaccess.com/api-integration/)

Here, add a new integration or edit an existing one.

Select scopes of the integration, set expiration and allowed IP addresses, and generate a token.

Additionally, you can monitor the activity and communication of the integration from this interface.

<figure><img src="/files/A38ZbTdBRvTYeqmPaVQY" alt="API Integration detail."><figcaption><p>API Integration detail</p></figcaption></figure>

{% hint style="danger" %}
**Please note:** Immediately after being generated, you will see the token for a **limited period**. It is important to save the token in a secure place, as it provides access to the API and can be used to perform operations. After this period has expired, the token will be secured and you won’t be able to access it.
{% endhint %}

Your token can be used to authorize HTTP requests to the GoodAccess API. Each request must include an Authorization header with the token written as Bearer \<token>.

See the examples at the bottom of the page for correct syntax.

{% hint style="info" %}
Treat your token like a password and store it securely. For example, use the methods env and dotenv to store it in a development environment.
{% endhint %}

## Testing connection to GoodAccess API

To test your API connection, send an authenticated request to the test-connection endpoint. If the connection is successful, you will get a 200 return code.

## GET /api/v1/test-connection

> Test Connection

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Integrations"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/test-connection":{"get":{"tags":["Integrations"],"summary":"Test Connection","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

Below are examples of how to call the test endpoint in various languages.

{% tabs %}
{% tab title="curl" %}

```bash
curl -i https://integration.goodaccess.com/api/v1/test-connection \
  -H "Authorization: Bearer <integration_token>"
```

{% endtab %}

{% tab title="Python" %}

```python
import requests

url = 'https://integration.goodaccess.com/api/v1/test-connection'
headers = {
    'Authorization': 'Bearer <integration_token>'
}

response = requests.get(url, headers=headers)
```

{% endtab %}

{% tab title="Node" %}

```javascript
const axios = require('axios');

const url = 'https://integration.goodaccess.com/api/v1/test-connection';
const token = '<integration_token>';

axios.get(url, {
  headers: {
    'Authorization': `Bearer ${token}`
  }
})
.then(response => {
 //...
})
.catch(error => {
  //...
});
```

{% endtab %}

{% tab title="PHP" %}

```php
<?php

$url = 'https://integration.goodaccess.com/api/v1/test-connection';
$token = '<integration_token>';

$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url);
curl_setopt($ch, CURLOPT_HTTPHEADER, array(
    'Authorization: Bearer ' . $token,
));
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);

$response = curl_exec($ch);
$httpcode = curl_getinfo($ch, CURLINFO_HTTP_CODE);

curl_close($ch);
```

{% endtab %}
{% endtabs %}

## [API Reference](/configuration-guides/features/api-integration/api-reference)


# API Reference

Dive into the specifics of each API endpoint by checking out our complete documentation.

{% content-ref url="/pages/Z1c59mb4SWwM1QxtrTML" %}
[Members](/configuration-guides/features/api-integration/api-reference/members)
{% endcontent-ref %}

{% content-ref url="/pages/JoSqw0E0U3fdqtYpYkR9" %}
[Groups](/configuration-guides/features/api-integration/api-reference/groups)
{% endcontent-ref %}

{% content-ref url="/pages/6BOJr2jM9iJAK1GxrkNE" %}
[Systems](/configuration-guides/features/api-integration/api-reference/systems)
{% endcontent-ref %}

{% content-ref url="/pages/VkYXNu4is5fq7dIqDIOT" %}
[System Groups](/configuration-guides/features/api-integration/api-reference/system-groups)
{% endcontent-ref %}

{% content-ref url="/pages/UQQO6oAnzD8lKm7S6mJL" %}
[Access Cards](/configuration-guides/features/api-integration/api-reference/access-cards)
{% endcontent-ref %}

{% content-ref url="/pages/Cr8qHgR71XZHI9Nwcu34" %}
[Relations](/configuration-guides/features/api-integration/api-reference/relations)
{% endcontent-ref %}

{% content-ref url="/pages/hBjysHKWNkyEGepVURx8" %}
[Gateways](/configuration-guides/features/api-integration/api-reference/gateways)
{% endcontent-ref %}

{% content-ref url="/pages/8SPUZ9QWIm6h9Lp14O7V" %}
[Devices](/configuration-guides/features/api-integration/api-reference/devices)
{% endcontent-ref %}

{% content-ref url="/pages/L7cUyO8nmJrFNAKZJgPw" %}
[Tokens](/configuration-guides/features/api-integration/api-reference/tokens)
{% endcontent-ref %}

{% content-ref url="/pages/a1JxtyTQ2ZfRNcEJPgWH" %}
[Logs](/configuration-guides/features/api-integration/api-reference/logs)
{% endcontent-ref %}


# Members

This endpoint allows you to perform actions on a specific Member of your Team.

## GET /api/v1/members

> Fetch All Team Members

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Team Members"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/members":{"get":{"tags":["Team Members"],"summary":"Fetch All Team Members","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## GET /api/v1/member/{teamMemberId}

> Fetch Team Member by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Team Members"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/member/{teamMemberId}":{"get":{"tags":["Team Members"],"summary":"Fetch Team Member by its ID","parameters":[{"in":"path","name":"teamMemberId","schema":{"type":"string"},"required":true,"description":"ID of team member"}],"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## POST /api/v1/member/{teamMemberId}/disconnect

> Disconnect Team Member by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Team Members"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/member/{teamMemberId}/disconnect":{"post":{"tags":["Team Members"],"summary":"Disconnect Team Member by its ID","parameters":[{"in":"path","name":"teamMemberId","schema":{"type":"string"},"required":true,"description":"ID of team member"}],"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

{% hint style="info" %}
**💡 Implementing Step-Up Authentication**

You can use the **Disconnect** endpoint to enforce **Step-Up Authentication**. By terminating an active session, you trigger a mandatory re-authentication challenge upon the next reconnection attempt.

**Note**: This requires specific security policies to be enabled in your Control Panel. For setup instructions and common use cases, please refer to our [MFA Configuration Guide](/configuration-guides/features/mfa).
{% endhint %}

## POST /api/v1/member

> Create Team Member

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Team Members"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/member":{"post":{"tags":["Team Members"],"summary":"Create Team Member","requestBody":{"content":{"application/json":{"schema":{"type":"object"}}}},"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## PUT /api/v1/member/{teamMemberId}

> Update Team Member by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Team Members"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/member/{teamMemberId}":{"put":{"tags":["Team Members"],"summary":"Update Team Member by its ID","parameters":[{"in":"path","name":"teamMemberId","schema":{"type":"string"},"required":true,"description":"ID of team member"}],"requestBody":{"content":{"application/json":{"schema":{"type":"object","properties":{"name":{"type":"string","description":"New name for the member (only for members without an account)","maxLength":45},"password":{"type":"string","description":"New password for the member (only for members without an account)","minLength":8,"maxLength":45},"is_user_blocked":{"type":"boolean","description":"Block or unblock the member"}}}}}},"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## DELETE /api/v1/member/{teamMemberId}

> Delete Team Member by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Team Members"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/member/{teamMemberId}":{"delete":{"tags":["Team Members"],"summary":"Delete Team Member by its ID","parameters":[{"in":"path","name":"teamMemberId","schema":{"type":"string"},"required":true,"description":"ID of team member"}],"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## [Relations](/configuration-guides/features/api-integration/api-reference/relations)


# Groups

This endpoint allows you to perform actions on a specific Group of your Team.

## GET /api/v1/groups

> Fetch All Groups

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Groups"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/groups":{"get":{"tags":["Groups"],"summary":"Fetch All Groups","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## GET /api/v1/group/{groupId}

> Fetch Group by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Groups"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/group/{groupId}":{"get":{"tags":["Groups"],"summary":"Fetch Group by its ID","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## POST /api/v1/group

> Create Group

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Groups"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/group":{"post":{"tags":["Groups"],"summary":"Create Group","requestBody":{"content":{"application/json":{"schema":{"type":"object"}}}},"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"409":{"description":"Conflict","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## PUT /api/v1/group/{groupId}

> Update Group by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Groups"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/group/{groupId}":{"put":{"tags":["Groups"],"summary":"Update Group by its ID","requestBody":{"content":{"application/json":{"schema":{"type":"object"}}}},"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"409":{"description":"Conflict","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## DELETE /api/v1/group/{groupId}

> Remove Group by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Groups"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/group/{groupId}":{"delete":{"tags":["Groups"],"summary":"Remove Group by its ID","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## [Relations](/configuration-guides/features/api-integration/api-reference/relations)


# Systems

This endpoint allows you to perform actions on a specific System of your Team.

## GET /api/v1/systems

> Fetch All Systems

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Systems"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/systems":{"get":{"tags":["Systems"],"summary":"Fetch All Systems","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## GET /api/v1/system/{systemId}

> Fetch System by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Systems"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/system/{systemId}":{"get":{"tags":["Systems"],"summary":"Fetch System by its ID","parameters":[{"in":"path","name":"systemId","schema":{"type":"string"},"required":true,"description":"ID of system"}],"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

{% hint style="warning" %}
To create an Advanced System, include the `services` field in the request body. Once this field is present, an Advanced System will be created and the `port` and `protocol` defined in the Basic System will be **ignored**.
{% endhint %}

## POST /api/v1/system

> Create System

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Systems"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/system":{"post":{"tags":["Systems"],"summary":"Create System","requestBody":{"content":{"application/json":{"schema":{"type":"object","description":"To create an advanced system, include the services field in the request body. Once this field is present, an advanced system will be created and the port and protocol defined in the basic system will be ignored."}}}},"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"409":{"description":"Conflict","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## PUT /api/v1/system/{systemId}

> Update System by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Systems"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/system/{systemId}":{"put":{"tags":["Systems"],"summary":"Update System by its ID","parameters":[{"in":"path","name":"systemId","schema":{"type":"string"},"required":true,"description":"ID of system"}],"requestBody":{"content":{"application/json":{"schema":{"type":"object"}}}},"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"409":{"description":"Conflict","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## DELETE /api/v1/system/{systemId}

> Remove System by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Systems"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/system/{systemId}":{"delete":{"tags":["Systems"],"summary":"Remove System by its ID","responses":{"200":{"description":"Successful response","content":{"application/json":{}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## [Relations](/configuration-guides/features/api-integration/api-reference/relations)


# System Groups

This endpoint allows you to perform actions on a specific System Group of your Team.

## GET /api/v1/system-groups

> Fetch All System Groups

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"System Groups"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/system-groups":{"get":{"tags":["System Groups"],"summary":"Fetch All System Groups","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## GET /api/v1/system-group/{systemGroupId}

> Fetch System Group by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"System Groups"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/system-group/{systemGroupId}":{"get":{"tags":["System Groups"],"summary":"Fetch System Group by its ID","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## POST /api/v1/system-group

> Create System Group

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"System Groups"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/system-group":{"post":{"tags":["System Groups"],"summary":"Create System Group","requestBody":{"content":{"application/json":{"schema":{"type":"object"}}}},"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## PUT /api/v1/system-group/{systemGroupId}

> Update System Group by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"System Groups"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/system-group/{systemGroupId}":{"put":{"tags":["System Groups"],"summary":"Update System Group by its ID","requestBody":{"content":{"application/json":{"schema":{"type":"object"}}}},"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"409":{"description":"Conflict","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## DELETE /api/v1/system-group/{systemGroupId}

> Remove System Group by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"System Groups"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/system-group/{systemGroupId}":{"delete":{"tags":["System Groups"],"summary":"Remove System Group by its ID","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## [Relations](/configuration-guides/features/api-integration/api-reference/relations)


# Access Cards

Create custom Access Cards granting access to selected Systems and assign it to your Team Members.

## GET /api/v1/access-cards

> Fetch All access cards

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Access Cards"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/access-cards":{"get":{"tags":["Access Cards"],"summary":"Fetch All access cards","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## GET /api/v1/access-card/{accessCardId}

> Fetch Access Card by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Access Cards"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/access-card/{accessCardId}":{"get":{"tags":["Access Cards"],"summary":"Fetch Access Card by its ID","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## POST /api/v1/access-card

> Create Access Card

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Access Cards"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/access-card":{"post":{"tags":["Access Cards"],"summary":"Create Access Card","requestBody":{"content":{"application/json":{"schema":{"type":"object"}}}},"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"409":{"description":"Conflict","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## PUT /api/v1/access-card/{accessCardId}

> Update Access Card by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Access Cards"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/access-card/{accessCardId}":{"put":{"tags":["Access Cards"],"summary":"Update Access Card by its ID","requestBody":{"content":{"application/json":{"schema":{"type":"object"}}}},"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"409":{"description":"Conflict","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## DELETE /api/v1/access-card/{accessCardId}

> Remove Access Card by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Access Cards"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/access-card/{accessCardId}":{"delete":{"tags":["Access Cards"],"summary":"Remove Access Card by its ID","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## [Relations](/configuration-guides/features/api-integration/api-reference/relations)


# Relations

Define relations like Access Cards with Systems or Members, and Groups with Access Cards or Members.

## POST /api/v1/relation/access-card/{accessCardId}/system/{systemId}

> Creates relation between access card and system

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Relation"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/relation/access-card/{accessCardId}/system/{systemId}":{"post":{"tags":["Relation"],"summary":"Creates relation between access card and system","requestBody":{"content":{}},"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"409":{"description":"Conflict","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## DELETE /api/v1/relation/access-card/{accessCardId}/system/{systemId}

> Remove relation between access card and system

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Relation"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/relation/access-card/{accessCardId}/system/{systemId}":{"delete":{"tags":["Relation"],"summary":"Remove relation between access card and system","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## POST /api/v1/relation/access-card/{accessCardId}/member/{teamMemberId}

> Creates relation between access card and team member

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Relation"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/relation/access-card/{accessCardId}/member/{teamMemberId}":{"post":{"tags":["Relation"],"summary":"Creates relation between access card and team member","requestBody":{"content":{}},"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"409":{"description":"Conflict","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## DELETE /api/v1/relation/access-card/{accessCardId}/member/{teamMemberId}

> Remove relation between access card and member

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Relation"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/relation/access-card/{accessCardId}/member/{teamMemberId}":{"delete":{"tags":["Relation"],"summary":"Remove relation between access card and member","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## POST /api/v1/relation/group/{groupId}/access-card/{accessCardId}

> Creates relation between group and access card

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Relation"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/relation/group/{groupId}/access-card/{accessCardId}":{"post":{"tags":["Relation"],"summary":"Creates relation between group and access card","requestBody":{"content":{}},"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"409":{"description":"Conflict","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## DELETE /api/v1/relation/group/{groupId}/access-card/{accessCardId}

> Removes relation between group and access card

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Relation"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/relation/group/{groupId}/access-card/{accessCardId}":{"delete":{"tags":["Relation"],"summary":"Removes relation between group and access card","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## POST /api/v1/relation/group/{groupId}/member/{teamMemberId}

> Creates relation between group and team member

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Relation"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/relation/group/{groupId}/member/{teamMemberId}":{"post":{"tags":["Relation"],"summary":"Creates relation between group and team member","requestBody":{"content":{}},"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"409":{"description":"Conflict","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## DELETE /api/v1/relation/group/{groupId}/member/{teamMemberId}

> Removes relation between group and team member

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Relation"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/relation/group/{groupId}/member/{teamMemberId}":{"delete":{"tags":["Relation"],"summary":"Removes relation between group and team member","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## POST /api/v1/relation/system-group/{systemGroupId}/access-card/{accessCardId}

> Creates relation between system group and access card

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Relation"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/relation/system-group/{systemGroupId}/access-card/{accessCardId}":{"post":{"tags":["Relation"],"summary":"Creates relation between system group and access card","requestBody":{"content":{}},"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"409":{"description":"Conflict","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## DELETE /api/v1/relation/system-group/{systemGroupId}/access-card/{accessCardId}

> Removes relation between system group and access card

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Relation"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/relation/system-group/{systemGroupId}/access-card/{accessCardId}":{"delete":{"tags":["Relation"],"summary":"Removes relation between system group and access card","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## POST /api/v1/relation/system-group/{systemGroupId}/system/{systemId}

> Creates relation between system group and system

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Relation"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/relation/system-group/{systemGroupId}/system/{systemId}":{"post":{"tags":["Relation"],"summary":"Creates relation between system group and system","requestBody":{"content":{}},"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"409":{"description":"Conflict","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## DELETE /api/v1/relation/system-group/{systemGroupId}/system/{systemId}

> Removes relation between system group and system

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Relation"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/relation/system-group/{systemGroupId}/system/{systemId}":{"delete":{"tags":["Relation"],"summary":"Removes relation between system group and system","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```


# Gateways

This endpoint allows you to fetch data about the Gateways of your Team.

## GET /api/v1/gateways

> Fetch All Gateways

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Gateways"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/gateways":{"get":{"tags":["Gateways"],"summary":"Fetch All Gateways","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## GET /api/v1/gateway/{gatewayId}

> Fetch Gateway by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Gateways"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/gateway/{gatewayId}":{"get":{"tags":["Gateways"],"summary":"Fetch Gateway by its ID","parameters":[{"in":"path","name":"gatewayId","schema":{"type":"string"},"required":true,"description":"ID of gateway"}],"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```


# Devices

This endpoint allows you to fetch data about the Devices of your Team Members.

## GET /api/v1/devices

> Fetch All Devices

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/devices":{"get":{"tags":["Devices"],"summary":"Fetch All Devices","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## GET /api/v1/device/{deviceId}

> Fetch Device by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/device/{deviceId}":{"get":{"tags":["Devices"],"summary":"Fetch Device by its ID","parameters":[{"in":"path","name":"systemId","schema":{"type":"string"},"required":true,"description":"ID of system"}],"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## PUT /api/v1/device/{deviceId}

> Update Device by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/device/{deviceId}":{"put":{"tags":["Devices"],"summary":"Update Device by its ID","requestBody":{"content":{"application/json":{"schema":{"type":"object"}}}},"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## DELETE /api/v1/device/{deviceId}

> Remove Device by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/device/{deviceId}":{"delete":{"tags":["Devices"],"summary":"Remove Device by its ID","responses":{"200":{"description":"Successful response","content":{"application/json":{}}},"404":{"description":"Not Found","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```


# Tokens

This endpoint allows you to perform actions on a specific Token of your Integration.

## Token Scopes

To define what a token can access, you must assign it specific **Scopes**. Each scope grants permission for a particular action or set of data.

{% hint style="danger" %}
**Principle of Least Privilege:** Always grant only the scopes necessary for the specific integration. For example, a logging integration should only have `*-logs.read` scopes.
{% endhint %}

<details>

<summary><strong>Click to expand the full list of Scopes</strong></summary>

| Scope                                      | Description                                   |
| ------------------------------------------ | --------------------------------------------- |
| **Members**                                |                                               |
| `members.create`                           | Create (invite) a new team member             |
| `members.read`                             | Read a specific team member detail            |
| `members.read-all`                         | List all team members                         |
| `members.update`                           | Update a team member                          |
| `members.delete`                           | Delete a team member                          |
| `members.disconnect`                       | Disconnect a team member’s active VPN session |
| **Groups**                                 |                                               |
| `groups.create`                            | Create a new member group                     |
| `groups.read`                              | Read a specific member group detail           |
| `groups.read-all`                          | List all member groups                        |
| `groups.update`                            | Update a member group                         |
| `groups.delete`                            | Delete a member group                         |
| **Systems**                                |                                               |
| `systems.create`                           | Create a new system                           |
| `systems.read`                             | Read a specific system detail                 |
| `systems.read-all`                         | List all systems                              |
| `systems.update`                           | Update a system                               |
| `systems.delete`                           | Delete a system                               |
| **System Groups**                          |                                               |
| `system-groups.create`                     | Create a new system group                     |
| `system-groups.read`                       | Read a specific system group detail           |
| `system-groups.read-all`                   | List all system groups                        |
| `system-groups.update`                     | Update a system group                         |
| `system-groups.delete`                     | Delete a system group                         |
| **Access Cards**                           |                                               |
| `access-cards.create`                      | Create a new access card                      |
| `access-cards.read`                        | Read a specific access card detail            |
| `access-card.read-all`                     | List all access cards                         |
| `access-cards.update`                      | Update an access card                         |
| `access-cards.delete`                      | Delete an access card                         |
| **Relations**                              |                                               |
| `member-group-relation.add`                | Add a member to a group                       |
| `member-group-relation.delete`             | Remove a member from a group                  |
| `member-ac-relation.add`                   | Add a member to an access card                |
| `member-ac-relation.delete`                | Remove a member from an access card           |
| `group-access-card-relation.add`           | Assign an access card to a member group       |
| `group-access-card-relation.delete`        | Remove an access card from a member group     |
| `system-system-group-relation.add`         | Add a system to a system group                |
| `system-system-group-relation.delete`      | Remove a system from a system group           |
| `system-ac-relation.add`                   | Add a system to an access card                |
| `system-ac-relation.delete`                | Remove a system from an access card           |
| `system-group-access-card-relation.add`    | Assign an access card to a system group       |
| `system-group-access-card-relation.delete` | Remove an access card from a system group     |
| **Gateways**                               |                                               |
| `gateways.read`                            | Read a specific gateway detail                |
| `gateway.read-all`                         | List all gateways                             |
| **Devices**                                |                                               |
| `devices.read`                             | Read a specific device detail                 |
| `devices.read-all`                         | List all devices                              |
| `devices.delete`                           | Delete a device                               |
| **Tokens**                                 |                                               |
| `token.create`                             | Create a new API token                        |
| `token.read`                               | Read a specific API token detail              |
| `token.read-all`                           | List all API tokens                           |
| `token.delete`                             | Delete an API token                           |
| **Logs**                                   |                                               |
| `gateway-log.read`                         | Read gateway-level logs                       |
| `system-logs.read`                         | Read system-level logs                        |
| `threat-blocker-logs.read`                 | Read threat blocker logs                      |
| `device-posture-check-logs.read`           | Read device posture check logs                |
| `admin-logs.read`                          | Read admin activity / audit logs              |

</details>

## GET /api/v1/tokens

> Fetch All Tokens

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Tokens"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/tokens":{"get":{"tags":["Tokens"],"summary":"Fetch All Tokens","responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## GET /api/v1/token/{tokenId}

> Fetch Token by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Tokens"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/token/{tokenId}":{"get":{"tags":["Tokens"],"summary":"Fetch Token by its ID","parameters":[{"in":"path","name":"tokenId","schema":{"type":"string"},"required":true,"description":"UUID of the token"}],"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## POST /api/v1/token

> Create a new Token

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Tokens"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/token":{"post":{"tags":["Tokens"],"summary":"Create a new Token","requestBody":{"content":{"application/json":{"schema":{"type":"object","properties":{"name":{"type":"string","description":"Name of the token"},"expires_at":{"type":"string","description":"Expiration date of the token (format 'Y-m-d H:i:s')"},"allowed_ips":{"type":"array","description":"List of IP addresses allowed to use this token. If empty, all IPs are allowed.","items":{"type":"string"}},"allowed_scopes":{"type":"array","description":"List of scopes (permissions) granted to this token. Each scope corresponds to a specific API action.\n","items":{"type":"string","enum":["token.create","token.read","token.delete","token.read-all","members.disconnect","device-posture-check-logs.read","threat-blocker-logs.read","admin-logs.read","devices.read-all","devices.delete","devices.read","group-access-card-relation.delete","group-access-card-relation.add","member-group-relation.delete","member-group-relation.add","system-group-access-card-relation.delete","system-group-access-card-relation.add","system-system-group-relation.delete","system-system-group-relation.add","system-ac-relation.delete","system-ac-relation.add","member-ac-relation.delete","member-ac-relation.add","groups.read-all","system-groups.read-all","access-card.read-all","gateway.read-all","system.read-all","gateway-log.read","members.read-all","system-groups.delete","system-groups.update","system-groups.read","system-groups.create","groups.delete","groups.update","groups.read","groups.create","systems.delete","systems.update","systems.read","systems.create","system-logs.read","access-cards.delete","access-cards.update","access-cards.read","access-cards.create","gateways.read","members.delete","members.update","members.read","members.create"]}}}}}}},"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"type":"object"}}}},"400":{"description":"Validation Error","content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## DELETE /api/v1/token/{tokenId}

> Revoke Token by its ID

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Tokens"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/token/{tokenId}":{"delete":{"tags":["Tokens"],"summary":"Revoke Token by its ID","parameters":[{"in":"path","name":"tokenId","schema":{"type":"string"},"required":true,"description":"UUID of the token to revoke"}],"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```


# Logs

This endpoint allows you to fetch the logs of your Team.

## GET /api/v1/gateway-level-logs

> Gateway Level Logs

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Logs"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/gateway-level-logs":{"get":{"tags":["Logs"],"summary":"Gateway Level Logs","requestBody":{"content":{"application/json":{"schema":{"type":"object"}}}},"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## GET /api/v1/system-level-logs

> System Level Access Logs

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Logs"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/system-level-logs":{"get":{"tags":["Logs"],"summary":"System Level Access Logs","requestBody":{"content":{"application/json":{"schema":{"type":"object"}}}},"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## GET /api/v1/threat-blocker-logs

> Threat Blocker Logs

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Logs"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/threat-blocker-logs":{"get":{"tags":["Logs"],"summary":"Threat Blocker Logs","requestBody":{"content":{"application/json":{"schema":{"type":"object"}}}},"parameters":[{"in":"query","name":"members[]","schema":{"type":"array","items":{"type":"string"}},"description":"Filter by member UUIDs"},{"in":"query","name":"domains[]","schema":{"type":"array","items":{"type":"string"}},"description":"Filter by blocked domain names"},{"in":"query","name":"search","schema":{"type":"string"},"description":"Search across domain, member name and username"},{"in":"query","name":"sort_by","schema":{"type":"string","enum":["member","domain","hits","last_hit"]},"description":"Field to sort by"},{"in":"query","name":"sort_dir","schema":{"type":"string","enum":["asc","desc"],"default":"desc"},"description":"Sort direction"}],"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"array","items":{"type":"object"}}}}},"400":{"description":"Bad Request","content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## GET /api/v1/device-posture-check-logs

> Device Posture Check Logs

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Logs"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/device-posture-check-logs":{"get":{"tags":["Logs"],"summary":"Device Posture Check Logs","requestBody":{"content":{"application/json":{"schema":{"type":"object"}}}},"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"array","items":{"type":"object"}}}}},"400":{"description":"Bad Request","content":{"application/json":{"schema":{"type":"object"}}}},"404":{"description":"Not Found","content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```

## GET /api/v1/admin-logs

> Admin Logs

```json
{"openapi":"3.0.0","info":{"title":"GoodAccess Customer","version":"1.0.0"},"tags":[{"name":"Logs"}],"servers":[{"url":"https://integration.goodaccess.com"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer"}}},"paths":{"/api/v1/admin-logs":{"get":{"tags":["Logs"],"summary":"Admin Logs","requestBody":{"content":{"application/json":{"schema":{"type":"object"}}}},"parameters":[{"in":"query","name":"categories[]","schema":{"type":"array","items":{"type":"string"}},"description":"Filter by log category names"},{"in":"query","name":"search","schema":{"type":"string"},"description":"Search across message, category, admin name and email"}],"responses":{"200":{"description":"OK","headers":{"Content-Type":{"schema":{"type":"string"}}},"content":{"application/json":{"schema":{"type":"array","items":{"type":"object"}}}}},"400":{"description":"Bad Request","content":{"application/json":{"schema":{"type":"object"}}}}}}}}}
```


# Acronis Integration

This guide will show you how to set up an integration between GoodAccess and Acronis CyberApp.

## Key Aspects of the Integration

1. **Threat Blocker Alerts**: Whenever a user attempts to access a potentially harmful website or a site you've restricted for your team, you'll receive an alert through Acronis notifying you that the access attempt has been blocked.

   <figure><img src="/files/gWgZkp18NaxEggRwUeWv" alt="Acronis alert for a Threat Blocker action blocking access to a restricted or harmful website."><figcaption><p>Acronis alert for a Threat Blocker action</p></figcaption></figure>
2. **Device Posture Check Alerts**: To prevent users with outdated or non-compliant devices from connecting to your network, you can configure [Device Posture Check](/configuration-guides/features/zero-trust-access-control/device-posture-check) in GoodAccess. If a user with a non-compliant device attempts to connect, their access will be denied, and you will receive an alert through Acronis.

   <figure><img src="/files/35csAsQpMlayGCbJBa6i" alt="Acronis alert for a Device Posture Check blocking access due to a non-compliant device."><figcaption><p>Acronis alert for a Device Posture Check action</p></figcaption></figure>
3. **Overview of Managed Teams**: The Acronis dashboard provides real-time status and activity updates for the teams you manage through GoodAccess.

## Configuration guide

### Prerequisites

* [GoodAccess Partner account](https://www.goodaccess.com/partners)
* Acronis Cyber Portal account

### Step 1 - Creating an Account Token

[Log in to the GoodAccess **Control Panel**, and go to **Profile** (top right corner) > **Security** > **Account Tokens**.](https://account.goodaccess.com/security-settings/)

Click **+ Create Token**.

* **Name** - Give the token a name
* **Expiration** - The time period after which the token becomes invalid. If 'Unlimited Expiration' is selected, the token will not expire (not recommended).
* **Token** - Immediately after being generated, you will see the token for a **limited period**. It is important to save the token in a secure place.
* **IP Addresses** - Leave blank

Click **Save**.

<figure><img src="/files/1FGQRffjGwprgikmokA2" alt="Account Tokens section of the GoodAccess Account Panel."><figcaption><p>Account Tokens section of the GoodAccess Account Panel</p></figcaption></figure>

### Step 2 - Creating an integration with Acronis

Log in to the Acronis Portal, and go to **Integrations**.

Search for **GoodAccess**, and click **Configure**.

Enter the token from [Step 1](#step-1-creating-an-account-token), and click **Enable**.

{% hint style="info" %}
If the token is valid, the integration will be enabled. If not, please [contact us](https://www.goodaccess.com/contact).
{% endhint %}

<figure><img src="/files/j5DMIiO8okqIv7K19E8h" alt="Integrations section of the Acronis Portal."><figcaption><p>Integrations section of the Acronis Portal</p></figcaption></figure>

You have now successfully set up the integration between GoodAccess and Acronis.


# SIEM Integration

Enhance threat visibility with Security Information and Event Management (SIEM) integration for automated log forwarding, policy-driven analysis, and API-triggered incident mitigation.

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

SIEM Integration enables secure and efficient log forwarding to your Security Information and Event Management (SIEM) system for analysis and threat detection. Data is transmitted in 1-minute intervals, ensuring timely delivery and processing. Additionally, our [API Integration](/configuration-guides/features/api-integration) allows SIEM systems to take automated actions, such as blocking users when threats are detected.

## Prerequisites

* A SIEM system that supports the **JSON** log format and can receive logs via **Syslog (UDP, TCP, or TCP with TLS)**.

## Configuration guide

{% hint style="info" %}
Please refer to your SIEM system's documentation for details on port/protocol you should use.
{% endhint %}

[Log in to the GoodAccess **Control Panel**, and go to **Settings** > **SIEM**.](https://app.goodaccess.com/siem/)

Check **Enable SIEM Integration**, and connect your SIEM system.

* **Host** - Enter your SIEM system's Hostname/IP
* **Port** - Specify the port number used for communication
* **Protocol -** Choose between:
  * TCP
    * When using TCP, we strongly recommend enabling encrypted communication via **TLS**. To enable TLS, upload a valid **CA certificate**.
  * UDP
* **Data exported to SIEM** - Choose from:
  * Admin Logs
  * Threat Blocker Logs
  * Device Posture Check Logs
  * Gateway Access Logs

Click **Save**.

<figure><img src="/files/g8m6JhbkGot81ZzHoWoB" alt="SIEM Integration setup wizard."><figcaption><p>SIEM Integration setup wizard</p></figcaption></figure>

You have now successfully set up the integration between GoodAccess and your SIEM system.


# SSO/SCIM

Logging in with a third-party identity provider makes the login process effortless and increases security.

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

You may set up SSO with any provider supporting SAML 2.0.

You can find more detailed information about SCIM and how it helps businesses in our [blog article](https://www.goodaccess.com/blog/what-is-scim).

<table data-view="cards"><thead><tr><th data-card-target data-type="content-ref"></th><th data-hidden></th><th data-hidden></th><th data-hidden></th><th data-hidden data-type="files"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td><a href="/pages/XJeAbnotvId623Honi3B">/pages/XJeAbnotvId623Honi3B</a></td><td></td><td></td><td></td><td></td><td><a href="/files/vAlC0Q6CRHGHMkXdUUJ9">/files/vAlC0Q6CRHGHMkXdUUJ9</a></td></tr><tr><td><a href="/pages/7FcBjZz4uHfFbUiGv85i">/pages/7FcBjZz4uHfFbUiGv85i</a></td><td></td><td></td><td></td><td></td><td><a href="/files/aJ6cqCCge4ub06P46T5p">/files/aJ6cqCCge4ub06P46T5p</a></td></tr><tr><td><a href="/pages/A4HJNhGL2bKBtJUhJIyF">/pages/A4HJNhGL2bKBtJUhJIyF</a></td><td></td><td></td><td></td><td></td><td><a href="/files/3Xtmt7c315VMVBZANl9B">/files/3Xtmt7c315VMVBZANl9B</a></td></tr><tr><td><a href="/pages/nkwxFDqCBnNr0uDTHZLl">/pages/nkwxFDqCBnNr0uDTHZLl</a></td><td></td><td></td><td></td><td></td><td><a href="/files/HOBqLbxXBcUxEOKEDu7M">/files/HOBqLbxXBcUxEOKEDu7M</a></td></tr><tr><td><a href="/pages/U6SWkJI2DayOuQHvBq4j">/pages/U6SWkJI2DayOuQHvBq4j</a></td><td></td><td></td><td></td><td></td><td><a href="/files/WuVJwRtF5jHOLHr3Ad26">/files/WuVJwRtF5jHOLHr3Ad26</a></td></tr><tr><td><a href="/pages/JwWTzCJAyTflcvhFaXi5">/pages/JwWTzCJAyTflcvhFaXi5</a></td><td></td><td></td><td></td><td></td><td><a href="/files/hqW78dO7V4kvO73jIgys">/files/hqW78dO7V4kvO73jIgys</a></td></tr><tr><td><a href="/pages/EmH3UMXGaxHQHpqpkLLn">/pages/EmH3UMXGaxHQHpqpkLLn</a></td><td></td><td></td><td></td><td></td><td><a href="/files/i3CUwnIz3v4PdMAz3Rk5">/files/i3CUwnIz3v4PdMAz3Rk5</a></td></tr><tr><td><a href="/pages/TDd057tjgMjrZ2POoSD6">/pages/TDd057tjgMjrZ2POoSD6</a></td><td></td><td></td><td></td><td></td><td><a href="/files/Jt1VzNF5XKr5weJCbeOy">/files/Jt1VzNF5XKr5weJCbeOy</a></td></tr><tr><td><a href="/pages/THVEYmR5i2XGntl5GQsR">/pages/THVEYmR5i2XGntl5GQsR</a></td><td></td><td></td><td></td><td></td><td><a href="/files/JLWwO1oSVGexaK03Gk9P">/files/JLWwO1oSVGexaK03Gk9P</a></td></tr></tbody></table>


# Auth0

This guide will show you how to integrate GoodAccess with Auth0 SSO.

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

{% hint style="danger" %}
**Remember to grant your users access permissions to GoodAccess. Users without them won't be able to log in.**
{% endhint %}

## Step 1 - Adding a new identity provider

[Log in to the GoodAccess **Control Panel**, and go to **Settings** > **SSO & Identity**.](https://app.goodaccess.com/sso-and-identity/)

Click **+ Add provider**, enter the **Provider name**, choose your **Identity Provider**, and click **Continue**.

## Step 2 - Setting up Single Sign-On with SAML

Log in to the [Auth0 Admin console](https://manage.auth0.com/), go to **Applications** > **Applications**, and click **+ Create Application**.

Give the application a name, select **Native**, and click **Create**.

Go to **Addons**, and open **SAML2**.

<figure><img src="/files/EhlgMUzh1EJAbHaT4QZ9" alt="Auth0 Admin console with key steps to creating a new application."><figcaption><p>Creating a new application</p></figcaption></figure>

<figure><img src="/files/eYWQR540Dbzj4cP6EKLt" alt="Auth0 Admin console with key steps to creating a new application."><figcaption><p>Creating a new application</p></figcaption></figure>

<figure><img src="/files/b8Prsrn49h8xR1xzRtTa" alt="Auth0 Admin console with key steps to opening the SAML2 addon."><figcaption><p>Opening the SAML2 addon</p></figcaption></figure>

### 1. Settings

Go to **Settings**, and copy the details from GoodAccess - **(2) GoodAccess links**.

* **Application Callback URL** - Assertion Consumer Service URL

Copy the below code into **Settings**:

```
{
  "mappings": {
    "email": "email",
    "name": "name"
  },
  "createUpnClaim": false,
  "passthroughClaimsWithNoMapping": false,
  "mapUnknownClaimsAsIs": false,
  "mapIdentities": true
}
```

Return to GoodAccess, and click **Continue**.

Return to Auth0, scroll down to the bottom of the page, and click **Enable**.

<figure><img src="/files/viVWJ3fdLdKL9OT7zc0y" alt="Auth0 Admin console with key steps to setting up the &#x22;Settings&#x22;."><figcaption><p>Setting up the Settings</p></figcaption></figure>

### 2. Usage

Go to **Usage**, download the **Identity Provider Metadata**, and open the file in a text editor (e.g. Notepad).

Copy the details to GoodAccess - **(3) Identity Provider links**, and click **Continue**.

* **Sign in URL** - Identity Provider Login URL
* **Entity ID** - Issuer
* **X509 signing certificate** - Copy the certificate from the text editor

Click **Submit** to finish the configuration.

<figure><img src="/files/VkwXkP8lVcqTvovFKIZw" alt="Auth0 Admin console with key steps to setting up the &#x22;Usage&#x22;."><figcaption><p>Setting up the Usage</p></figcaption></figure>

<figure><img src="/files/2YH3SsWF3aclkgJeEZxY" alt="Notepad with highlighted X509 signin certificate."><figcaption><p>Copying the certificate from the Notepad</p></figcaption></figure>

You have now successfully set up your Auth0 SSO with GoodAccess.


# Cisco Duo

This guide will show you how to integrate GoodAccess with Cisco Duo SSO.

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

{% hint style="danger" %}
**Remember to grant your users access permissions to GoodAccess. Users without them won't be able to log in.**
{% endhint %}

## Prerequisites

* Enabled [**Duo Single Sign-On**](https://duo.com/docs/sso#enable-duo-single-sign-on)
* Configured [**Authentication Source**](https://duo.com/docs/sso#configure-your-authentication-source)

## Step 1 - Adding a new identity provider

[Log in to the GoodAccess **Control Panel**, and go to **Settings** > **SSO & Identity**.](https://app.goodaccess.com/sso-and-identity/)

Click **+ Add provider**, enter the **Provider name**, choose your **Identity Provider**, and click **Continue**.

## Step 2 - Setting up Single Sign-On with SAML

Log in to the [Duo Admin Panel](https://admin.duosecurity.com/), and go to **Applications** > **Protect an Application**.

Search for **Generic SAML Service Provider**, and click **Protect**.

<figure><img src="/files/uhQa8qJb8HEThsjjAqIO" alt="Duo Admin Panel with key steps to protecting a new application."><figcaption><p>Protecting a new application</p></figcaption></figure>

### 1. Metadata

Click **Download certificate**, and open the file in a text editor (e.g. Notepad).

Copy the details to GoodAccess - **(3) Identity Provider links**.

* **Sign in URL** - Single Sign-On URL
* **Entity ID** - Entity ID
* **X509** **signing certificate** - Copy the certificate from the text editor

<figure><img src="/files/yXnsg3PochRQacjd0Jrh" alt="Duo Admin Panel with key steps to setting up the Identity Provider details."><figcaption><p>Setting up the Identity Provider details</p></figcaption></figure>

### 2. Service Provider

Copy the details from GoodAccess - **(2) GoodAccess links**.

* **Metadata Discovery** - None (manual input)
* **Entity ID** - Entity ID
* **ACS URL** - Assertion Consumer Service URL
* **Service Provider Login URL** - Login URL
* **Default Relay State** - Relay State

<figure><img src="/files/Fpyr7FuqFmslypZFIvA7" alt="Duo Admin Panel with key steps to setting up the Service Provider details."><figcaption><p>Setting up the Service Provider details</p></figcaption></figure>

### 3. SAML Response

* **NameID format** - urn:oasis:names:tc:**SAML:2.0**:nameid-format:**persistent**
* **NameID attribute** - \<Email Address>
* **Signature algorithm** - SHA256
* **Signing options** - Sign response

#### Map atttibutes

| IdP Attribute    | SAML Response Attribute |
| ---------------- | ----------------------- |
| \<Email Address> | email                   |
| \<Username>      | name                    |

Scroll down to the bottom of the page and click **Save**.

Return to GoodAccess, skip the next step, and click **Submit**.

<figure><img src="/files/ar5u8MuLUGRtLak3TkNi" alt="Duo Admin Panel with key steps to setting up the SAML Response details."><figcaption><p>Setting up the SAML Response details</p></figcaption></figure>

You have now successfully set up your Cisco Duo SSO with GoodAccess.


# Google Workspace

This guide will show you how to integrate GoodAccess with Google Workspace SSO/SCIM.

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

{% hint style="danger" %}
**Remember to** [**grant your Google users access permissions**](#step-4-managing-user-access) **to GoodAccess. Users without them won't be able to log in.**
{% endhint %}

## Step 1 - Adding a new identity provider

[Log in to the GoodAccess **Control Panel**, and go to **Settings** > **SSO & Identity**.](https://app.goodaccess.com/sso-and-identity/)

Click **+ Add provider**, enter the **Provider name**, choose your **Identity Provider**, and click **Continue**.

## Step 2 - Setting up Single Sign-On with SAML

Log in to the [Google Admin console](https://admin.google.com/), and go to [Apps > Web and mobile apps](https://admin.google.com/ac/apps/unified).

Click **Add App**, and **Add custom SAML app**.

<figure><img src="/files/nbmpBSixE5yEz9plksoV" alt="Google Admin console with key steps to adding a new custom SAML application."><figcaption><p>Adding a new custom SAML application</p></figcaption></figure>

### 1.  App details

Give the appplication a name, upload a logo, and click **Continue**.

<figure><img src="/files/1iuTBqYFxX6tVndq2Lrb" alt="Google Admin console with key steps to setting up the &#x22;App details&#x22;."><figcaption><p>Setting up the App details</p></figcaption></figure>

### 2. Google Identity Provider details

Copy the details to GoodAccess - **(3) Identity Provider links**, and click **Continue**.

* **Sign in URL** - SSO URL
* **Entity ID** - Entity ID
* **X509 signing certificate** - Certificate

<figure><img src="/files/sgoRDcYSl6biupCTD5tk" alt="Google Admin console with key steps to setting up the &#x22;Google Identity Provider details&#x22;."><figcaption><p>Setting up the Google Identity Provider details</p></figcaption></figure>

### 3. Service provider details

Copy the details from GoodAccess - **(2) GoodAccess links**, and click **Continue**.

* **ACS URL** - Assertion Consumer Service URL
* **Entity ID** - Entity ID
* **Start URL** - Login URL
* **Name ID format** - UNSPECIFIED
* **Name ID** - Basic Information > Primary email

<figure><img src="/files/wTis4wiZXmYsjkKbms9y" alt="Google Admin console with key steps to setting up the &#x22;Service provider details&#x22;."><figcaption><p>Setting up the Service provider details</p></figcaption></figure>

### 4. Attribute mapping

Click **ADD MAPPING**, and add two attributes as follows:

| Google Directory attributes | App attributes           |
| --------------------------- | ------------------------ |
| Primary email               | "email" (without quotes) |
| First name                  | "name" (without quotes)  |

Click **Finish** to confirm your settings.

<figure><img src="/files/tdVtUQvt8u8p5GwazY6A" alt="Google Admin console with key steps to setting up the &#x22;Attribute mapping&#x22;."><figcaption><p>Setting up Attribute mapping</p></figcaption></figure>

{% hint style="info" %}
If you want to set up SCIM, save the **Provider ID** for the next step, and click **Submit**.

If you don't want to set up SCIM, skip the next step in GoodAccess, and click **Submit** to finish the configuration.
{% endhint %}

You have now successfully set up your Google Workspace SSO with GoodAccess.

## Step 3 (optional) - Setting up SCIM using an API

Since SCIM for Google Workspace is not currently supported for public use, it's necessary to use a combination of Google Apps Script and GoodAccess API Integration for complete user management.

{% hint style="info" %}
The user provisioning time period depends on the [Trigger](#id-4.-creating-a-trigger-for-the-script) settings (default is 1 hour).
{% endhint %}

### 1. Creating a new API Integration

[In the GoodAccess **Control Panel**, go to **Settings** > **API Integration**.](https://app.goodaccess.com/api-integration/)

Create a new [API Integration](/configuration-guides/features/api-integration) with the scopes specified below, and securely save the **Token** for the next step.

* Members
  * Create
  * Update
  * Remove
* Groups
  * Create
  * Update
  * Remove

### 2. Creating the Google Apps Script

Go to [Google Apps Script](https://script.google.com/home/start), and click **+** **New Project**.

Click **+** to **add a** **service**, and add **Admin SDK API**.

<figure><img src="/files/SeKZ8J7TwpwCMfEB7o7w" alt="Google Apps Script project with key steps to adding Admin SDK API service."><figcaption><p>Adding Admin SDK API service</p></figcaption></figure>

Delete any placeholder code in the editor (e.g., `function myFunction() {...}`). Copy the following code snippet and paste it into the code editor:

{% hint style="danger" %}
**Configuration Required**

Before running the script, you must update the configuration variables at the top of the file:

1. **Mandatory replacements**

Replace these placeholders with your specific values:

* `<DOMAIN_NAME>` - The verified domain of your organization in Google Workspace (e.g. goodaccess.com).
* `<PROVIDER_ID>` - The Provider ID you obtained in the final step of the GoodAccess SSO configuration form.
* `<TOKEN>` - The Token you obtained when creating the GoodAccess API Integration.

2. **Define who gets synced (Sync Group)**

**How it works**: *Only* users belonging to the designated Sync Group are provisioned into GoodAccess. However, all other Google Workspace groups (unless excluded below) are still synchronized, and your imported users will automatically be assigned to them based on their Google Workspace memberships.

You have two options to set up the Sync Group:

* **Use the default setup**: Create a group in your Google Admin console named exactly `sync-to-goodaccess` and add the users you want to provision.
* **Use an existing group**: If you already have a group for this purpose (e.g., `vpn-users`), change the prefix in the `SYNC_GROUP_EMAIL` variable. For example, change `'sync-to-goodaccess@'` to `'vpn-users@'` .

3. **Optional filtering**

Review and modify this list to exclude specific groups from synchronization:

* `EXCLUDED_GROUPS` - Defines groups to ignore. You can use specific names (e.g., `ga-example`) or naming patterns with wildcards (e.g., `gcp-*` excludes any group starting with "gcp-").
  {% endhint %}

```php
/**
 * CONFIGURATION
 */
const DOMAIN            = '<DOMAIN_NAME>';       // The verified domain of your organization in Google Workspace (e.g. goodaccess.com)
const PROVIDER_ID       = '<PROVIDER_ID>';       // The Provider ID you obtained in the final step of the GoodAccess SSO configuration form
const INTEGRATION_TOKEN = '<TOKEN>';             // The Token you obtained when creating the GoodAccess API Integration

/**
 * SYNC GROUP:
 * Only users belonging to this specific group will be synchronized to GoodAccess.
 * Example: 'sync-to-goodaccess@yourdomain.com'
 */
const SYNC_GROUP_EMAIL  = 'sync-to-goodaccess@' + DOMAIN;

/**
 * EXCLUDED GROUPS:
 * List of group names or patterns to ignore. Supports '*' as a wildcard.
 * Examples: 'gcp-*', 'internal-testing', '*-temp'
 */
const EXCLUDED_GROUPS = [
  "gcp-*"
];

/**
 * MAIN FUNCTION
 * Orchestrates the synchronization process.
 */
function syncUsers() {
  // 1. Get IDs of all users who are members of the mandatory sync group
  const authorizedUserIds = getAuthorizedUserIds();
  
  if (authorizedUserIds.size === 0) {
    Logger.log('No users found in the sync group: ' + SYNC_GROUP_EMAIL);
    return;
  }

  // 2. Fetch detailed info for those authorized users
  const users = getAllAuthorizedUsers(authorizedUserIds);
  
  // 3. Fetch all groups and their members (filtered by exclusion list and authorization)
  const groups = getFilteredGroups(authorizedUserIds);

  // 4. Send data to GoodAccess
  sendRequest(users, groups);
}

/**
 * Retrieves a Set of user IDs that belong to the "sync-to-goodaccess" group.
 */
function getAuthorizedUserIds() {
  const authorizedIds = new Set();
  let pageToken;

  try {
    do {
      const response = AdminDirectory.Members.list(SYNC_GROUP_EMAIL, {
        pageToken: pageToken,
        maxResults: 200 // Maximum allowed by API for members
      });

      if (response.members) {
        response.members.forEach(member => {
          // We only care about users, not nested groups or customers
          if (member.type === 'USER') {
            authorizedIds.add(member.id);
          }
        });
      }
      pageToken = response.nextPageToken;
    } while (pageToken);
  } catch (e) {
    Logger.log('Error fetching sync group members: ' + e.message);
  }

  return authorizedIds;
}

/**
 * Fetches user details (email, name) but only for users in the authorized set.
 */
function getAllAuthorizedUsers(authorizedUserIds) {
  const members = {};
  let pageToken;

  do {
    const response = AdminDirectory.Users.list({
      domain: DOMAIN,
      pageToken: pageToken,
      maxResults: 500 // Increased limit for better performance
    });

    if (response.users) {
      response.users.forEach(user => {
        // Only include user if they are in the sync group
        if (authorizedUserIds.has(user.id)) {
          members[user.id] = {
            email: user.primaryEmail,
            name: user.name.fullName
          };
        }
      });
    }
    pageToken = response.nextPageToken;
  } while (pageToken);

  return members;
}

/**
 * Fetches all domain groups, filters them by exclusion patterns,
 * and includes only members who are also in the authorized sync group.
 */
function getFilteredGroups(authorizedUserIds) {
  const groups = {};
  let pageToken;

  do {
    const response = AdminDirectory.Groups.list({
      domain: DOMAIN,
      pageToken: pageToken,
      maxResults: 200
    });

    if (response.groups) {
      response.groups.forEach(group => {
        const groupEmail = group.getEmail();
        const groupName = groupEmail.split("@")[0];

        // Skip if group matches any excluded pattern
        if (isExcluded(groupName)) {
          return;
        }

        const members = getGroupMembers(groupEmail, authorizedUserIds);
        
        // Only add group if it has at least one authorized member
        if (members.length > 0) {
          groups[group.id] = {
            name: groupName,
            members: members
          };
        }
      });
    }
    pageToken = response.nextPageToken;
  } while (pageToken);

  return groups;
}

/**
 * Gets members of a specific group, filtered by the authorized user list.
 */
function getGroupMembers(groupEmail, authorizedUserIds) {
  let members = [];
  let pageToken;

  do {
    const response = AdminDirectory.Members.list(groupEmail, {
      pageToken: pageToken,
      maxResults: 200
    });

    if (response.members) {
      response.members.forEach(member => {
        // Only add member if they are a user and exist in the authorized sync group
        if (member.id != null && authorizedUserIds.has(member.id)) {
          members.push(member.id);
        }
      });
    }
    pageToken = response.nextPageToken;
  } while (pageToken);

  return members;
}

/**
 * Checks if a group name matches any of the excluded patterns (supports *).
 */
function isExcluded(groupName) {
  return EXCLUDED_GROUPS.some(pattern => {
    const regexPattern = pattern.replace(/\*/g, '.*');
    const regex = new RegExp("^" + regexPattern + "$", "i");
    return regex.test(groupName);
  });
}

/**
 * Sends the collected data to the GoodAccess API.
 */
function sendRequest(users, groups) {
  const apiUrl = 'https://integration.goodaccess.com/api/v2/google-workspace/sync-users';
  
  const payload = {
    'domain': DOMAIN,
    'users': users,
    'groups': groups,
    'provider_id': PROVIDER_ID
  };
  
  const options = {
    'method': 'post',
    'contentType': 'application/json',
    'headers': {
      'authorization': INTEGRATION_TOKEN
    },
    'payload': JSON.stringify(payload),
    'muteHttpExceptions': true
  };
  
  try {
    const response = UrlFetchApp.fetch(apiUrl, options);
    if (response.getResponseCode() == 200) {
      Logger.log('The API request was successfully sent.');
    } else {
      Logger.log("Error sending API request. Code: " + response.getResponseCode() + " Body: " + response.getContentText());
    }
  } catch (e) {
    Logger.log("Critical error in UrlFetchApp: " + e.message);
  }
}
```

### 3. Authorizing the script

Before automating the synchronization, you must save the script and run it manually once to grant the necessary permissions.

Click the **Save project** icon, and ensure the function **syncUsers** is selected.

Click the **Run** button, and click **Review permissions**.

{% hint style="danger" %}
You might see a screen asking to "Select what \[Project Name] can access".

Ensure you **check the "Select All" box** to grant all the required permissions (view groups, see users, connect to external service).

If you instead see a "Google hasn't verified this app" warning, click **Advanced** and then **Go to \[Project Name] (unsafe)**.
{% endhint %}

Click **Continue** or **Allow**.

Wait for the execution log to start. If configured correctly, you should see "Execution started" and "Execution completed" at the bottom of the screen.

<figure><img src="/files/XFpGL83jkCxUcN63spf9" alt="Google Apps Script project with key steps to authorizing the script."><figcaption><p>Authorizing the script</p></figcaption></figure>

### 4. Creating a trigger for the script

In the left menu, go to **Triggers**, and click **+ Add Trigger**.

* Choose which function to run - **syncUsers**
* Choose which deployment should run - **Head**
* Select event source - **Time-driven**
* Select type of time based trigger - **Hour timer**
* Select hour interval - **Every hour**

Click **Save**.

<figure><img src="/files/q7owtZk4a1tvksqDjnMN" alt="Google Apps Script project with key steps to creating a trigger for the script."><figcaption><p>Creating a trigger for the script</p></figcaption></figure>

You have now successfully set up Google Workspace SCIM with GoodAccess.

## Step 4 - Managing user access

In the application click **User access**.

Choose who should have access, select **ON**, and click **Save**.

<div><figure><img src="/files/4CTVj9iHeVRXtW5vtMqN" alt="Google Admin console with key steps to managing user access."><figcaption><p>Managing user access</p></figcaption></figure> <figure><img src="/files/GsZYgdilvliu6XtaABm5" alt="Google Admin console with key steps to managing user access."><figcaption><p>Managing user access</p></figcaption></figure></div>


# JumpCloud

This guide will show you how to integrate GoodAccess with JumpCloud SSO.

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

{% hint style="danger" %}
**Remember to** [**grant your JumpCloud users access permissions**](#step-3-managing-user-access) **to GoodAccess. Users without them won't be able to log in.**
{% endhint %}

## Step 1 - Adding a new identity provider

[Log in to the GoodAccess **Control Panel**, and go to **Settings** > **SSO & Identity**.](https://app.goodaccess.com/sso-and-identity/)

Click **+ Add provider**, enter the **Provider name**, choose your **Identity Provider**, and click **Continue**.

## Step 2 - Setting up Single Sign-On with SAML

Log in to the [JumpCloud Admin console](https://console.jumpcloud.com/login/admin), and go to **User Authentication** > **SSO Applications**.

Click **+ Add New Application**, select **Custom Application**, and click **Next**.

Select **Manage Single Sign-On (SSO)** > **Configure SSO with SAML**, and click **Next**.

Give the application a name, and click **Save Application**.

Click **Configure Application**.

<figure><img src="/files/4oxNdSz2ffmqdgbwRpId" alt="JumpCloud Admin console with key steps to adding a new custom SAML application."><figcaption><p>Adding a new custom SAML application</p></figcaption></figure>

<figure><img src="/files/JuqgpW0dJ2BQCDKCTv0B" alt="JumpCloud Admin console with key steps to adding a new custom SAML application."><figcaption><p>Adding a new custom SAML application</p></figcaption></figure>

<figure><img src="/files/hF72pSAoFcDhMtjzmhgU" alt="JumpCloud Admin console with key steps to adding a new custom SAML application."><figcaption><p>Adding a new custom SAML application</p></figcaption></figure>

### 1. Single Sign-On Configuration

Copy the details from GoodAccess - **(2) GoodAccess links**.

* **SP Entity ID** - Entity ID
* **ACS URLs** - Assertion Consumer Service URL
* **SAMLSubject NameID** - email
* **SAMLSubject NameID Format** - urn:oasis:names:tc:**SAML:2.0**:nameid-format:**unspecified**
* **Signature Algorithm** - RSA-SHA256
* **Default Relay State** - Relay State
* **Login URL** - Login URL

Return to GoodAccess, and click **Continue**.

Return to JumpCloud.

### 2. Attributes

Click **add attribute**, and add the following attribute:

| Service Provider Attribute Name | JumpCloud Attribute Name |
| ------------------------------- | ------------------------ |
| "email" (without quotes)        | email                    |

### 3. Setting up GoodAccess

Click **Copy Metadata URL**, and open the URL in a new tab.

Copy the details to GoodAccess - **(3) Identity Provider links**, and click **Continue**.

* **Sign in URL** - IDP URL
* **Entity ID** - IdP Entity ID (choose a name)
* **X509 signing certificate** - Copy the certificate from the new tab

Return to JumpCloud, and click **Save**.

<figure><img src="/files/63XPq1CrJqbScJ2uznQ4" alt="JumpCloud Admin console with key steps to setting up Single Sign-On."><figcaption><p>Setting up Single Sign-On</p></figcaption></figure>

<figure><img src="/files/JR9sXGU5XcxIM4FNI7sj" alt="JumpCloud Admin console with key steps to setting up Single Sign-On."><figcaption><p>Setting up Single Sign-On</p></figcaption></figure>

<figure><img src="/files/Zze1788QYBOXTgOTFHNk" alt="XML file in web browser highlighting the X509 signing certificate."><figcaption><p>Copying the certificate from the new tab</p></figcaption></figure>

{% hint style="info" %}
If you don't want to setup SCIM, skip the next step in GoodAccess, and click **Submit** to finish the configuration.
{% endhint %}

You have now successfully set up your JumpCloud SSO with GoodAccess.

## Step 3 (optional) - Setting up SCIM

In the application, go to **Identity Management**.

Copy the **URL** and **Token** from GoodAccess - **(4) User provisioning (SCIM)**.

* **API Type** - SCIM API
* **SCIM Version** - SCIM 2.0
* **Base URL** - URL
* **Token Key** - Token
* **Test User Email** - Enter any email address (e.g. <test@test.com>)

Return to GoodAccess, and click **Submit**.

Return to JumpCloud, and click **Test Connection**.

Click **Activate**, and **Save** to finish the configuration.

<figure><img src="/files/E8FKnOi7xk0IHy2h59FR" alt="JumpCloud Admin console with key steps to setting up SCIM."><figcaption><p>Setting up SCIM</p></figcaption></figure>

{% hint style="info" %}
The whole provisioning process will take around **20 minutes** to complete depending on the number of members and groups being added.
{% endhint %}

You have now successfully set up JumpCloud SCIM with GoodAccess.

## Step 4 - Managing user access

In the application, go to **User Groups**.

Choose who should have access, and click **Save**.

<figure><img src="/files/pAvPxEjhLeARLONa5wvN" alt="JumpCloud Admin console with key steps to managing user access."><figcaption><p>Managing user access</p></figcaption></figure>


# Microsoft Entra ID

This guide will show you how to integrate GoodAccess with Microsoft Entra ID SSO/SCIM.

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

{% hint style="danger" %}
**Remember to** [**grant your Azure users access permissions**](#step-4-managing-user-access) **to GoodAccess. Users without them won't be able to log in.**
{% endhint %}

## Step 1 - Adding a new identity provider

[Log in to the GoodAccess **Control Panel**, and go to **Settings** > **SSO & Identity**.](https://app.goodaccess.com/sso-and-identity/)

Click **+ Add provider**, enter the **Provider name**, choose your **Identity Provider**, and click **Continue**.

## Step 2 - Setting up Single Sign-On with SAML

Log in to the [Azure Portal](https://portal.azure.com/), and go to **Enterprise applications** (you can use the searchbar).

Click **+ New application**, and **+ Create your own application**.

Give the application a name, choose **Integrate any other application you don't find in the gallery (Non-gallery)**, and click **Create**.

In your new application go to **Single Sign-On** > **SAML**.

<div><figure><img src="/files/Cef3q7B5iXkZOcxO8C7D" alt="Azure Portal with key steps to creating a new enterprise application."><figcaption><p>Creating a new enterprise application</p></figcaption></figure> <figure><img src="/files/bO6CNFMKUNwAZLO0t8kN" alt="Azure Portal with key steps to creating a new enterprise application."><figcaption><p>Creating a new enterprise application</p></figcaption></figure></div>

<figure><img src="/files/7v5sp3EotLe1xQrpM4eR" alt="Azure Portal with key steps to selecting SAML as a single sign-on method for the enterprise application."><figcaption><p>Selecting SAML as a single sign-on method</p></figcaption></figure>

### 1. Basic SAML Configuration

Click **Edit** to open Basic SAML Configuration.

Copy the details from GoodAccess - **(2) GoodAccess links**.

* **Identifier** - Entity ID
* **Reply URL** - Assertion Consumer Service URL
* **Sign on URL** - Login URL
* **Relay State** - Relay State

Return to GoodAccess, and click **Continue**.

Return to Azure, and click **Save**.

<div><figure><img src="/files/f0gnNJOpHMh3J85HhW3W" alt="Azure Portal with key steps to opening the &#x22;Basic SAML Configuration&#x22;."><figcaption><p>Opening the Basic SAML Configuration</p></figcaption></figure> <figure><img src="/files/BCpS327JBiHPkyPFdnHU" alt="Azure Portal with key steps to setting up the &#x22;Basic SAML Configuration&#x22;."><figcaption><p>Setting up the Basic SAML Configuration</p></figcaption></figure></div>

### 2. Attributes & Claims

Click **Edit** to open Attributes & Claims.

Under the Additional claims section click on the record with the value **user.userprincipalname** and edit it as follows:

* **Name** - "name" (without quotes)
* **Namespace** - Delete pre-filled URL

Click **Save**.

Then, still in the Additional claims section click on the record with the value **user.mail** and edit it as follows:

* **Name** - "email" (without quotes)
* **Namespace** - Delete pre-filled URL
* **Source attribute** - user.userprincipalname

Don't forget to **Save**.

<figure><img src="/files/cvZjOMAc82UzkI01xpqq" alt="Azure Portal with key steps to setting up the &#x22;Attributes &#x26; Claims&#x22;."><figcaption><p>Setting up Attributes &#x26; Claims</p></figcaption></figure>

<div><figure><img src="/files/OI12MRiy1h1jwZ3Jyzxn" alt="Azure Portal with key steps to managing the &#x22;user.userprincipalname&#x22; claim."><figcaption><p>Managing the "user.userprincipalname" claim</p></figcaption></figure> <figure><img src="/files/bZoT874YZJOACc2U1bc1" alt="Azure Portal with key steps to managing the &#x22;user.mail&#x22; claim."><figcaption><p>Managing the "user.mail" claim</p></figcaption></figure></div>

### 3. SAML Certificates

Download the **Certificate (Base64)**, and open the file in a text editor (e.g. Notepad).

<figure><img src="/files/7BgO9qZn5ZYSH50SB6CV" alt="Azure Portal with key steps to downloading the certificate."><figcaption><p>Downloading the certificate</p></figcaption></figure>

### 4. Set up GoodAccess

Copy the details to GoodAccess - **(3) Identity Provider links**, and click **Continue**.

* **Sign in URL** - Login URL
* **Entity ID** - Microsoft Entra ID Identifier
* **X509 signing certificate** - Copy the certificate from the text editor

<figure><img src="/files/dwCeO8wSxZP0rMlFKRn1" alt="Azure Portal with key steps to setting up GoodAccess."><figcaption><p>Setting up GoodAccess</p></figcaption></figure>

{% hint style="info" %}
If you don't want to setup SCIM, skip the next step in GoodAccess, and click **Submit** to finish the configuration.
{% endhint %}

You have now successfully set up your Microsoft Entra ID SSO with GoodAccess.

## Step 3 (optional) - Setting up SCIM

In the application, go to **Provisioning** > **Provisioning**, and set **Provisioning mode** to **Automatic**.

Expand **Admin Credentials,** and copy the **URL** and **Token** from GoodAccess - **(4) User provisioning (SCIM)**.

Return to GoodAccess, and click **Submit**.

Return to Azure, and click **Test Connection**, and **Save** to confirm your settings.

<figure><img src="/files/rtBOrOT0o8CzVWl5tTja" alt="Azure Portal with key steps to setting up SCIM."><figcaption><p>Setting up SCIM</p></figcaption></figure>

### 1. Attribute Mapping

Open **Mappings**, and select **Provision Microsoft Entra ID Users**.

Here, make sure that only the following four attributes are listed:

* userName
* active
* displayName
* externalId

If there are other attributes except these four, **Delete** them to prevent provisioning issues.

Don't forget to **Save**.

<div data-full-width="false"><figure><img src="/files/ZRH4S8qKMaMXaa1hzcli" alt="Azure Portal with key steps to setting up the &#x22;Attribute Mapping&#x22;." width="563"><figcaption><p>Setting up the Attribute Mapping</p></figcaption></figure> <figure><img src="/files/M7mxBEKCkyIXsXQsGrFL" alt="Azure Portal with key steps to setting up the &#x22;Attribute Mapping&#x22;." width="563"><figcaption><p>Setting up the Attribute Mapping</p></figcaption></figure></div>

### 2. Starting the provisioning

{% hint style="danger" %}
Users created via **Provisioning on demand** may be skipped by Azure during future automatic provisioning.

**We strongly recommend avoiding this function.**

If you have already created users this way, click the **Restart provisioning** button to restore synchronization for all users.
{% endhint %}

Go to **Overview**, and click **Start provisioning**.

<figure><img src="/files/SYYSclackBNCCuXnzc1t" alt="Azure Portal with key steps to starting the provisioning."><figcaption><p>Starting the provisioning</p></figcaption></figure>

{% hint style="info" %}
The whole provisioning process will take around **20 minutes** to complete depending on the number of members and groups being added.
{% endhint %}

You have now successfully set up Microsoft Entra ID SCIM with GoodAccess.

## Step 4 - Managing user access

In the application, go to **Users and groups**, and click **+ Add user/group**.

Choose who should have access, and click **Assign**.

<figure><img src="/files/qAsYuXx9LLpKak6HnFyB" alt="Azure Portal with key steps to managing user access."><figcaption><p>Managing user access</p></figcaption></figure>


# Okta

With this guide you will learn how to integrate GoodAccess with Okta SSO/SCIM.

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

{% hint style="danger" %}
**Remember to** [**grant your Okta users access permissions**](#step-4-managing-user-access) **to GoodAccess. Users without them won't be able to log in.**
{% endhint %}

## Step 1 - Adding a new identity provider

[Log in to the GoodAccess **Control Panel**, and go to **Settings** > **SSO & Identity**.](https://app.goodaccess.com/sso-and-identity/)

Click **+ Add provider**, enter the **Provider name**, choose your **Identity Provider**, and click **Continue**.

## Step 2 - Setting up Single Sign-On with SAML

Log in to the Okta Admin console, and go to **Applications** > **Applications**.

Click **Create App Integration**, select **SAML 2.0**, and click **Next**.

<div><figure><img src="/files/5Ctgwp336lYRH7bQCdmA" alt="Okta Admin console with key steps to creating a new application integration."><figcaption><p>Creating a new application integration</p></figcaption></figure> <figure><img src="/files/T6mkUm516OtvX29O4r5N" alt="Okta Admin console with key steps to selecting SAML 2.0 as a sign-in method for the application integration."><figcaption><p>Selecting SAML 2.0 as a sign-in method</p></figcaption></figure></div>

### 1. General Settings

Give the application a name, and click **Next**.

<figure><img src="/files/XAv4GTwLEU7b3VA5ZYzn" alt="Okta Admin console with key steps to setting up the &#x22;General Settings&#x22;."><figcaption><p>Setting up the General Settings</p></figcaption></figure>

### 2. Configure SAML

Copy the details from GoodAccess - **(2) GoodAccess links**.

#### General

* **Single Sign-On URL** - Assertion Consumer Service URL
* **Audience URI (SP Entity ID)** -  Entity ID
* **Default RelayState** - Relay State
* **Name ID format** - Unspecified
* **Application username** - Email

#### **Attribute Statements**

| Name                     | Name format | Value      |
| ------------------------ | ----------- | ---------- |
| "email" (without quotes) | Unspecified | user.email |

Return to GoodAccess, and click **Continue**.

Return to Okta, and click **Next**.

<figure><img src="/files/jWoiAyuhxjtyi0ns9bO0" alt="Okta Admin console with key steps to configuring SAML."><figcaption><p>Configuring SAML</p></figcaption></figure>

### 3. Feedback

Choose one of the **Feedback** options, and click **Finish**.

### 4. Setting up GoodAccess

In the application go to **Sign** **On** > **SAML 2.0**, and click **More details**.

Copy the details to GoodAccess - **(3) Identity Provider links**, and click **Continue**.

* **Sign in URL** - Sign on URL
* **Entity ID** - Issuer
* **X509** **signing certificate** - Signing Certificate

<figure><img src="/files/9QKZl7sNhRT0F4bdmMb0" alt="Okta Admin console with key steps to setting up GoodAccess."><figcaption><p>Setting up GoodAccess</p></figcaption></figure>

{% hint style="info" %}
If you don't want to setup SCIM, skip the next step in GoodAccess, and click **Submit** to finish the configuration.
{% endhint %}

You have now successfully set up your Okta SSO with GoodAccess.

## Step 3 (optional) - Setting up SCIM

In the application, go to **General** > **App Settings**, and click **Edit**.

Select **SCIM**, and click **Save**.

<figure><img src="/files/daWdSPT21iFrOktA1wVm" alt="Okta Admin console with key steps to enabling SCIM."><figcaption><p>Enabling SCIM</p></figcaption></figure>

### 1. SCIM Connection

Go to **Provisioning** > **Integration**, and click **Edit**.

Copy the **URL** and **Token** from GoodAccess - **(4) User provisioning (SCIM)**.

* **SCIM connector base URL** - URL
* **Unique identifier field for users** - "email" (without quotes)
* **Supported provisioning actions**
  * Push New Users
  * Push Profile Updates
  * Push Groups
* **Authentication Mode** - HTTP Header
* **Authorization** - Token

Return to GoodAccess, and click **Submit**.

Return to Okta, and click **Save**.

<figure><img src="/files/vgWyfWNsprLyhieMeBzt" alt="Okta Admin console with key steps to setting up SCIM connection."><figcaption><p>Setting up SCIM connection</p></figcaption></figure>

### 2. Provisioning to App

Go to **Provisioning** > **To App**, and click **Edit**.

**Enable**:

* Create Users
* Update User Attributes
* Deactivate Users

Click **Save** to finish the configuration.

<figure><img src="/files/ebhRctVqCPdZxlpp4h5a" alt="Okta Admin console with key steps to setting up provisioning to app."><figcaption><p>Setting up provisioning to app</p></figcaption></figure>

### 3. (optional) Adding groups to provisioning

Go to **Push Groups**, and click **+ Push Groups** > **Find groups by name/rule**.&#x20;

Find the desired group, and click **Save**.

<figure><img src="/files/gAm4IFsxyBZ2Oxadv6Nk" alt="Okta Admin console with key steps to adding groups to provisioning."><figcaption><p>Adding groups to provisioning</p></figcaption></figure>

{% hint style="info" %}
The whole provisioning process will take around **20 minutes** to complete depending on the number of members and groups being added.
{% endhint %}

You have now successfully set up your Okta SCIM with GoodAccess.

## Step 4 - Managing user access

In the application, go to **Assigments**, and click **Assign** > **Assign to People/Groups**.

Choose who should have access, and click **Done**.

<div><figure><img src="/files/fSkmW4URmLSt1rFWu25V" alt="Okta Admin console with key steps to managing user access."><figcaption><p>Managing user access</p></figcaption></figure> <figure><img src="/files/jWK7ETCgXFbHap40uBay" alt="Okta Admin console with key steps to managing user access."><figcaption><p>Managing user access</p></figcaption></figure></div>


# OneLogin

This guide will show you how to integrate GoodAccess with OneLogin SSO/SCIM.

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

{% hint style="danger" %}
**Remember to** [**grant your OneLogin users access permissions**](#step-4-managing-user-access) **to GoodAccess. Users without them won't be able to log in.**
{% endhint %}

### Step 1 - Adding a new identity provider <a href="#step-1-adding-a-new-identity-provider" id="step-1-adding-a-new-identity-provider"></a>

[Log in to the GoodAccess **Control Panel**, and go to **Settings** > **SSO & Identity**.](https://app.goodaccess.com/sso-and-identity/)

Click **+ Add provider**, enter the **Provider name**, choose your **Identity Provider**, and click **Continue**.

### Step 2 - Setting up Single Sign-On with SAML <a href="#step-2-setting-up-single-sign-on-with-saml" id="step-2-setting-up-single-sign-on-with-saml"></a>

Log in to the [OneLogin Admin console](https://app.onelogin.com/login), and go to **Applications** > **Applications**.

Click **Add App**, and select **SCIM Provisioner with SAML (SCIM v2 Enterprise, full SAML)** (you can use the searchbar).

Give the application a name, and click **Save**.

<figure><img src="/files/WrIc7sp7jY5sqCvMou0h" alt="OneLogin Admin console with key steps to adding a new custom SAML application."><figcaption><p>Adding a new custom SAML application</p></figcaption></figure>

<figure><img src="/files/l7VU1F4siLWsXLLPW5XG" alt="OneLogin Admin console with key steps to adding a new custom SAML application."><figcaption><p>Adding a new custom SAML application</p></figcaption></figure>

### 1. Configuration

Go to **Configuration**, and copy the details from GoodAccess - **(2) GoodAccess links**.

* **SAML Audience URL** - Entity ID
* **RelayState** - Relay State
* **ACS (Consumer) URL** - Assertion Consumer Service URL
* **Login URL** - Login URL
* **SAML initiator** - OneLogin
* **SAML nameID format** - Email

Leave the rest at default values.

Return to GoodAccess, and click **Continue**.

Return to OneLogin.

<figure><img src="/files/ppFT1aICLU8o6Ru359Zb" alt="OneLogin Admin console with key steps to setting up the &#x22;Configuration&#x22;."><figcaption><p>Setting up the Configuration</p></figcaption></figure>

### 2. Parameters

Go to **Parameters**, and click **( + )**.

* **Name** - "email" (without quotes)
* **Value** - Email
* **Flags** - Check Include in SAML assertion

Click **Save**.

<div><figure><img src="/files/cwfDTeH859cJjC3ZLtfa" alt="OneLogin Admin console with key steps to setting up the &#x22;Parameters&#x22;." width="563"><figcaption><p>Setting up the Parameters</p></figcaption></figure> <figure><img src="/files/StqpNK7fu9NLJ60vpZxh" alt="OneLogin Admin console with key steps to setting up the &#x22;Parameters&#x22;." width="279"><figcaption><p>Setting up the Parameters</p></figcaption></figure></div>

### 3. SSO

Go to **SSO**, and set **SAML Signature Algorithm** to **SHA-256**.&#x20;

Click **Save**, then copy the details to GoodAccess - **(3) Identity Provider links**, and click **Continue**.

* **Sign in URL** - SAML 2.0 Endpoint (HTTP)
* **Entity ID** - Issuer URL
* **X509 signing certificate** - Click **View Details** and copy the certificate

<figure><img src="/files/Ip37PYF46wanZYo6mvpW" alt="OneLogin Admin console with key steps to setting up the &#x22;SSO&#x22;."><figcaption><p>Setting up the SSO</p></figcaption></figure>

{% hint style="info" %}
If you don't want to setup SCIM, skip the next step in GoodAccess, and click **Submit** to finish the configuration.
{% endhint %}

You have now successfully set up your OneLogin SSO with GoodAccess.

## Step 3 (optional) - Setting up SCIM

### 1. API Connection

In the application, go to **Configuration**, and scroll down to the bottom of the page.

Copy the **URL** and **Token** from GoodAccess - **(4) User provisioning (SCIM)**.

Copy the below code into **SCIM JSON Template**:

```
{
  "schemas": [
    "urn:scim:schemas:core:2.0",
    "urn:ietf:params:scim:schemas:extension:enterprise:2.0:User"
  ],
  "userName": "{$user.email}",
  "displayName": "{$user.email}",
  "externalId": "{$user.id}",
  "name": {
    "familyName": "{$user.lastname}",
    "givenName": "{$user.firstname}",
    "formatted": "{$user.display_name}"
  },
  "emails": [{
    "value": "{$user.email}",
    "type": "work",
    "primary": true
  }]
}
```

Return to GoodAccess, and click **Submit**.

Return to OneLogin, click **Save**, and **Enable** to confirm your settings.

<figure><img src="/files/hvhIzJOs5TQNjfH2lo6Y" alt="OneLogin Admin console with key steps to setting up the &#x22;API Connection&#x22;."><figcaption><p>Setting up the API Connection</p></figcaption></figure>

### 2. (optional) Adding groups to provisioning

{% hint style="danger" %}
During our testing, this feature was not supported by the default SCIM connector. However, it is possible the identity provider has implemented it by now.
{% endhint %}

Go to **Parameters**, and open the existing **Groups** parameter. Here, check **Include in User Provisioning**, and click **Save**.

Go to **Provisioning** > **Entitlements**, and click **Refresh**.

<figure><img src="/files/QagtF1K1CWNuLrxv9Wgj" alt="OneLogin Admin console with key steps to adding groups to provisioning." width="479"><figcaption><p>Adding groups to provisioning</p></figcaption></figure>

### 3. Starting the provisioning

Go to **Provisioning**, check **Enable provisioning**, and click **Save**.

<figure><img src="/files/w5ZtDJQz2xXPSCXrIjEz" alt="OneLogin Admin console with key steps to starting the provisioning."><figcaption><p>Starting the provisioning</p></figcaption></figure>

{% hint style="info" %}
The whole provisioning process will take around **20 minutes** to complete depending on the number of members and groups being added.
{% endhint %}

You have now successfully set up OneLogin SCIM with GoodAccess.

## Step 4 - Managing user access

Go to **Access**, choose which roles should have access and click **Save.**

<figure><img src="/files/OfuGK86AacoYBgmarPeZ" alt="OneLogin Admin console with key steps to managing user access."><figcaption><p>Managing user access</p></figcaption></figure>


# Ping Identity

This guide will show you how to integrate GoodAccess with Ping Identity SSO/SCIM.

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

{% hint style="danger" %}
**Remember to** [**grant your Ping Identity users access permissions**](#step-3-managing-user-access) **to GoodAccess. Users without them won't be able to log in.**
{% endhint %}

## Step 1 - Adding a new identity provider

[Log in to the GoodAccess **Control Panel**, and go to **Settings** > **SSO & Identity**.](https://app.goodaccess.com/sso-and-identity/)

Click **+ Add provider**, enter the **Provider name**, choose your **Identity Provider**, and click **Continue**.

## Step 2 - Setting up Single Sign-On with SAML

Log in to the Ping Identity Admin console, go to **Applications** > **Applications**, and click **(+)**.

Give the application a name, select **SAML Application**, and click **Configure**.

Select **Manually Enter**, and copy the details from GoodAccess - **(2) GoodAccess links**.

* **ACS URLs** - Assertion Consumer Service URL
* **Entity ID** - Entity ID

Return to GoodAccess, and click **Continue**.

Return to Ping Identity, and click **Save**.

<figure><img src="/files/IXOS11nhcv2i7toDykTa" alt="Ping Identity Admin console with key steps to creating a new SAML application."><figcaption><p>Creating a new SAML application</p></figcaption></figure>

### 1. Attribute Mappings

Go to **Attribute Mappings**, click the **Edit icon**, and add the following attributes:

| Attributes               | PingOne Mappings |
| ------------------------ | ---------------- |
| "email" (without quotes) | Email Address    |
| "name" (without quotes)  | Username         |

Check the **Required** boxes, and click **Save**.

<figure><img src="/files/dg9tOZS1vlsVmUnpdTat" alt="Ping Identity Admin console with key steps to setting up the &#x22;Attribute Mappings&#x22;."><figcaption><p>Setting up the Attribute Mappings</p></figcaption></figure>

### 2. Configuration

Go to **Configuration**, click **Download Metadata**, and open the file in a text editor (e.g. Notepad).

Copy the details to GoodAccess - **(3) Identity Provider links**, and click **Continue**.

* **Sign in URL** - Single Signon Service
* **Entity ID** - Issuer ID
* **X509 signing certificate** - Copy the certificate from the text editor

Don't forget to **Enable** the application.

<figure><img src="/files/sVI7E1yVuxCWMHWstOmL" alt="Ping Identity Admin console with key steps to setting up GoodAccess."><figcaption><p>Setting up GoodAccess</p></figcaption></figure>

<figure><img src="/files/OQKwt3usm9kPP5DICJyN" alt="Notepad with highlighted X509 signing certificate."><figcaption><p>Copying the certificate from the Notepad</p></figcaption></figure>

{% hint style="info" %}
If you don't want to setup SCIM, skip the next step in GoodAccess, and click **Submit** to finish the configuration.
{% endhint %}

You have now successfully set up your Ping Identity SSO with GoodAccess.

## Step 3 - Managing user access

{% hint style="danger" %}
**Please note:** If no groups are selected, **all users will have access**. To prevent unauthorized access, ensure you add at least one group, even when setting up SCIM.
{% endhint %}

{% hint style="warning" %}
If you are setting up SCIM, skip this section. User access for SCIM is managed separately—please refer to [#user-filter](#user-filter "mention") for details.
{% endhint %}

In the application, go to **Access**, and click the **Edit icon**.

Choose who should have access, and click **Save**.

<figure><img src="/files/22jeQUV7IR2p8LMMdDYS" alt="Ping Identity Admin console with key steps to managing user access."><figcaption><p>Managing user access</p></figcaption></figure>

## Step 4 (optional) - Setting up SCIM

### 1. Provisioning Connection

Go to **Integrations** > **Provisioning**, click **(+)** to create a new connection, and select **Identity Store**.

Select **SCIM Outbound**, and click **Next**.

Give the connection a name, and click **Next**.

<figure><img src="/files/ujUvl3jl260pcja7BbKl" alt="Ping Identity Admin console with key steps to creating a new provisioning connection."><figcaption><p>Creating a new provisioning connection</p></figcaption></figure>

<figure><img src="/files/O7bSpIQz6ks8ij19xAck" alt="Ping Identity Admin console with key steps to creating a new provisioning connection."><figcaption><p>Creating a new provisioning connection</p></figcaption></figure>

#### Authentication

Copy the **URL** and **Token** from GoodAccess - **(4) User provisioning (SCIM)**.

* **SCIM BASE URL** - URL
* **SCIM Version** - 2.0
* **Authentication Method** - OAuth 2 Bearer Token
* **Oauth Access Token** - Token
* **Auth Type Header** - Bearer

Return to GoodAccess, and click **Submit**.

Return to Ping Identity, click **Test Connection**, and **Next**.

<figure><img src="/files/ZyCHXXJGBUlRn7nAqozQ" alt="Ping Identity Admin console with key steps to setting up the &#x22;Authentication&#x22;."><figcaption><p>Setting up the Authentication</p></figcaption></figure>

#### Preferences

Select actions to allow, and click **Save**.

Don't forget to **Enable** the connection.

<figure><img src="/files/u9TS8cF84mxOwGK4jxFP" alt="Ping Identity Admin console with key steps to setting up the &#x22;Preferences&#x22;."><figcaption><p>Setting up the Preferences</p></figcaption></figure>

### 2. Provisioning Rule

Go to **Integrations** > **Provisioning**, and click **(+)** to create a new rule.

Give the rule a name, and click **Create Rule**.

Click **(+)** to add your new connection as **Target**, and click **Save**.

<figure><img src="/files/a7dS6jGJrcvXCJ7HNtnZ" alt="Ping Identity Admin console with key steps to creating a new provisioning rule."><figcaption><p>Creating a new provisioning rule</p></figcaption></figure>

#### User Filter

Click the **Edit icon** to modify the user provisioning criteria.

For instance, you can use the **Group Names** attribute to provision users based on their membership in a specific group.

| Attribute   | Operator | Value   |
| ----------- | -------- | ------- |
| Group Names | Contains | Group 1 |
| Group Names | Contains | Group 2 |

Click **Save**.

<figure><img src="/files/6d2HF3K2N9rjfTz7lEk8" alt="Ping Identity Admin console with key steps to setting up the &#x22;User Filter&#x22;."><figcaption><p>Setting up the User Filter</p></figcaption></figure>

#### Attribute Mapping

Click the **Edit icon**, and edit the existing mapping and add a new one as follows:

| Identity Provider Directory | GoodAccess  |
| --------------------------- | ----------- |
| Email Address               | userName    |
| Username                    | displayName |

Click **Save**.

<figure><img src="/files/15qd69BPkbFXeaVsynHS" alt="Ping Identity Admin console with key steps to setting up the &#x22;Attribute Mapping&#x22;."><figcaption><p>Setting up the Attribute Mapping</p></figcaption></figure>

#### (optional) Group Provisioning

Click the **Edit icon**, and select groups you want to provision. Group memberships in GoodAccess are updated according to [#user-filter](#user-filter "mention") criteria.

Click **Save**.

Don't forget to **Enable** the rule.

<figure><img src="/files/kZgeGc53VCG01SFSSxek" alt="Ping Identity Admin console with key steps to setting up the &#x22;Group Provisioning&#x22;."><figcaption><p>Setting up the Group Provisioning</p></figcaption></figure>

{% hint style="info" %}
The whole provisioning process will take around **20 minutes** to complete depending on the number of members and groups being added.
{% endhint %}

You have now successfully set up your Ping Identity SCIM with GoodAccess.


# Universal (SAML)

This guide will show you how to integrate GoodAccess with with any SSO provider supporting SAML.

{% hint style="info" %}
This feature is available in **Premium plan and higher**.
{% endhint %}

{% hint style="danger" %}
**Remember to grant your users access permissions to GoodAccess. Users without them won't be able to log in.**
{% endhint %}

You may set up Single Sign-On (SSO) in [Control Panel > Settings > SSO & Identity](https://app.goodaccess.com/sso-and-identity/).

## Step 1

1. Go to the settings of your identity provider and look for an option to add a new application.
2. If asked for the **sign-in method**, select **SAML (2.0)**.
3. Name your application and choose a logo.

## Step 2

{% hint style="danger" %}
These details are general and are the same for every identity provider. However, individual identity providers can use different names for the fields and the settings may vary in details.

If you are lost, we recommend checking our other [guides](/configuration-guides/features/sso-scim) for identity providers where you can gain more insight on the setup of yours. If that doesn't help you, check the guides from your provider or [contact us](https://www.goodaccess.com/contact).
{% endhint %}

When asked for **SAML configuration**, enter the details from GoodAccess - **(2) GoodAccess links**.

* **Identifier** - Entity ID
* **Reply URL** - Assertion Consumer Service URL
* **Sign on URL** - Login URL
* **Relay State** - Relay State

For **User Attributes & Claims** create the following attributes:

{% hint style="warning" %}
**Important:** Attribute names are case-sensitive. Please enter them exactly as shown (all lowercase).
{% endhint %}

| Name      | Name Format | Value / Source Attribute                                                                           |
| --------- | ----------- | -------------------------------------------------------------------------------------------------- |
| **email** | Unspecified | Select the attribute representing the user's primary email address (e.g., `user.mail` or `email`). |
| **name**  | Unspecified | Select the attribute representing the user's full name (e.g., `user.displayname` or `name`).       |

## Step 3

Add **permissions** for the application to an existing group within your identity provider or create a new one and assign users to it.

## Step 4

Open your newly created application, look for SAML settings and copy the following details into **GoodAccess - (3) Identity Provider Links**.

* **SSO/Login URL** - Sign in URL
* **Identifier/Issuer** - Entity ID
* **Certificate** - X509 signing certificate

## Step 5

Now switch back to GoodAccess, click **Continue**, and **Submit**.


# MFA

Multi-factor authentication (MFA) is an access control technique that requires a user to provide one or more additional proofs of identity on top of the password and username.

{% hint style="info" %}
This feature is available in the **Essential plan and higher**.
{% endhint %}

You may set up MFA for your account in [Control Panel > Account (top right corner) > Security](https://account.goodaccess.com/security-settings/).

By enabling MFA you will be prompted to enter a security code from an TOTP-based authentication app (e.g. [Google Authenticator](https://support.google.com/accounts/answer/1066447?hl=en), [Microsoft Authenticator](https://www.microsoft.com/en-us/account/authenticator), [Authy](https://authy.com/download/) or [1Password](https://support.1password.com/one-time-passwords/)) every time you log in.

## Backup Codes

When setting up MFA, a set of backup codes will be automatically generated for you.

These are one-time codes that can be used if you lose access to your primary MFA device, ensuring you can always securely regain access to your account.

Each backup code can only be used once. You can regenerate these codes at any time, which will invalidate any previously generated codes to maintain security.

If you use a backup code to log in, you can disable MFA using your password. The option to regenerate backup codes will be disabled until a new MFA is set up or until logging in with your current MFA.

{% hint style="danger" %}
Protect your backup codes as if they were passwords.
{% endhint %}

## Managing Team MFA

You may manage Team MFA in [Control Panel > Settings > MFA & Login Security](https://app.goodaccess.com/mfa-and-login-security/).

Once enabled, Team Admins or Members will be forced to use MFA while logging in to the Control Panel, Client Application, or both, depending on your configuration.

## Step-Up Authentication via API

For advanced security workflows, you can trigger **Step-Up Authentication** by interrupting a user's active session via a **Disconnect** [API endpoint](/configuration-guides/features/api-integration/api-reference/members#post-api-v1-member-teammemberid-disconnect). This forces the user to re-authenticate as soon as the application attempts to reconnect.

**Use Cases**:

* **Automated Security Response**: Integrate with your **SIEM/SOC** to automatically terminate sessions when a high-risk event (e.g., login from an unusual country) is detected.
* **Contextual Security**: Enforce a fresh MFA challenge during a device posture change or for periodic security re-verification of highly sensitive resources.

To make this effective, you must ensure that the user cannot reconnect automatically without an MFA challenge. In the [Control Panel > Settings > MFA & Login Security](https://app.goodaccess.com/mfa-and-login-security/), you must have at least one of the following connection policies enabled:

* **TOTP Prior Connection**: The user will be prompted to enter a 6-digit code from their authenticator app before the connection is established.
* **PIN & Biometrics Prior Connection**: The user must unlock the connection attempt using their device’s biometrics (TouchID/FaceID/Windows Hello) or the application PIN.

{% hint style="danger" %}
**Warning**: If neither of these options is enabled, the client application may attempt to restore the connection automatically, which would bypass the Step-Up Authentication intent.
{% endhint %}

## Reset of MFA

To reset your MFA, ask your Team Admin or [contact our technical support](https://www.goodaccess.com/contact).

Team Admin can reset user's MFA in [Control Panel > Members > Edit button of the Member](https://app.goodaccess.com/team-members/). This action is not performed immediately but requires the user to take action upon receiving an email and precisely navigate to setting up a new MFA; the old MFA is invalidated after the new one is set up.


# Passkeys

Secure your account with Passkeys—fast, easy, and phishing-proof WebAuthn authentication for passwordless login using Face ID, Touch ID, or a PIN.

{% hint style="info" %}
This feature is available in the **Essential plan and higher**.
{% endhint %}

Passkeys are a passwordless authentication method that allows you to sign in using biometrics (such as Face ID or fingerprint recognition) or a PIN on your trusted devices. Instead of typing a password, Passkeys use cryptographic keys that are securely stored on your device.

## Why use Passkeys?

Passkeys offer several benefits over traditional passwords:

* **Enhanced Security**: Passkeys cannot be stolen in phishing attacks, as they do not rely on traditional passwords.
* **Seamless Access**: Sign in quickly with Face ID, Touch ID, or a device PIN—no need to remember complex passwords.
* **Cross-Device Support**: Passkeys can sync across devices using secure cloud storage, allowing easy sign-ins on multiple platforms.

## Supported Browsers

Browser support for WebAuthn is quickly improving. To verify if your device supports Passkeys or for latest updates, visit this [link](https://webauthn.me/browser-support).

<table data-header-hidden data-full-width="false"><thead><tr><th width="111"></th><th width="94"></th><th width="80"></th><th width="146"></th><th valign="middle"></th><th width="97"></th><th></th></tr></thead><tbody><tr><td></td><td><strong>Android 7+</strong></td><td><strong>iOS 14.5+</strong></td><td><strong>Windows 10 (with Windows Hello)</strong></td><td valign="middle"><strong>macOS Catalina</strong></td><td><strong>macOS Big Sur</strong></td><td><strong>Desktop Linux</strong></td></tr><tr><td><strong>Chrome</strong></td><td><mark style="color:orange;"><strong>Yes</strong></mark></td><td><mark style="color:orange;"><strong>Yes</strong></mark></td><td><mark style="color:orange;"><strong>Yes</strong></mark></td><td valign="middle"><mark style="color:orange;"><strong>Yes</strong></mark></td><td><mark style="color:orange;"><strong>Yes</strong></mark></td><td>-</td></tr><tr><td><strong>Safari</strong></td><td>N/A</td><td><mark style="color:orange;"><strong>Yes</strong></mark></td><td>N/A</td><td valign="middle">No</td><td><mark style="color:orange;"><strong>Yes</strong></mark></td><td>N/A</td></tr><tr><td><strong>Firefox</strong></td><td>No</td><td><mark style="color:orange;"><strong>Yes</strong></mark></td><td><mark style="color:orange;"><strong>Yes</strong></mark></td><td valign="middle">No</td><td>No</td><td>-</td></tr><tr><td><strong>Brave</strong></td><td>No</td><td><mark style="color:orange;"><strong>Yes</strong></mark></td><td><mark style="color:orange;"><strong>Yes</strong></mark></td><td valign="middle"><mark style="color:orange;"><strong>Yes</strong></mark></td><td><mark style="color:orange;"><strong>Yes</strong></mark></td><td>-</td></tr><tr><td><strong>Edge</strong></td><td>No</td><td><mark style="color:orange;"><strong>Yes</strong></mark></td><td><mark style="color:orange;"><strong>Yes</strong></mark></td><td valign="middle"><mark style="color:orange;"><strong>Yes</strong></mark></td><td><mark style="color:orange;"><strong>Yes</strong></mark></td><td>-</td></tr><tr><td><strong>Internet Explorer</strong></td><td>N/A</td><td>N/A</td><td>No</td><td valign="middle">N/A</td><td>N/A</td><td>N/A</td></tr></tbody></table>

## Registering a Passkey

You may set up Passkeys for your account in [Control Panel > Account (top right corner) > Security](https://account.goodaccess.com/security-settings/).

Click **Register Passkey**, and give it a name (e.g., Laptop).

Click **Register Passkey**, and verify your identity using biometrics or a device PIN.

Once registered, simply use your chosen biometric or device PIN whenever you log in.

## Frequently Asked Questions (FAQ)

<details>

<summary>Can I still use my password?</summary>

Yes! You can continue using your password, but we highly recommend Passkeys for a faster and more secure experience.

</details>

<details>

<summary>What happens if I lose my device?</summary>

If your device is lost, you can recover access by using another trusted device, password or your account recovery options.

</details>

<details>

<summary>Where can I use Passkeys?</summary>

Passkeys are supported on most modern devices, including smartphones, tablets, and computers running the latest operating systems. They are also compatible with most modern web browsers.

For the latest compatibility details, see [#supported-browsers](#supported-browsers "mention").

</details>

<details>

<summary>Can I use Passkeys on multiple devices?</summary>

Yes! If your devices support secure cloud synchronization, your Passkeys can be accessed across multiple trusted devices.

</details>

<details>

<summary>Are Passkeys safe from hackers?</summary>

Yes! Passkeys use strong encryption and are stored securely on your device, making them resistant to phishing and hacking attempts.

</details>

<details>

<summary>How do I remove a Passkey?</summary>

You can manage and delete your Passkeys from your [account security settings](https://account.goodaccess.com/security-settings/) at any time.

</details>

*Stay secure, stay password-free!*


# MSI deployment

Centralize and automate Client App deployment across all devices using MDM tools for efficient and secure enterprise distribution.

{% hint style="info" %}
This feature is available in the **Essential plan and higher**.
{% endhint %}

This page provides an overview of Client Application deployment using MDM tools. Select a deployment scenario below and follow the corresponding instructions.

## 🚀 Deployment scenarios

The Client Application can be deployed using different methods depending on your environment and update strategy:

#### Automatic updates

The application is installed with automatic updates enabled.

* The built-in updater is enabled
* The application updates automatically without requiring administrator action
* MDM tools are used only for initial deployment
* Version control is handled by the application itself

👉 This corresponds to `AUTO_UPDATES=true` in [🔧 Public properties](#public-properties).

**👉 Ensure that version enforcement is disabled in your MDM tool so the application can update itself.**

💡 Example (Microsoft Intune): Configure “Ignore app version” to “Yes” so that application updates are not enforced by the MDM tool.

*Recommended for environments where application updates are handled automatically without user or administrator involvement.*

#### Manual updates

The application is managed through your MDM tool.

* The built-in updater is disabled
* Application updates are controlled by administrators via MDM
* New versions must be deployed manually through the management system

👉 This corresponds to `AUTO_UPDATES=false` in [🔧 Public properties](#public-properties).

**👉 Ensure that the built-in updater is disabled and that application version control is enforced through your MDM tool.**

💡 Example (Microsoft Intune): Configure “Ignore app version” to “No”, allowing the MDM tool to enforce application updates.

*Recommended for environments where application updates are centrally managed by administrators.*

## ⚙️ Command-line arguments

The following arguments control installation behavior.

#### **/qn (silent installation)**

Runs the installation in silent mode without any user interface.

* No prompts or dialogs are shown
* Installation runs in the background

#### /norestart

Prevents the system from restarting after the installation is completed.

* The installation finishes without triggering a system reboot
* Any required restart must be handled manually

## 🔧 Public properties

These MSI public properties define how the application behaves after installation.

{% hint style="danger" %}
Changing the AUTO\_UPDATES property inconsistently with the selected deployment scenario may lead to unexpected application behavior across environments.
{% endhint %}

#### **AUTO\_UPDATES**

* **Default:** true
* **Values:** true / false
* **Format:** `AUTO_UPDATES=false`

Defines how the application handles updates when new versions are available.

* **true:**\
  The built-in updater is enabled. The application prompts the user to install updates when available and will automatically install them if the update is not applied within a certain period.
* **false:**\
  The built-in updater is disabled. The application notifies the user about updates and requires administrator-managed installation.

#### **DEFAULT\_PROTOCOL**

* **Default:** openvpn
* **Values:** openvpn / ikev2
* **Format:** `DEFAULT_PROTOCOL=ikev2`

Defines the default connection protocol used by the application.

* **openvpn:**\
  Recommended for stable and persistent connections (e.g., RDP sessions).
* **ikev2:**\
  Alternative protocol suitable for standard VPN connections.

#### **PERSISTENT**

* **Default:** false
* **Values:** true / false
* **Format:** `PERSISTENT=true`

Controls whether the application maintains connection state across system sessions.

* **true:**\
  Automatically establishes a connection at system startup (before user login) and keeps the connection active after Windows lock or user logout.
* **false:**\
  Connects only after user login and disconnects on logout or lock screen.

## 📥 Download

* [MSI package](https://link.goodaccess.com/download-windows-link)

{% hint style="danger" %}
**The MSI package grants per-user update capabilities**.

When deploying via MDM tools, this behavior can be controlled by enabling or disabling automatic updates.

⚠️ **Incorrect configuration may lead to unexpected behavior or issues related to deployment.**

Please select one deployment scenario above and ensure that all settings and arguments are configured consistently.
{% endhint %}

## 📓 Changelog

* [Windows changelog](/product-changelog/windows)


# Threat Blocker

Protect your Team and company resources by automated detection and blocking of malicious domains.

{% hint style="info" %}
This feature is available in the **Essential plan and higher**.
{% endhint %}

You may set up Threat Blocker in [Control Panel > Settings > Threat Blocker & DNS](https://app.goodaccess.com/threat-blocker-and-dns/).

## Threat Blocker

Threat Blocker provides automated detection and blocking of malicious domains. It draws on multiple threat intelligence feeds to protect against malware, ransomware, phishing, botnet C\&C, spammers, and more.

Threat Blocker is enabled by default.

{% hint style="danger" %}
**Please note:** Disabling Threat Blocker also disables [Custom Domain Blocking](/configuration-guides/features/custom-domain-blocking), [Custom Domain Names](/configuration-guides/features/dns-management#custom-domain-names-for-your-systems) and [GoodAccess DNS servers](/configuration-guides/features/dns-management#dns-servers).
{% endhint %}

## Excluded domains

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

{% hint style="danger" %}
**Please note:** Excluding a domain will change the behavior of Threat Blocker and may increase security risk.
{% endhint %}

Threat Blocker will ignore domains listed here.

To exclude a specific domain, click the **+ Add domains** button.

You may specify the domain by its domain name or IP address.

Don't forget to **Save changes**.


# Custom Domain Blocking

Restrict access to specific domains for your Team.

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

You may set up Custom Domain Blocking in [Control Panel > Settings > Threat Blocker & DNS](https://app.goodaccess.com/threat-blocker-and-dns/).

The Custom Domain Blocking feature allows you to restrict access to specific domains, ensuring a secure environment where users cannot navigate to prohibited websites.

To block a specific domain, click the **+ Add domains** button.

You may specify the domain by its domain name or IP address.

Don't forget to **Enable Custom Domain Blocking**, and **Save changes**.


# DNS Management

Manage custom DNS records for your Team.

You may set up DNS Management in [Control Panel > Settings > Threat Blocker & DNS](https://app.goodaccess.com/threat-blocker-and-dns/).

## Custom Domain Names for your Systems

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

Set up custom private DNS records for your Systems. You can configure custom addresses for Systems on your LAN or assign names to Systems with custom IP addresses.

To set up custom private DNS records, click the **+ Add custom domain** button.

Don't forget to **Save changes**.

## Custom Zone Forwarding

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

Set up forwarding of DNS request for your private or public DNS zone. Specify zone name and IP addresses of your resolvers that handle DNS queries to a given DNS zone. These resolvers can be public or private and located in a connected Cloud & Branch network.

To set up custom zone forwarding, click the **+ Add custom zone forwarding** button.

Don't forget to **Save changes**.

## DNS Servers

{% hint style="info" %}
This feature is available in the **Essential plan and higher**.
{% endhint %}

By default, GoodAccess DNS servers are enabled. Disabling them will cause your Team to use public DNS servers (Google) when connected to the GoodAccess Gateway.

### Custom DNS Servers

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

Set up custom DNS servers your Team will use when connected to the GoodAccess Gateway.

{% hint style="danger" %}
**Please note:** Disabling GoodAccess or using Custom DNS servers also disables [Threat Blocker](/configuration-guides/features/threat-blocker), [Custom Domain Blocking](/configuration-guides/features/custom-domain-blocking), [Custom Domain Names](#custom-domain-names-for-your-systems) and [Custom Zone Forwarding](#custom-zone-forwarding).
{% endhint %}

Don't forget to **Save changes**.


# Split Tunneling

Access your critical systems via the secure GoodAccess gateway and route non-essential traffic directly to optimize latency.

{% hint style="info" %}
This feature is available in the **Essential plan and higher**.
{% endhint %}

You may set up Split Tunneling in [Control Panel > Settings > Split Tunneling](https://app.goodaccess.com/split-tunneling/).

By enabling Split Tunneling only traffic addressed to your defined Systems will pass through the GoodAccess Gateway. All other traffic will be routed directly through the internet.

Additionally, you can add custom domains or IP addresses in the **Custom Split Tunneling** configuration.

To set up Split Tunneling, add the **Members/Groups** it will apply to, check **Enable Split Tunneling**, and click **Save changes**.

{% hint style="warning" %}
**Please note:**

* This feature only works with OpenVPN.
* This feature only works on desktop applications (Windows, macOS, and Linux).
* Enabling this feature will disable full network encryption and other security features provided by GoodAccess.
  {% endhint %}


# Port Forwarding

Forward specific incoming traffic to your Gateway to an internal private IP address of your Team Member.

{% hint style="info" %}
This feature is available in the **Essential plan and higher**.
{% endhint %}

You may set up Port Forwarding in [Control Panel > Network > Gateways > Edit button](https://app.goodaccess.com/gateways/).

{% hint style="danger" %}
**We highly recommend opening only the ports you need.**

Opening the whole range of ports (i.e. 1-65535) presents a high security risk to your network.
{% endhint %}

{% hint style="warning" %}
Enabling Port Forwarding automatically locks the private IP addresses for the selected device. This setting cannot be disabled while Port Forwarding is active.

Once locked, you can view the assigned private IPs in the Device detail.
{% endhint %}

{% hint style="info" %}
In case you want to create a rule for both protocols using same port number, you need to create separate rule for each protocol.
{% endhint %}

* **Device:** Select a Member and the device you want to forward incoming traffic to
* **Service Name:** Name the new port forwarding rule
* **Public Port / Range:** Enter the public port number or range
* **Local Port / Range:** Enter the local port number or range&#x20;
* **Protocol:** Select the TCP or UDP protocol


# Branch Connector

Branch Connector allows you to connect your private on-premise networks to the GoodAccess Gateway to make your private systems accessible using the GoodAccess Client Application.

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

{% content-ref url="/pages/W4orXafYTIpHCuWrOdwr" %}
[Cisco](/configuration-guides/branch-connector/cisco)
{% endcontent-ref %}

{% content-ref url="/pages/8fp5TFxC59rrOCZfV2Hb" %}
[Cisco Meraki](/configuration-guides/branch-connector/cisco-meraki)
{% endcontent-ref %}

{% content-ref url="/pages/7R8ndfoUUy2A8bqubx86" %}
[FortiGate](/configuration-guides/branch-connector/fortigate)
{% endcontent-ref %}

{% content-ref url="/pages/5x1Ph765FnlJRbkwhveb" %}
[MikroTik](/configuration-guides/branch-connector/mikrotik)
{% endcontent-ref %}

{% content-ref url="/pages/I695mFDKw2VHXFaBuaD8" %}
[SonicWall](/configuration-guides/branch-connector/sonicwall)
{% endcontent-ref %}

{% content-ref url="/pages/kepH97pCB6W8cDcPkyje" %}
[UniFi USG](/configuration-guides/branch-connector/unifi-usg)
{% endcontent-ref %}

{% content-ref url="/pages/55vZhj8CIy87h6QtjUUQ" %}
[Zyxel Nebula Control Center](/configuration-guides/branch-connector/zyxel-nebula-control-center)
{% endcontent-ref %}

{% content-ref url="/pages/5QXKf1Confa5MF3UC99a" %}
[Other supported routers and firewalls](/configuration-guides/branch-connector/other-supported-routers-and-firewalls)
{% endcontent-ref %}


# Cisco

This guide will show you how to connect your Cisco device to the GoodAccess Gateway via a site-to-site connection using the IPsec protocol.

## Step 1 - Creating a new branch connection

[Log in to the GoodAccess **Control Panel**, and go to **Network** > **Clouds & Branches**.](https://app.goodaccess.com/branches/)

Click **+ Add new**, enter a **Name** (e.g., Prague Office), select the required **Gateway**, and define your local **Subnets** (using CIDR notation).

Choose **IPSec** **Protocol**, and click **Continue**.

Fill out the configuration form (Public IP, Pre-Shared Key, etc.). These parameters must match the configuration you will set on your device in the next steps.

Click **Submit** to finish, or **Continue** to define optional **Branch Segments** for finer access control.

{% hint style="info" %}
You may return to the configuration via the **Edit** button of your Branch at any time.
{% endhint %}

{% hint style="info" %}
**Example of configuration (Default preset):**

* **Shared Secret** - Create a new strong password
* **Public IP** - IP of your Cisco
* **IKE Lifetime (Phase 1)** - 8 hours (28800 seconds)
* **Tunnel Lifetime (Phase 2)** - 1 hour (3600 seconds)
* **Dead Peer Detection Delay** - 30 seconds
* **Encryption (Phase 1)** - aes256
* **Encryption (Phase 2)** - aes256
* **Integrity (Phase 1)** - sha256
* **Integrity (Phase 2)** - sha256
* **Diffie-Hellman Groups (Phase 1)** - 16 - modp4096
* **Diffie-Hellman Groups (Phase 2)** - 16 - modp4096
  {% endhint %}

## Step 2 - Creating a new IPSec profile

Log in to your Cisco device, and go to **VPN** > **IPSec Profiles**. Click **Add** to create a new profile.

Give the profile a name and set the configuration as follows:

* **Keying mode** - Auto
* **IKE Version** - IKEv2
* **Phase I & II Options** - Must match configuration from GoodAccess [(Step 1)](#step-1-creating-a-new-branch-connection)

Click **Apply** to confirm your settings.

<figure><img src="/files/KINPGJbjXZG97mROHsMC" alt="Router&#x27;s graphical user interface (GUI) with arrows highlighting key steps to creating a new IPSec profile."><figcaption><p>Creating a new IPSec profile</p></figcaption></figure>

## Step 3 - Creating a new site-to-site connection

Go to **VPN** > **Site-to-Site**. Click the **Add** button to create a new connection.

Give the connection a name and set the configuration as follows:

* **IPSec Profile** - Select the profile you just created [(Step 2)](#step-2-creating-a-new-ipsec-profile)
* **Remote Endpoint** - Select Static IP and enter the IP of your GoodAccess Gateway

#### Local/Remote IKE Authentication Method

* **Pre-shared Key** - Shared Secret from GoodAccess [(Step 1)](#step-1-creating-a-new-branch-connection)

<figure><img src="/files/muPQzKrPlgVm75kzoGKM" alt="Router&#x27;s graphical user interface (GUI) with arrows highlighting key steps to creating a new site-to-site connection."><figcaption><p>Creating a new site-to-site connection</p></figcaption></figure>

### **Local Group Setup**

* **Local Identifier Type** - Local WAN IP
* **Local Identifier** - Your public IP
* **Local IP Type** - Subnet
* **IP Address** - IP of your network
* **Subnet Mask** - Your Subnet Mask

### **Remote Group Setup**

* **Remote Identifier Type** - Remote WAN IP
* **Remote Identifier** - IP of your GoodAccess Gateway
* **Remote IP Type** - Subnet
* **IP Address** - Subnet of your GoodAccess Gateway
* **Subnet Mask** - Subnet Mask of your GoodAccess Gateway

Don't forget to **Apply** changes.

<figure><img src="/files/PpdRaKN4vBKLqYPNn5LE" alt="Router&#x27;s graphical user interface (GUI) showing configuration for the Local &#x26; Remote Group Setup sections of a site-to-site connection."><figcaption><p>Setting up the local &#x26; remote group setup of a site-to-site connection</p></figcaption></figure>

You have now successfully connected your device to GoodAccess.

{% hint style="warning" %}
**Firewall rules**

Make sure that your device allows incoming connections from your **GoodAccess Gateway private subnet** on the following ports:

* **UDP 500**
* **UDP 4500**
  {% endhint %}

{% hint style="info" %}
**You may check the status of the connection in:**

* **GoodAccess:** Go to **Control Panel > Network > Clouds & Branches** to view the tunnel status. Use the **Test Connection** button to validate the IPsec tunnel itself, or optionally to test a specific system (target must have ICMP enabled).
* **Cisco:** Go to **VPN > Site-to-Site > Status > VPN Status**.
  {% endhint %}

## Step 4 (optional) - Enabling DPD

Switch to **Advanced Setup** and **enable DPD (Dead Peer Detection)**.

Click **Apply** to confirm your settings.

<figure><img src="/files/rRTgJTEiHooifHozNWuz" alt="Router&#x27;s graphical user interface (GUI) with arrows highlighting key steps to enabling Dead Peer Detection (DPD) for a site-to-site connection."><figcaption><p>Setting up DPD (Dead Peer Detection)</p></figcaption></figure>

## Step 5 (optional) - Saving the configuration

Click on the **Red floppy disk** icon to access **Configuration Management**, and click on **Apply**.

{% hint style="info" %}
By saving the configuration, you prevent the risk of losing your IPsec configuration even if the router reboots or loses power.
{% endhint %}

<figure><img src="/files/0J7unykLNpGMEnoNVo8m" alt="Router&#x27;s graphical user interface (GUI) with arrows highlighting key steps to saving the configuration."><figcaption><p>Saving the configuration</p></figcaption></figure>


# Cisco Meraki

This guide will show you how to connect your Cisco Meraki device to the GoodAccess Gateway via a site-to-site connection using the IPsec protocol.

## Step 1 - Creating a new branch connection

[Log in to the GoodAccess **Control Panel**, and go to **Network** > **Clouds & Branches**.](https://app.goodaccess.com/branches/)

Click **+ Add new**, enter a **Name** (e.g., Prague Office), select the required **Gateway**, and define your local **Subnets** (using CIDR notation).

Choose **IPSec** **Protocol**, and click **Continue**.

Fill out the configuration form (Public IP, Pre-Shared Key, etc.). These parameters must match the configuration you will set on your device in the next steps.

Click **Submit** to finish, or **Continue** to define optional **Branch Segments** for finer access control.

{% hint style="info" %}
You may return to the configuration via the **Edit** button of your Branch at any time.
{% endhint %}

{% hint style="info" %}
**Example of configuration:**

* **Shared Secret** - Create a new strong password
* **Public IP** - IP of your Cisco
* **IKE Lifetime (Phase 1)** - 8 hours (28800 seconds)
* **Tunnel Lifetime (Phase 2)** - 1 hour (3600 seconds)
* **Dead Peer Detection Delay** - 30 seconds
* **Encryption (Phase 1)** - aes256
* **Encryption (Phase 2)** - aes256
* **Integrity (Phase 1)** - sha256
* **Integrity (Phase 2)** - sha256
* **Diffie-Hellman Groups (Phase 1)** - 14 - modp2048&#x20;
* **Diffie-Hellman Groups (Phase 2)** - 14 - modp2048&#x20;
  {% endhint %}

## Step 2 - Creating a new site-to-site connection

Log in to the [Cisco Meraki Admin console](https://account.meraki.com/login), and go to **Security & SD WAN** > **Site-to-site VPN**.

{% hint style="info" %}
Make sure that the **local LAN** you wish to access via GoodAccess is participating in the VPN.
{% endhint %}

Scroll down to the **Organization-wide settings** > **Non-Meraki VPN peers**, and click **Add a peer**.

Give the peer a name and set the configuration as follows:

* **IKE version** - IKEv2
* **Public IP** - IP of your GoodAccess Gateway
* **Private subnets** - Subnet of your GoodAccess Gateway
* **Preshared secret** - Shared Secret [(Step 1)](#step-1-creating-a-new-branch-connection)
* **IPsec policies** - Click **Default** and set the configuration as follows:

{% hint style="info" %}
Must match configuration from GoodAccess [(Step 1)](#step-1-creating-a-new-branch-connection).
{% endhint %}

#### Phase 1

* **Encryption** - AES256
* **Authentication** - SHA256
* **Diffie-Hellman group** - 14
* **Lifetime (seconds)** - 28800

#### Phase 2

* **Encryption** - AES256
* **Authentication** - SHA256
* **PFS group** - 14
* **Lifetime (seconds)** - 3600

Click **Update**, and **Save** to finish the configuration.

You have now successfully connected your device to GoodAccess.

{% hint style="warning" %}
**Firewall rules**

Make sure that your device allows incoming connections from your **GoodAccess Gateway private subnet** on the following ports:

* **UDP 500**
* **UDP 4500**
  {% endhint %}

{% hint style="info" %}
**You may check the status of the connection in:**

* **GoodAccess:** Go to **Control Panel > Network > Clouds & Branches** to view the tunnel status. Use the **Test Connection** button to validate the IPsec tunnel itself, or optionally to test a specific system (target must have ICMP enabled).
* **Cisco Meraki:** Go to **Security & SD WAN > VPN Status > Non-Meraki peer**.
  {% endhint %}


# FortiGate

This guide will show you how to connect your FortiGate device to the GoodAccess Gateway via a site-to-site connection using the IPSec protocol.

## Step 1 - Creating a new branch connection

[Log in to the GoodAccess **Control Panel**, and go to **Network** > **Clouds & Branches**.](https://app.goodaccess.com/branches/)

Click **+ Add new**, enter a **Name** (e.g., Prague Office), select the required **Gateway**, and define your local **Subnets** (using CIDR notation).

Choose **IPSec** **Protocol**, and click **Continue**.

Fill out the configuration form (Public IP, Pre-Shared Key, etc.). These parameters must match the configuration you will set on your device in the next steps.

Click **Submit** to finish, or **Continue** to define optional **Branch Segments** for finer access control.

{% hint style="info" %}
You may return to the configuration via the **Edit** button of your Branch at any time.
{% endhint %}

{% hint style="info" %}
**Example of configuration (Default preset):**

* **Shared Secret** - Create a new strong password
* **Public IP** - IP of your FortiGate
* **IKE Lifetime (Phase 1)** - 8 hours (28800 seconds)
* **Tunnel Lifetime (Phase 2)** - 1 hour (3600 seconds)
* **Dead Peer Detection Delay** - 30 seconds
* **Encryption (Phase 1)** - aes256
* **Encryption (Phase 2)** - aes256
* **Integrity (Phase 1)** - sha256
* **Integrity (Phase 2)** - sha256
* **Diffie-Hellman Groups (Phase 1)** - 16 - modp4096
* **Diffie-Hellman Groups (Phase 2)** - 16 - modp4096
  {% endhint %}

## Step 2 - Creating new addresses

Log in to your FortiGate device, and go to **Policy & Objects** > **Addresses**. Click **Create New** and select **Address**.

Give the address a name and set the configuration as follows:

{% hint style="info" %}
You have to create **two** Addresses - **local** and **remote**.
{% endhint %}

<figure><img src="/files/mwzRK2EFZf8SktfZJJSa" alt="Router&#x27;s graphical user interface (GUI) with arrows highlighting key steps to creating a new address."><figcaption><p>Creating a new address</p></figcaption></figure>

### **Local Address**

* **Type** - Subnet
* **IP/Netmask** - Subnet of FortiGate's local network and mask (e.g. 131.31.231.0/255.255.255.0)
* **Interface** - Optional

<figure><img src="/files/CD3AOuRTXqDF4DAcqxfu" alt="Router&#x27;s graphical user interface (GUI) showing configuration of the local address."><figcaption><p>Creating a local address</p></figcaption></figure>

Click **OK** to confirm your settings.

### **Remote Address**

* **Type** - Subnet
* **IP/Netmask** - Subnet of your GoodAccess Gateway and mask (e.g. 124.24.0.0/255.255.252.0)
* **Interface** - Optional

<figure><img src="/files/LNBykjLq3jSgQy1LcRNs" alt="Router&#x27;s graphical user interface (GUI) showing configuration of the remote address."><figcaption><p>Creating a remote address</p></figcaption></figure>

Click **OK** to confirm your settings.

## Step 3 - Creating a new IPSec tunnel

Go to **VPN** > **IPsec Tunnels**. Click **Create New** and select **IPSec Tunnel**.

Give the tunnel a name, select **Custom**, and click **Next**.

**Edit** all the sections as follows:

<div><figure><img src="/files/3FdtqRrVioYzFLf7K8wj" alt="Router&#x27;s graphical user interface (GUI) with arrows highlighting key steps to creating a new IPSec tunnel."><figcaption><p>Creating a new IPSec tunnel</p></figcaption></figure> <figure><img src="/files/7CKaCwBSYSAvYi9yZ6Ls" alt="Router&#x27;s graphical user interface (GUI) showing first step of the VPN Creation Wizard."><figcaption><p>Naming a new IPSec tunnel</p></figcaption></figure></div>

<figure><img src="/files/9Xl94qjVxyEmF7Uj4kCG" alt="Router&#x27;s graphical user interface (GUI) with arrows highlighting key steps to configuring an IPSec tunnel."><figcaption><p>Setting up a new IPSec tunnel</p></figcaption></figure>

### Network

* **Remote Gateway** - Static IP Address
* **IP Address** - IP of your GoodAccess Gateway
* **Interface** - WAN (depends on your site)
* **NAT Traversal** - Optional
* **Deed Peer Detection** - Optional
* **Advanced:**
  1. **Add route** - Enabled
  2. **Auto discovery sender** - Disabled
  3. **Auto discovery receiver** - Disabled
  4. **Exchange interface IP** - Disabled
  5. **Device creation** - Enabled

<figure><img src="/files/JZuHYu2sML8BQT9O8bJy" alt="Router&#x27;s graphical user interface (GUI) showing configuration for the Network section of an IPSec tunnel."><figcaption><p>Setting up the network section of a IPSec tunnel</p></figcaption></figure>

### **Authentication**

**Method** - Pre-shared Key

**Pre-shared Key** - Shared Secret [(Step 1)](#step-1-creating-a-new-branch-connection)

**IKE Version** - 2

<figure><img src="/files/qbBlm5aMqO08SNQtJkHr" alt="Router&#x27;s graphical user interface (GUI) showing configuration for the Authentication section of an IPSec tunnel."><figcaption><p>Setting up the authentication section of a IPSec tunnel</p></figcaption></figure>

### **Phase 1**

{% hint style="info" %}
Must match configuration from GoodAccess [(Step 1)](#step-1-creating-a-new-branch-connection).
{% endhint %}

<figure><img src="/files/jGBgxKkkPrvnVcpTcotK" alt="Router&#x27;s graphical user interface (GUI) showing configuration for the Phase 1 section of an IPSec tunnel."><figcaption><p>Setting up the Phase 1 section of a IPSec tunnel</p></figcaption></figure>

### **Phase 2**

{% hint style="info" %}
Must match configuration from GoodAccess [(Step 1)](#step-1-creating-a-new-branch-connection).
{% endhint %}

* **Local/Remote Address** - Select **Named Address**, and choose Local/Remote Address [(Step 2)](#step-2-creating-new-addresses)

<figure><img src="/files/3RQ5FbrKCUBfND8QTuEx" alt="Router&#x27;s graphical user interface (GUI) showing configuration for the Phase 2 section of an IPSec tunnel."><figcaption><p>Setting up the Phase 2 section of a IPSec tunnel</p></figcaption></figure>

Click **OK** to confirm your settings.

## Step 4 - Creating a new static route

Go to **Network** > **Static Routes** and click **Create New**.

Set the **Destination** as **Subnet** and enter the subnet of your GoodAccess Gateway and mask (e.g. 124.24.0.0/255.255.252.0).

Click **OK** to confirm your settings.

<div><figure><img src="/files/xyrAHyp8qkxQ5BLXpwNs" alt="Router&#x27;s graphical user interface (GUI) with arrows highlighting key steps to creating a new static route."><figcaption><p>Creating a new static route</p></figcaption></figure> <figure><img src="/files/XnLMZkxk1Vf3944muwqe" alt="Router&#x27;s graphical user interface (GUI) showing configuration of a static route."><figcaption><p>Setting up the new static route</p></figcaption></figure></div>

You have now successfully connected your device to GoodAccess.

{% hint style="warning" %}
**Firewall rules**

Make sure that your device allows incoming connections from your **GoodAccess Gateway private subnet** on the following ports:

* **UDP 500**
* **UDP 4500**
  {% endhint %}

{% hint style="info" %}
**You may check the status of the connection in:**

* **GoodAccess:** Go to **Control Panel > Network > Clouds & Branches** to view the tunnel status. Use the **Test Connection** button to validate the IPsec tunnel itself, or optionally to test a specific system (target must have ICMP enabled).
* **FortiGate:** Go to **Monitor > IPSec Monitor**.
  {% endhint %}


# MikroTik

This guide will show you how to connect your MikroTik device to the GoodAccess Gateway via a site-to-site connection using the IPSec protocol.

{% hint style="info" %}

#### Connecting MikroTik with IKEv2

* Does not require on-premise public static IP
* IKEv2 configuration allows you to use MikroTik as the main router (which is connected to internet) or place it locally in your LAN behind the main router
  {% endhint %}

## Step 1 - Creating a new branch connection

[Log in to the GoodAccess **Control Panel**, and go to **Network** > **Clouds & Branches**.](https://app.goodaccess.com/branches/)

Click **+ Add new**, enter a **Name** (e.g., Prague Office), select the required **Gateway**, and define your local **Subnets** (using CIDR notation).

Choose **IKEv2** **Protocol**, and click **Submit** to create the connection, or **Continue** to define optional **Branch Segments** for finer access control.

Once the connection is created, locate it in the list and click the **Configuration Guide** button to retrieve the parameters and configuration files for your device.

{% hint style="info" %}
You may return to the configuration via the **Edit** button of your Branch at any time.
{% endhint %}

## Step 2 - Uploading the script and setup files

Download a script for MikroTik:

* [RouterOS v6 (6.46 and newer)](https://goodaccess-storage.b-cdn.net/mikrotik/ga-setup-branch.rsc)
* [RouterOS v7](https://goodaccess-storage.b-cdn.net/mikrotik/ga-setup-branch-v7.rsc)

Log in to your MikroTik device, and go to **Files**.

**Upload** the script and setup files from [Step 1 ](#step-1-creating-a-new-branch-connection)(extract the files first).

<figure><img src="/files/gHTaVoH11t7siB6OdxSt" alt="Router&#x27;s graphical user interface (GUI) with labeled elements highlighting key steps to uploading files to MikroTik."><figcaption><p>Uploading the script and setup files</p></figcaption></figure>

## Step 3 - Setting up a site-to-site connection

{% hint style="danger" %}
**Please note:** Deploying the script on a already configured device could disrupt your existing setup. Please review the script thoroughly and ensure compatibility with your current configuration before deployment.
{% endhint %}

Go to **Terminal** and run the following script:

```
/import ga-setup-branch.rsc
```

Enter the credentials from GoodAccess [(Step 1)](#step-1-creating-a-new-branch-connection):

* **VPN username**
* **VPN password**
* **Gateway address**
* **Gateway subnet**
* **What is your local network** - Cloud/Branch subnet
* **What is CA certificate name** - Name of the CA Certificate file stored in your MikroTik files&#x20;

<figure><img src="/files/7254ToLlIMpEky3kAfvw" alt="Router&#x27;s Terminal showing configuration of a site-to-site connection."><figcaption><p>Setting up the site-to-site connection</p></figcaption></figure>

Connection is established when the message "**Script file loaded and executed successfully**" appears.

You have now successfully connected your device to GoodAccess.

{% hint style="warning" %}
**Firewall rules**

Make sure that your device allows incoming connections from your **GoodAccess Gateway private subnet** on the following ports:

* **UDP 500**
* **UDP 4500**
  {% endhint %}

{% hint style="info" %}
**You may check the status of the connection in:**

* **GoodAccess:** Go to **Control Panel > Network > Clouds & Branches** to view the tunnel status. Use the **Test Connection** button to validate the IPsec tunnel itself, or optionally to test a specific system (target must have ICMP enabled).
* **MikroTik:** Go to **IP > IPSec > Policies and Active Peers**.
  {% endhint %}


# SonicWall

This guide will show you how to connect your SonicWall device to the GoodAccess Gateway via a site-to-site connection using the IPSec protocol.

## Step 1 - Creating a new branch connection

[Log in to the GoodAccess **Control Panel**, and go to **Network** > **Clouds & Branches**.](https://app.goodaccess.com/branches/)

Click **+ Add new**, enter a **Name** (e.g., Prague Office), select the required **Gateway**, and define your local **Subnets** (using CIDR notation).

Choose **IPSec** **Protocol**, and click **Continue**.

Fill out the configuration form (Public IP, Pre-Shared Key, etc.). These parameters must match the configuration you will set on your device in the next steps.

Click **Submit** to finish, or **Continue** to define optional **Branch Segments** for finer access control.

{% hint style="info" %}
You may return to the configuration via the **Edit** button of your Branch at any time.
{% endhint %}

{% hint style="info" %}
**Example of configuration:**

* **Shared Secret** - Create a new strong password
* **Public IP** - IP of your SonicWall
* **IKE Lifetime (Phase 1)** - 8 hours (28800 seconds)
* **Tunnel Lifetime (Phase 2)** - 1 hour (3600 seconds)
* **Dead Peer Detection Delay** - 30 seconds
* **Encryption (Phase 1)** - aes256
* **Encryption (Phase 2)** - aes256
* **Integrity (Phase 1)** - sha256
* **Integrity (Phase 2)** - sha256
* **Diffie-Hellman Groups (Phase 1)** - 14 - modp2048&#x20;
* **Diffie-Hellman Groups (Phase 2)** - 14 - modp2048&#x20;
  {% endhint %}

## Step 2 - Creating new address objects

Log in to your SonicWall device, and go to **Object** > **Match Objects** > **Addresses** > **Address Objects**. Click **+ Add**.

{% hint style="info" %}
You have to create **two** objects - **gateway** and **subnet**.
{% endhint %}

<figure><img src="/files/icCFac6JUW1itVisXJg2" alt="Router&#x27;s graphical user interface (GUI) highlighting key steps to creating a new address object."><figcaption><p>Creating a new address object</p></figcaption></figure>

### Gateway

* **Name** - Give the object a name
* **Zone Assignment** - VPN
* **Type** - Host
* **IP Address** - IP of your GoodAccess Gateway

Click **Save**.

<figure><img src="/files/hlSwtjxk8z4HpxVKYzD2" alt="Router&#x27;s graphical user interface (GUI) highlighting key steps to configuring the Gateway address object."><figcaption><p>Setting up the Gateway address object</p></figcaption></figure>

### Subnet

* **Name** - Give the object a name
* **Zone Assignment** - VPN
* **Type** - Network
* **Network** - Subnet of your GoodAccess Gateway
* **Netmask / Prefix Length** - Subnet Mask of your GoodAccess Gateway

Click **Save**.

<figure><img src="/files/z0ApJvoYjwUayLKjg0XN" alt="Router&#x27;s graphical user interface (GUI) highlighting key steps to configuring the Subnet address object."><figcaption><p>Setting up the Subnet address object</p></figcaption></figure>

## Step 3 - Creating a new site-to-site connection

Go to **Network** > **IPSec VPN** > **Rules and Settings** > **Policies** > **IPv4**, and click **+ Add**.

<figure><img src="/files/zvbsSX01ikr8XpY2QqHJ" alt="Router&#x27;s graphical user interface (GUI) highlighting key steps to creating a new site-to-site connection."><figcaption><p>Creating a new site-to-site connection</p></figcaption></figure>

### General

#### Security Policy

* **Policy Type** - Site to Site
* **Authentication Method** - IKE Using Preshared Secret
* **Name** - Give the connection a name
* **IPsec Primary Gateway Name or Address** - IP of your GoodAccess Gateway

#### IKE Authentication

* **Shared Secret / Confirm Shared Secret** - Shared Secret [(Step 1)](#step-1-creating-a-new-branch-connection)
* **Local IKE ID** - IPv4 Address + IP of your SonicWall
* **Peer IKE ID** - IPv4 Address + IP of your GoodAccess Gateway

<figure><img src="/files/yeav2bMQfaBUT9HPLKKb" alt="Router&#x27;s graphical user interface (GUI) showing the configuration of the General section of a VPN policy."><figcaption><p>Setting up the General section</p></figcaption></figure>

### Network

#### Local Networks

* **Choose local network from list** - Select local network you want to access with GoodAccess

#### Remote Networks

* **Choose destination network from list** - Select your [Subnet address object](#subnet)

<figure><img src="/files/kKqXe2UcGnsnKFBS7m0h" alt="Router&#x27;s graphical user interface (GUI) showing the configuration of the Network section of a VPN policy."><figcaption><p>Setting up the Network section</p></figcaption></figure>

### Proposals

{% hint style="info" %}
Must match configuration from GoodAccess [(Step 1)](#step-1-creating-a-new-branch-connection).
{% endhint %}

#### IKE (Phase 1) Proposal

* **Exchange** - IKEv2 Mode
* **DH Group** - Group 14
* **Encryption** - AES-256
* **Authentication** - SHA256
* **Life Time (seconds)** - IKE Lifetime (Phase 1)

#### IPSec (Phase 2) Proposal

* **Protocol** - ESP
* **Encryption** - AES-256
* **Authentication** - SHA256
* **Enable Perfect Forward Secrecy**
* **DH Group** - Group 14
* **Life Time (seconds)** - Tunnel Lifetime (Phase 2)

<figure><img src="/files/Gd1znDzzxSn3el0BEF58" alt="Router&#x27;s graphical user interface (GUI) showing the configuration of the Proposals section of a VPN policy."><figcaption><p>Setting up the Proposals section</p></figcaption></figure>

### Advanced

* **Enable Keep Alive**

Click **Save**.

<figure><img src="/files/ncbjPQYQwEQPzFKD58k5" alt="Router&#x27;s graphical user interface (GUI) showing the configuration of the Advanced section of a VPN policy."><figcaption><p>Setting up the Advanced section</p></figcaption></figure>

You have now successfully connected your device to GoodAccess.

{% hint style="warning" %}
**Firewall rules**

Make sure that your device allows incoming connections from your **GoodAccess Gateway private subnet** on the following ports:

* **UDP 500**
* **UDP 4500**
  {% endhint %}

{% hint style="info" %}
**You may check the status of the connection in:**

* **GoodAccess:** Go to **Control Panel > Network > Clouds & Branches** to view the tunnel status. Use the **Test Connection** button to validate the IPsec tunnel itself, or optionally to test a specific system (target must have ICMP enabled).
* **SonicWall:** Go to **Network > IPSec VPN > Rules & Settings > Active Tunnels**.
  {% endhint %}


# UniFi USG

This guide will show you how to connect your UniFi device to the GoodAccess Gateway via a site-to-site connection using the IPsec protocol.

## Step 1 - Creating a new branch connection

[Log in to the GoodAccess **Control Panel**, and go to **Network** > **Clouds & Branches**.](https://app.goodaccess.com/branches/)

Click **+ Add new**, enter a **Name** (e.g., Prague Office), select the required **Gateway**, and define your local **Subnets** (using CIDR notation).

Choose **IPSec** **Protocol**, and click **Continue**.

Fill out the configuration form (Public IP, Pre-Shared Key, etc.). These parameters must match the configuration you will set on your device in the next steps.

Click **Submit** to finish, or **Continue** to define optional **Branch Segments** for finer access control.

{% hint style="info" %}
You may return to the configuration via the **Edit** button of your Branch at any time.
{% endhint %}

{% hint style="info" %}
**Example of configuration (Default preset):**

* **Shared Secret** - Create a new strong password
* **Public IP** - IP of your UniFi
* **IKE Lifetime (Phase 1)** - 8 hours (28800 seconds)
* **Tunnel Lifetime (Phase 2)** - 1 hour (3600 seconds)
* **Dead Peer Detection Delay** - 30 seconds
* **Encryption (Phase 1)** - aes256
* **Encryption (Phase 2)** - aes256
* **Integrity (Phase 1)** - sha256
* **Integrity (Phase 2)** - sha256
* **Diffie-Hellman Groups (Phase 1)** - 16 - modp4096
* **Diffie-Hellman Groups (Phase 2)** - 16 - modp4096
  {% endhint %}

## Step 2 - Creating a new site-to-site connection

Log in to the [UniFi management interface](https://unifi.ui.com), and go to **Settings** > **VPN** > **Site-to-Site VPN**.

Give the VPN a name and set the configuration as follows:

* **VPN Type** - IPsec
* **Pre-Shared Key** - Shared Secret [(Step 1)](#step-1-creating-a-new-branch-connection)
* **Remote IP / Host** - IP of your GoodAccess Gateway

### Network Configuration

* **VPN Type** - Route Based
* **Remote Network(s)** - Static + Subnet of your GoodAccess Gateway

### Advanced

{% hint style="info" %}
Must match configuration from GoodAccess [(Step 1)](#step-1-creating-a-new-branch-connection).
{% endhint %}

Switch to **Manual**, and set the configuration as follows:

* **Key Exchange Version** - IKEv2
* **IKE (Phase 1)**
  * **Encryption** - AES-256
  * **Hash** - SHA256
  * **DH Group** - 16
  * **Lifetime** - 28800
* **ESP (Phase 2)**
  * **Encryption** - AES-256
  * **Hash** - SHA256
  * **DH Group** - 16
  * **Lifetime** - 3600
* **Perfect Forward Secrecy (PFS)** - Enabled

Click **Add.**

You have now successfully connected your device to GoodAccess.

{% hint style="info" %}
UniFi automatically creates the necessary firewall rules and static routes.
{% endhint %}

{% hint style="info" %}
**You may check the status of the connection in:**

* **GoodAccess:** Go to **Control Panel > Network > Clouds & Branches** to view the tunnel status. Use the **Test Connection** button to validate the IPsec tunnel itself, or optionally to test a specific system (target must have ICMP enabled).
* **UniFi:** Go to **Settings > VPN > Site-to-Site VPN**.
  {% endhint %}


# Zyxel Nebula Control Center

This guide will show you how to connect your branch in Zyxel Nebula Control Center to the GoodAccess Gateway via a site-to-site connection using the IPSec protocol.

## Step 1 - Creating a new branch connection

[Log in to the GoodAccess **Control Panel**, and go to **Network** > **Clouds & Branches**.](https://app.goodaccess.com/branches/)

Click **+ Add new**, enter a **Name** (e.g., Prague Office), select the required **Gateway**, and define your local **Subnets** (using CIDR notation).

Choose **IPSec** **Protocol**, and click **Continue**.

Fill out the configuration form (Public IP, Pre-Shared Key, etc.). These parameters must match the configuration you will set on your device in the next steps.

Click **Submit** to finish, or **Continue** to define optional **Branch Segments** for finer access control.

{% hint style="info" %}
You may return to the configuration via the **Edit** button of your Branch at any time.
{% endhint %}

{% hint style="info" %}
**Example of configuration (Default preset):**

* **Shared Secret** - Create a new strong password
* **Public IP** - IP of your site
* **IKE Lifetime (Phase 1)** - 8 hours (28800 seconds)
* **Tunnel Lifetime (Phase 2)** - 1 hour (3600 seconds)
* **Dead Peer Detection Delay** - 30 seconds
* **Encryption (Phase 1)** - aes256
* **Encryption (Phase 2)** - aes256
* **Integrity (Phase 1)** - sha256
* **Integrity (Phase 2)** - sha256
* **Diffie-Hellman Groups (Phase 1)** - 16 - modp4096
* **Diffie-Hellman Groups (Phase 2)** - 16 - modp4096
  {% endhint %}

## Step 2 - Creating a new site-to-site connection

Log in to the Zyxel Nebula Control Center, and switch to the site you want to connect to GoodAccess.

Go to **Configure** > **Firewall** > **Site-to-Site VPN**.

<figure><img src="/files/4JfgF9oFm7kd08oiDlxf" alt="Nebula Control Center menu with key steps for navigating to the Site-to-Site VPN configuration."><figcaption><p>Menu of Configure > Firewall</p></figcaption></figure>

**Enable** the local network you want to access via GoodAccess.

Under the Non-Nebula VPN peers section click on the **+ Add** button, give it a name, and set the configuration as follows:

* **Public IP** - IP of your GoodAccess Gateway
* **Private subnet** - Subnet of your GoodAccess Gateway
* **Pre-shared secret** - Shared Secret [(Step 1)](#step-1-creating-a-new-branch-connection)

Click on the **Default** button, and set the  configuration as follows:

* **IKE version** - IKEv2
* **Phase 1 & 2** - Must match configuration from GoodAccess [(Step 1)](#step-1-creating-a-new-cloud-connection)

Click **OK**, and then **Save**.

<div data-full-width="false"><figure><img src="/files/urMUWJPvve2DNyzCFEGB" alt="Nebula Control Center with key steps to creating a new site-to-site connection." width="563"><figcaption><p>Creating a new site-to-site connection</p></figcaption></figure></div>

<figure><img src="/files/qQfGKFlISsTM0bvg6ln3" alt="Nebula Control Center showing configuration for the Phase 1 and 2 section of an IPSec policy."><figcaption><p>Setting up the Phase 1 &#x26; 2 configuration</p></figcaption></figure>

You have now successfully connected your branch to GoodAccess.

{% hint style="warning" %}
**Firewall rules**

Make sure that your device allows incoming connections from your **GoodAccess Gateway private subnet** on the following ports:

* **UDP 500**
* **UDP 4500**
  {% endhint %}

{% hint style="info" %}
**You may check the status of the connection in:**

* **GoodAccess:** Go to **Control Panel > Network > Clouds & Branches** to view the tunnel status. Use the **Test Connection** button to validate the IPsec tunnel itself, or optionally to test a specific system (target must have ICMP enabled).
* **Nebula Control Center:** Go to **Monitor > Firewall > VPN connections**.
  {% endhint %}


# Other supported routers and firewalls

Here you will find a list of other supported routers and firewalls.

The following routers and firewalls are fully compatible with GoodAccess.&#x20;

If you need any help with configuration, please [contact our technical support](https://www.goodaccess.com/contact).

Barracuda

Cisco ASA (Route Based)

Cisco Meraki

Check Point

D-Link DIR-130/330

DrayTek Vigor 3900

Juniper (JunOS) SRX

Linksys

Netgear BR500

Palo Alto

pfSense

Sophos XG

Synology

TP-Link

UniFi USG

Untangle NG

WatchGuard

Zyxel USG


# Cloud Connector

Cloud Connector allows you to connect your private cloud networks to the GoodAccess Gateway in order to make your private cloud systems and apps accessible using the GoodAccess Client Application.

{% hint style="info" %}
This feature is available in the **Premium plan and higher**.
{% endhint %}

<table data-view="cards"><thead><tr><th data-card-target data-type="content-ref"></th><th data-hidden></th><th data-hidden></th><th data-hidden></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td><a href="/pages/pXAz8KLFvMEGlwdh7F5H">/pages/pXAz8KLFvMEGlwdh7F5H</a></td><td></td><td></td><td></td><td><a href="/files/DR2Onsc1oapeqLRFG2q9">/files/DR2Onsc1oapeqLRFG2q9</a></td></tr><tr><td><a href="/pages/qZeAUzqF4LxM56RLe3EN">/pages/qZeAUzqF4LxM56RLe3EN</a></td><td></td><td></td><td></td><td><a href="/files/Vh0DsIkAxfeNpWT9XLjf">/files/Vh0DsIkAxfeNpWT9XLjf</a></td></tr><tr><td><a href="/pages/pKWc7xK70Oa0XKWJCY4d">/pages/pKWc7xK70Oa0XKWJCY4d</a></td><td></td><td></td><td></td><td><a href="/files/YCaESliiWRCdV7pil27u">/files/YCaESliiWRCdV7pil27u</a></td></tr><tr><td><a href="/pages/U7Y1g8NmLS2docsE9DZ5">/pages/U7Y1g8NmLS2docsE9DZ5</a></td><td></td><td></td><td></td><td><a href="/files/teT8FoQGBdZSOb9FOw03">/files/teT8FoQGBdZSOb9FOw03</a></td></tr></tbody></table>


# AWS

This guide will show you how to connect your AWS cloud to the GoodAccess Gateway via a site-to-site connection using the IPsec protocol.

## Step 1 - Creating a new cloud connection

[Log in to the GoodAccess **Control Panel**, and go to **Network** > **Clouds & Branches**.](https://app.goodaccess.com/branches/)

Click **+ Add new**, enter a **Name** (e.g., AWS Production), select the required **Gateway**, and define the **Subnets** **of your AWS VPC** (using CIDR notation).

Choose **IPSec** **Protocol**, and click **Continue**.

Fill out the configuration form (Public IP, Pre-Shared Key, etc.). These parameters must match the configuration you will set in your AWS environment in the next steps.

Click **Submit** to finish, or **Continue** to define optional **Branch Segments** for finer access control.

{% hint style="info" %}
You may return to the configuration via the **Edit** button of your Cloud at any time.
{% endhint %}

{% hint style="info" %}
**Example of configuration (Default preset):**

* **Shared Secret** - Create a new strong password
* **Public IP** - IP of the tunnel of your AWS VPN connection
* **IKE Lifetime (Phase 1)** - 8 hours (28800 seconds)
* **Tunnel Lifetime (Phase 2)** - 1 hour (3600 seconds)
* **Dead Peer Detection Delay** - 30 seconds
* **Encryption (Phase 1)** - aes256
* **Encryption (Phase 2)** - aes256
* **Integrity (Phase 1)** - sha256
* **Integrity (Phase 2)** - sha256
* **Diffie-Hellman Groups (Phase 1)** - 16 - modp4096
* **Diffie-Hellman Groups (Phase 2)** - 16 - modp4096
  {% endhint %}

## Step 2 - Opening the VPC service

Log in to the AWS, and go to **Services** > **VPC** (you can use the searchbar).

<div align="center"><figure><img src="/files/jgzT565hTy7WHnRofTHu" alt="AWS&#x27;s graphical user interface (GUI) showing a VPC service search query."><figcaption><p>Locating the VPC application</p></figcaption></figure></div>

## Step 3 - Creating a new customer gateway

Go to **Virtual Private Network (VPN)** > **Customer Gateways** and click **Create customer gateway**.

Give the customer gateway a name and set the configuration as follows:

* **BGP ASN** - 65000
* **IP address** - IP of your GoodAccess Gateway

Click **Create customer gateway** to confirm your settings.

<div><figure><img src="/files/RNXrLCN1BKGmnvjfL7EY" alt="AWS&#x27;s graphical user interface (GUI) showing left side menu of the VPC service for the private virtual network (VPN) section."><figcaption><p>Menu of VPC > VPN</p></figcaption></figure> <figure><img src="/files/2mLswCDqKZOrZza2cA95" alt="AWS&#x27;s graphical user interface (GUI) showing configuration of a customer gateway."><figcaption><p>Creating a customer gateway</p></figcaption></figure></div>

## Step 4 - Creating a new virtual private gateway

{% hint style="danger" %}
If you already have a virtual private gateway attached to your VPC, skip this section and continue with [Step 5 - Creating a new VPN connection](#step-5-creating-a-new-vpn-connection).
{% endhint %}

Go to **Virtual Private Network (VPN)** > **Virtual Private Gateways** and click **Create virtual private gateway**.

Give the virtual private gateway a name, and choose **Amazon default ASN**.

Click **Create virtual private gateway** to confirm your settings.

Select the newly created virtual private gateway and click **Attach to VPC**.

<div><figure><img src="/files/69kmXEEyQ9dOtv1Cgsxf" alt="AWS&#x27;s graphical user interface (GUI) showing configuration of a virtual private gateway."><figcaption><p>Creating a virtual private gateway</p></figcaption></figure> <figure><img src="/files/HwLwrilietmFXXmh8IqZ" alt="AWS&#x27;s graphical user interface (GUI) with arrows highlighting key steps to attaching a virtual private gateway to the VPC."><figcaption><p>Attaching the virtual private gateway to VPC</p></figcaption></figure></div>

## Step 5 - Creating a new VPN connection

Go to **Virtual Private Network (VPN)** > **Site-to-Site VPN Connections** and click **Create VPN connection**.

Give the VPN connection a name and set the configuration as follows:

* **Target gateway type** - Virtual private gateway
* **Customer gateway** - Existing
* **Routing options** - Static
* **Static IP prefixes** - Subnet of your GoodAccess Gateway

Open **Tunnel 1 options**:

* **Pre-Shared key for Tunnel 1** - Shared Secret [(Step 1)](#step-1-creating-a-new-cloud-connection)
* Select **Edit tunnel 1 options**
* **Phase I & II** - Must match configuration from GoodAccess [(Step 1)](#step-1-creating-a-new-cloud-connection)

Click **Create VPN connection** to confirm your settings.

<div><figure><img src="/files/qtAhQMhLPFE26A8VYD7n" alt="AWS&#x27;s graphical user interface (GUI) with arrows highlighting key steps to configuring a VPN connection."><figcaption><p>Creating a VPN connection</p></figcaption></figure> <figure><img src="/files/Ah4tRfjUWoiBqoWeLtTP" alt="AWS&#x27;s graphical user interface (GUI) with arrows highlighting key steps to configuring the Tunnel 1 section of a VPN connection."><figcaption><p>Setting up the Phase 1 &#x26; 2 configuration</p></figcaption></figure></div>

## Step 6 - Adding new routes

{% hint style="warning" %}
If your AWS subnet is associated with multiple route tables, make sure to add the required routes to **each** of those route tables.
{% endhint %}

Go to **Virtual Private Cloud (VPC)** > **Route Tables**. Click **Edit routes** and **Add** the following **routes**:

| **Destination**                   | **Target**                                                                |
| --------------------------------- | ------------------------------------------------------------------------- |
| Subnet of VPC                     | Local (default)                                                           |
| 0.0.0.0/0                         | Local Gateway (default)                                                   |
| Subnet of your GoodAccess Gateway | [Virtual Private Gateway](#step-4-creating-a-new-virtual-private-gateway) |

Don't forget to **Save changes**.

<figure><img src="/files/SxzhQQzJmnOw8PGupRmT" alt="AWS&#x27;s graphical user interface (GUI) with arrows highlighting key steps to editing routes."><figcaption><p>Editing the routes</p></figcaption></figure>

<figure><img src="/files/Aelzj7VHW2Af9TgL6xMT" alt="AWS&#x27;s graphical user interface (GUI) showing configuration of routes."><figcaption><p>Adding new routes</p></figcaption></figure>

You have now successfully connected your AWS cloud to GoodAccess.

{% hint style="warning" %}
**Firewall rules**

Make sure you allow connections from your **GoodAccess Gateway private subnet** to the resources in your **VPC** (e.g., virtual machines, databases, etc.).

Depending on your AWS security setup, you may need to allow this communication in:

* **Security Groups**
* **Network ACLs**
* **AWS Network Firewall**
  {% endhint %}

{% hint style="info" %}
**You may check the status of the connection in:**

* **GoodAccess:** Go to **Control Panel > Network > Clouds & Branches** to view the tunnel status. Use the **Test Connection** button to validate the IPsec tunnel itself, or optionally to test a specific system (target must have ICMP enabled).
* **AWS:** Go to **Virtual Private Network (VPN) > Site-to-Site VPN Connections**.
  {% endhint %}


# Google Cloud

This guide will show you how to connect your Google Cloud to the GoodAccess Gateway via a site-to-site connection using the IPsec protocol.

## Step 1 - Creating a new cloud connection

[Log in to the GoodAccess **Control Panel**, and go to **Network** > **Clouds & Branches**.](https://app.goodaccess.com/branches/)

Click **+ Add new**, enter a **Name** (e.g., GCP Production), select the required **Gateway**, and define the **Subnets** **of your Google Cloud VPC** (using CIDR notation).

Choose **IPSec** **Protocol**, and click **Continue**.

Fill out the configuration form (Public IP, Pre-Shared Key, etc.). These parameters must match the configuration you will set in your Google Cloud environment in the next steps.

Click **Submit** to finish, or **Continue** to define optional **Branch Segments** for finer access control.

{% hint style="info" %}
You may return to the configuration via the **Edit** button of your Cloud at any time.
{% endhint %}

{% hint style="info" %}
**Example of configuration (Default preset):**

* **Shared Secret** - Create a new strong password
* **Public IP** - IP of your Google Cloud VPN gateway
* **IKE Lifetime (Phase 1)** - 8 hours (28800 seconds)
* **Tunnel Lifetime (Phase 2)** - 1 hour (3600 seconds)
* **Dead Peer Detection Delay** - 30 seconds
* **Encryption (Phase 1)** - aes256
* **Encryption (Phase 2)** - aes256
* **Integrity (Phase 1)** - sha256
* **Integrity (Phase 2)** - sha256
* **Diffie-Hellman Groups (Phase 1)** - 16 - modp4096
* **Diffie-Hellman Groups (Phase 2)** - 16 - modp4096
  {% endhint %}

## Step 2 - Creating a new VPN connection

Log in to the [Google Cloud console](https://console.cloud.google.com/), and go to [**Network Connectivity** > **VPN**](https://console.cloud.google.com/hybrid/vpn/), and click **Create VPN Connection**.

Select **Classic VPN**, and click **Continue**.

<div data-full-width="false"><figure><img src="/files/tYigaoQSZsXDKXUfDVlN" alt="Google Cloud console with key steps to creating a new VPN connection."><figcaption><p>Creating a new VPN connection</p></figcaption></figure> <figure><img src="/files/ywnlgSIBiqdjiwJS2sBo" alt="Google Cloud console with key steps to creating a new VPN connection." width="233"><figcaption><p>Creating a new VPN connection</p></figcaption></figure></div>

### VPN gateway

* **Name** - Give the VPN gateway a name
* **Network** - Select default or a specific VPC
* **Region** - Preferably the region in which your resources lie
* **IP address** - Create an IP address

<figure><img src="/files/iMTGScMaUyR5jgeaWa2j" alt="Google Cloud console with key steps to configuring a new VPN gateway."><figcaption><p>Setting up a new VPN gateway</p></figcaption></figure>

### Tunnels

* **Name** - Give the tunnel a name
* **Remote peer IP address** - IP of your GoodAccess Gateway
* **IKE version** - IKEv2
* **IKE pre-shared key** - Shared Secret [(Step 1)](#step-1-creating-a-new-cloud-connection)
* **Routing options** - Route-based
* **Remote network IP ranges** - Subnet of your GoodAccess Gateway

Click **Done** and then **Create**.

<figure><img src="/files/sCiNOn2p0Xqh6VjsDWwR" alt="Google Cloud console with key steps to configuring tunnel for the new VPN gateway."><figcaption><p>Setting up tunnel for the new VPN gateway</p></figcaption></figure>

You have now successfully connected your Google Cloud resources to GoodAccess.

{% hint style="warning" %}
**Firewall rules**

Make sure you allow connections from your **GoodAccess Gateway private subnet** to the resources in your **VPC** (e.g., virtual machines, databases, etc.).

Depending on your Google Cloud security setup, you may need to allow this communication in:

* **Cloud Firewall**
* **Cloud NGFW**
  {% endhint %}

{% hint style="info" %}
**You may check the status of the connection in:**

* **GoodAccess:** Go to **Control Panel > Network > Clouds & Branches** to view the tunnel status. Use the **Test Connection** button to validate the IPsec tunnel itself, or optionally to test a specific system (target must have ICMP enabled).
* **Google Cloud:** Go to **Network Connectivity > VPN**.
  {% endhint %}


# Microsoft Azure

This guide will show you how to connect your Microsoft Azure cloud to the GoodAccess Gateway via a site-to-site connection using the IPsec protocol.

## Prerequisites

You need a **virtual network gateway** in Azure. If you don't have one, [follow this tutorial by Microsoft](https://learn.microsoft.com/en-us/azure/vpn-gateway/tutorial-create-gateway-portal).

## Step 1 - Creating a new cloud connection

[Log in to the GoodAccess **Control Panel**, and go to **Network** > **Clouds & Branches**.](https://app.goodaccess.com/branches/)

Click **+ Add new**, enter a **Name** (e.g., Azure Production), select the required **Gateway**, and define the **Subnets** **of your Azure Virtual Network** (using CIDR notation).

Choose **IPSec** **Protocol**, and click **Continue**.

Fill out the configuration form (Public IP, Pre-Shared Key, etc.). These parameters must match the configuration you will set in your Azure environment in the next steps.

Click **Submit** to finish, or **Continue** to define optional **Branch Segments** for finer access control.

{% hint style="info" %}
You may return to the configuration via the **Edit** button of your Cloud at any time.
{% endhint %}

{% hint style="info" %}
**Example of configuration:**

* **Shared Secret** - Create a new strong password
* **Public IP** - IP of your Azure virtual network gateway
* **IKE Lifetime (Phase 1)** - 8 hours (28800 seconds)
* **Tunnel Lifetime (Phase 2)** - 1 hour (3600 seconds)
* **Dead Peer Detection Delay** - 30 seconds
* **Encryption (Phase 1)** - aes256
* **Encryption (Phase 2)** - aes256
* **Integrity (Phase 1)** - sha256
* **Integrity (Phase 2)** - sha256
* **Diffie-Hellman Groups (Phase 1)** - 14 - modp2048
* **Diffie-Hellman Groups (Phase 2)** - 14 - modp2048 (PFS2048)
  {% endhint %}

## Step 2 - Creating a new local network gateway

Log in to the [Azure Portal](https://portal.azure.com/), and go to **Local network gateways** (you can use the searchbar), and click **+ Create**.

Set the configuration as follows:

* **Endpoint** - IP address
* **IP address** - IP of your GoodAccess Gateway
* **Address spaces** - Subnet of your GoodAccess Gateway

The remaining settings are up to you.

Click **Review + create** and then **Create**.

<div><figure><img src="/files/598ZkXqJm7pgteypogzH" alt="Azure Portal with key steps to creating a new local network gateway."><figcaption><p>Creating a new local network gateway</p></figcaption></figure> <figure><img src="/files/YZO26KES8SPmjRqx1Hfd" alt="Azure Portal with key steps to configuring a new local network gateway."><figcaption><p>Setting up a new local network gateway</p></figcaption></figure></div>

## Step 3 - Creating a new connection

Go to **Virtual network gateways** (you can use the searchbar), and select your virtual network gateway.

Go to **Connections,** click **+ Add**, and set the configuration as follows:

* **Connection type** - Site-to-site (IPsec)

The remaining settings are up to you.

Click **Next : Settings >**, and set the configuration as follows:

* **Virtual network gateway** - Choose from the dropdown
* **Local network gateway** - Choose from the dropdown
* **Shared key (PSK)** - Shared Secret [(Step 1)](#step-1-creating-a-new-cloud-connection)
* **IKE Protocol** - IKEv2
* **IPsec / IKE policy** - Custom
* **IKE Phase 1 & 2** - Must match configuration from GoodAccess [(Step 1)](#step-1-creating-a-new-cloud-connection)
* **IPsec SA lifetime in seconds** - Tunnel Lifetime (Phase 2)
* **DPD timeout in seconds** - Dead Peer Detection Delay

The remaining settings are up to you.

Click **Review + create**, and then **Create**.

<div><figure><img src="/files/6AMUvCaRTBy06Dynv8jM" alt="Azure Portal with key steps to creating a new connection."><figcaption><p>Creating a new connection</p></figcaption></figure> <figure><img src="/files/gwuXKwV3Sc9MADahlMS9" alt="Azure Portal with key steps to creating a new site-to-site connection."><figcaption><p>Creating a new site-to-site connection</p></figcaption></figure></div>

<figure><img src="/files/KHrUeHeJq2cOYZ7rtZse" alt="Azure Portal with key steps to configuring a new site-to-site connection."><figcaption><p>Setting up a new site-to-site connection</p></figcaption></figure>

You have now successfully connected your Azure resources to GoodAccess.

{% hint style="warning" %}
**Firewall rules**

Make sure you allow connections from your **GoodAccess Gateway private subnet** to the resources in your **Virtual Network (VNet)** (e.g., virtual machines, databases, etc.).

Depending on your Azure security setup, you may need to allow this communication in:

* **Network Security Groups (NSGs)**
* **Azure Firewall**
  {% endhint %}

{% hint style="info" %}
**You may check the status of the connection in:**

* **GoodAccess:** Go to **Control Panel > Network > Clouds & Branches** to view the tunnel status. Use the **Test Connection** button to validate the IPsec tunnel itself, or optionally to test a specific system (target must have ICMP enabled).
* **Azure:** Go to **Virtual network gateway > Connections**.
  {% endhint %}


# Other Public Cloud providers

Below is a list of other supported public cloud providers.

We support all public cloud providers that allow site-to-site connection with the IPsec or IKEv2 protocol. If you need any help with configuration, please [contact our technical support](https://www.goodaccess.com/contact).

Examples:

* IBM Cloud
* Oracle Cloud
* Alibaba Cloud
* RedHat
* Heroku
* Digital Ocean
* CloudFlare
* Linode
* Cloudways
* Rackspace


# IP whitelisting

IP whitelisting helps you to protect your publicly visible corporate systems like third-party SaaS services (CRMs, cloud tools, etc.) with GoodAccess.

{% content-ref url="/pages/Jc1g7TWQpt5ZLs3TiQA3" %}
[APACHE Web Server](/configuration-guides/ip-whitelisting/apache-web-server)
{% endcontent-ref %}

{% content-ref url="/pages/mxfwmzHs4LPRyiDPBnaI" %}
[AWS VPC](/configuration-guides/ip-whitelisting/aws-vpc)
{% endcontent-ref %}

{% content-ref url="/pages/Ry9J2nRt6I4n61RztXrL" %}
[Azure (Office 365)](/configuration-guides/ip-whitelisting/azure-office-365)
{% endcontent-ref %}

{% content-ref url="/pages/C7xNSnF0seYkGuyv43d7" %}
[Google Cloud](/configuration-guides/ip-whitelisting/google-cloud)
{% endcontent-ref %}

{% content-ref url="/pages/BG57kmoryuCyHF7Y7h81" %}
[Google Workspace](/configuration-guides/ip-whitelisting/google-workspace)
{% endcontent-ref %}

{% content-ref url="/pages/AZk9M4hVOM3GjT46am3i" %}
[Magento](/configuration-guides/ip-whitelisting/magento)
{% endcontent-ref %}

{% content-ref url="/pages/C6thiCpdEUsTpMgssUEn" %}
[Microsoft IIS](/configuration-guides/ip-whitelisting/microsoft-iis)
{% endcontent-ref %}

{% content-ref url="/pages/7vCT8fH0k781lkJxrb3h" %}
[NGINX](/configuration-guides/ip-whitelisting/nginx)
{% endcontent-ref %}

{% content-ref url="/pages/SbTFgOK1p5y0dxBoPx7i" %}
[OpenCart](/configuration-guides/ip-whitelisting/opencart)
{% endcontent-ref %}

{% content-ref url="/pages/2JBzp5CFx5xVuLb6ZfXx" %}
[PHP](/configuration-guides/ip-whitelisting/php)
{% endcontent-ref %}

{% content-ref url="/pages/12yDEeLXXQ2oOnHrbzHq" %}
[PHPMyAdmin](/configuration-guides/ip-whitelisting/phpmyadmin)
{% endcontent-ref %}

{% content-ref url="/pages/JGhTE16zWi2J8zHvBvtN" %}
[Pipedrive](/configuration-guides/ip-whitelisting/pipedrive)
{% endcontent-ref %}

{% content-ref url="/pages/rhqBtm9iuArA9Z9XQJ1J" %}
[SalesForce](/configuration-guides/ip-whitelisting/salesforce)
{% endcontent-ref %}

{% content-ref url="/pages/fq7OwX58pqPqxTu1kBhA" %}
[SSH server](/configuration-guides/ip-whitelisting/ssh-server)
{% endcontent-ref %}

{% content-ref url="/pages/BJx4P4lGRyx5XegsWOQP" %}
[WordPress](/configuration-guides/ip-whitelisting/wordpress)
{% endcontent-ref %}

{% content-ref url="/pages/nXnyqQ9xk9GWU0M7fyJi" %}
[Zoho CRM](/configuration-guides/ip-whitelisting/zoho-crm)
{% endcontent-ref %}


# APACHE Web Server

This guide will show you how to whitelist your GoodAccess IP address in APACHE Web Server.

## Step 1 <a href="#step-1" id="step-1"></a>

Open the [**.htaccess file generator**](http://toshop.com/go/c.htaccess-generator), enter your GoodAccess Gateway IP and click on **Generate .htaccess File.**

## Step 2

Set **I want to allow these IP addresses and ban everyone else.**

## Step 3

Create a .htaccess file with the generated content and copy it to your web server. Place it in the directory containing the part of the website that should be protected.

{% hint style="warning" %}
**Please note:** In case the .htaccess file doesn't work, check whether your APACHE is configured to **AllowOverride All**. See [APACHE AllowOverride documentation](https://httpd.apache.org/docs/2.4/mod/core.html#allowoverride).
{% endhint %}

{% hint style="info" %}
There are more ways to configure your APACHE web server, allowing access only through the GoodAccess network. See [APACHE Access Control documentation](https://httpd.apache.org/docs/2.4/howto/access.html) and [APACHE .htaccess file documentation](https://httpd.apache.org/docs/2.4/howto/htaccess.html).
{% endhint %}


# AWS VPC

This guide will show you how to whitelist your GoodAccess IP address in AWS VPC.

## Step 1

In AWS go to **Network & Security** > **Security Groups** > **Create security group**.

![](/files/ikFALbogAAnop2uRxgOJ)

## Step 2

**Name** the Security group, select the appropriate **VPC**, and fill out the **Inbound rules** section with the information provided below. Finally, click **Create security group**.

* **Type** - All traffic
* **Source** - **Custom** - GoodAccess Gateway I&#x50;**/32** (example: 11.22.33.44/32)

{% hint style="warning" %}
**Please note:** If you are using VPC peering, you can later update the rules for your VPC security groups to[ reference security groups in the peered VPC](https://docs.aws.amazon.com/vpc/latest/peering/vpc-peering-security-groups.html). In case you are using a Transit Gateway, note that spoke Amazon VPCs cannot reference security groups in other spokes connected to the same AWS Transit Gateway.
{% endhint %}

![](/files/uHQBxJzioPc4en6JFTrD)

## Step 3

#### **Attach resources to the security group**

* Return to the EC2 dashboard, go to **Instances** > **Instances**
* Select the instance you would like to apply the Security Group to (**Actions** > **Networking** > **Change Security Groups**)
* Select the newly created security group and **Assign security group**


# Azure (Office 365)

This guide will show you how to whitelist your GoodAccess IP address in Azure (Office 365).

## Prerequisites

* **Assigned roles**: Conditional Access Administrator and Security Administrator
* **Licence**: Microsoft Entra ID P1 or P2

## Step 1

In Azure go to **Conditional access** > **Named locations** > **IP ranges location**.

* Set **Name** + GoodAccess Gateway I&#x50;**/32** (example: 11.22.33.44/32)
* Check **Mark as trusted location** and **Create**

![](/files/IQRE9hXCy5baGuhE3W2U)

## Step 2

Go to **Policies** > **New Policy**

Choose your **New location** and specify who will have access.

<div><img src="/files/fZavz7YTts57eFfNETz5" alt=""> <figure><img src="/files/KLoYe8WUeCSC6hoDGpu1" alt=""><figcaption></figcaption></figure></div>

## Step 3

Switch to **Cloud apps or actions** and set restrictions.

<figure><img src="/files/STIJp9HJVpAnyRHwoEcb" alt=""><figcaption></figcaption></figure>

## Step 4

Open **Conditions** > **Locations** > **Switch Configure** to **Yes**.

* **Include** - Any location
* **Exclude** - Selected locations

<div><img src="/files/gc7QbWhOsj1SKRaOq02t" alt=""> <figure><img src="/files/KSSre4wVq8bLt3CNffc4" alt=""><figcaption></figcaption></figure></div>

## **Step 5**

Continue to **Grant**, choose **Block access** and **confirm** with **Select.**

Don't forget to set **Enable policy** to **On** before saving the configuration.

<figure><img src="/files/tkjxLkVXCIqGycwcvhdt" alt=""><figcaption></figcaption></figure>


# Google Cloud

This guide will show you how to whitelist your GoodAccess IP address in Google Cloud.

Open **VPC Network** > **Firewall** > **Create Firewall rule**.

<figure><img src="/files/2XJPk3P1wVnPiAJIgFur" alt=""><figcaption></figcaption></figure>

* Enter a **Name**
* **Logs** - Optional - Logs traffic related to the rule (this may increase the costs of your Google service)
* **Network** - Choose the network which contains resources you want to allow-list
* **Priority** - Leave default values
* **Direction of traffic** - Ingress
* **Actions on match** - Allow
* **Targets** - All instances in the network
* **Source filter** - IP ranges
* **Source IP ranges** -  GoodAccess Gateway I&#x50;**/32** (example: 11.22.33.44/32)
* **Second source filter** - None
* **Protocols and ports** - Allow all
* Click **Create**

<div><figure><img src="/files/LFRdjQewEiyBImm86j8P" alt=""><figcaption></figcaption></figure> <figure><img src="/files/AIshe38iTAPCqZDG1N1Z" alt=""><figcaption></figcaption></figure></div>


# Google Workspace

This guide will show you how to whitelist your GoodAccess IP address in Google Workspace.

{% hint style="info" %}
This guide is currently in development.
{% endhint %}

GoodAccess IP address can be whitelisted in Google Workspace. If you need any help with configuration, please [contact our technical support](https://www.goodaccess.com/contact). Alternatively, you can refer to [Google's official guide](https://support.google.com/a/answer/12642752) for step-by-step instructions.


# Magento

This guide will show you how to whitelist your GoodAccess IP address in Magento.

{% hint style="info" %}
**Prerequisites:**

* Ensure that you are running the latest version of the Fastly CDN module for Magento 2. See [Upgrade the Fastly Module](https://experienceleague.adobe.com/docs/commerce-cloud-service/user-guide/cdn/setup-fastly/fastly-configuration.html?lang=en#upgrade-the-fastly-module).
* Verify the environment configuration for the Fastly service. See [Test Fastly caching](https://experienceleague.adobe.com/docs/commerce-cloud-service/user-guide/cdn/setup-fastly/fastly-configuration.html?lang=en#test-fastly-caching).
* You must have **Admin credentials** to access the Magento Cloud Staging and Production environments.
* You will also need a list of client IP addresses to include on the allow list
  {% endhint %}

## **Step 1​**

Login to the Magento Admin interface, click **Stores** > **Settings** > **Configuration** > **Advanced** > **System**.

## Step 2

Expand **Full Page Cache** > **Fastly Configuration** > **Edge ACL**.

## Step 3

Create the ACL container:

* Click **Add ACL**.
* On the **ACL Container** page, enter a **ACL name**—`allowlist`.
* Select **Activate after the change** to make your changes to the version of the Fastly service configuration that you are editing.
* Click **Upload** to attach the ACL to your Fastly service configuration.

## Step 4

Add the list of IP addresses allowed to access the Magento Admin UI:

* Click the Settings icon for the `allowlist` ACL.
* Add and save the **IP Value** for **each client** IP address.
* Click **Cancel** to return to the system configuration page.

## Step 5

Click **Save Config**.

Refresh the cache according to the notification at the top of the page.


# Microsoft IIS

This guide will show you how to whitelist your GoodAccess IP address in Microsoft IIS.

To connect to Microsoft IIS through the GoodAccess Gateway, please refer to the following [**documentation**](https://docs.microsoft.com/en-us/iis/configuration/system.webserver/security/ipsecurity/)**.**


# NGINX

This guide will show you how to whitelist your GoodAccess IP address in NGINX.

## Step 1

#### Open the NGINX configuration file

If you are using NGINX’s main configuration file nginx.conf without [virtual hosts](http://ubiq.co/webmaster-blog/configure-multiple-host-names-nginx/), run the following command

```
sudo vi /etc/nginx/nginx.conf
```

If you have configured separate virtual hosts for your website (e.g. [www.example.com](http://www.example.com)), such as /etc/nginx/sites-enabled/example.conf then open its configuration with the following command

```
sudo vi /etc/nginx/sites-enabled/example.conf
```

## Step 2

There are multiple ways to whitelist an IP in NGINX. We will look at each one. If you want to whitelist the IP 45.43.23.21 for a domain or your entire website, you can add the following lines in your configuration file.

```
allow 45.43.23.21;
deny all;
```

The above lines will make NGINX deny all IPs except 45.43.23.21. The first line *allow 45.43.23.21* will allow access from that IP, *deny* all will block all other IPs.

{% content-ref url="/pages/tRFUOl0nfodIMIR6SKyN" %}
[Domain](/configuration-guides/ip-whitelisting/nginx/domain)
{% endcontent-ref %}

{% content-ref url="/pages/HvKp06dK6sWwrIzPw49L" %}
[Subdomain](/configuration-guides/ip-whitelisting/nginx/subdomain)
{% endcontent-ref %}

{% content-ref url="/pages/J1AbBcxTvDCM5TK0DCTS" %}
[URL](/configuration-guides/ip-whitelisting/nginx/url)
{% endcontent-ref %}


# Domain

This guide will show you how to whitelist your GoodAccess IP address in NGINX for a domain.

## Whitelist IP in NGINX for a domain

Add the above lines in any of the *http*, *server* or *location* / blocks as shown below

```
http{
   ...
   allow 45.43.23.21;
   deny all;
   ...
}

server{
    ...
    allow 45.43.23.21;
    deny all;
    ...
}


location / {
   allow 45.43.23.21;
   deny all;
}
```

## Restart NGINX

Run the following command to check the syntax of your updated config file.

```
sudo nginx -t
```

If there are no errors, run the following command to restart the NGINX server.

```
sudo systemctl restart nginx
```


# Subdomain

This guide will show you how to whitelist your GoodAccess IP address in NGINX for a subdomain.

## Whitelist an IP in NGINX for subdomain

Let’s say you have two subdomains (*blog.example.com* and *articles.example.com*) with their NGINX config files at */etc/nginx/sites-enabled/blog.conf* and */etc/nginx/sites-enabled/articles.conf*

If you want to whitelist an IP in NGINX for only 1 subdomain (e.g. blog.example.com), place the 2 lines below in the blog.conf file of that subdomain

```
sudo vim /etc/nginx/sites-enabled/blog.conf
```

```
server {
  server blog.example.com;
  allow 45.43.23.21;
  deny all;
}
```

If you want to whitelist an IP in both subdomains, then add the 2 lines in both *blog.conf* and *articles.conf* files.

## Restart NGINX

Run the following command to check the syntax of your updated config file.

```
sudo nginx -t
```

If there are no errors, run the following command to restart the NGINX server.

```
sudo systemctl restart nginx
```


# URL

This guide will show you how to whitelist your GoodAccess IP address in NGINX for a URL.

## Whitelist an IP in NGINX for a URL

If you want to whitelist an IP for just one URL (e.g. /accounts/login) then add the *allow* directive below in the *location* block of that URL.

```
location /accounts/login {
   allow 45.43.23.21;
   deny all;
}
```

## Restart NGINX

Run the following command to check the syntax of your updated config file.

```
sudo nginx -t
```

If there are no errors, run the following command to restart the NGINX server.

```
sudo systemctl restart nginx
```


# OpenCart

This guide will show you how to whitelist your GoodAccess IP address in OpenCart.

{% hint style="info" %}
You will need your site's FTP credentials to connect. If you are not sure how to find them, please refer to your hosting provider.
{% endhint %}

* Connect to the server that hosts your site files using an **FTP client** of your choice (like FileZilla)
* Navigate to your **admin folder** and create a new file with the name **".htaccess"** (If such a file exists already, open it for editing)
* Paste the below parameters to this .htaccess file and replace "*1.2.3.4"* with your GoodAccess Gateway IP (You can allow more IP addresses by adding multiple "*Allow from"* lines)

```
Order deny,allow
Deny from all
Allow from 1.2.3.4
```

**Save and upload the file.**


# PHP

This guide will show you how to whitelist your GoodAccess IP address in PHP.

There are multiple ways how to whitelist your GoodAccess IP in PHP.\
Below is an example of a basic whitelisting function. For more advanced setup, please refer to the following [**documentation**](https://www.php.net/manual/en/reserved.variables.server.php).

```php
function isAllowed($ip){
    $whitelist = array(‘111.111.111.111’, ‘112.112.112.112’);    // If the ip is matched, return true
    if(in_array($ip, $whitelist)) {
        return true;
    }    return false;
}
```

Using the whitelisting function for access control.

```php
if (! isAllowed($_SERVER[‘REMOTE_ADDR’])) {
    exit;
}
```


# PHPMyAdmin

This guide will show you how to whitelist your GoodAccess IP address in PHPMyAdmin.

{% hint style="info" %}
This guide has been created for Ubuntu 20.04 / Apache 2
{% endhint %}

## Step 1

Open **phpmyadmin.conf** for editing.

```
sudo nano /etc/apache2/sites-available/phpmyadmin.conf
```

## Step 2

Add the following lines below the line **“DirectoryIndex index.php”**

```
Require ip specific_ip_address
Require ip ::1
```

Replace ***specific\_ip\_address*** with the GoodAccess Gateway IP.

## Step 3

**Save and close** the file and **Restart Apache2** for the changes to take effect.

```
sudo systemctl restart apache2
```


# Pipedrive

This guide will show you how to whitelist your GoodAccess IP address in Pipedrive.

Go to **Settings** > **Security Center** > **Rules** > **Add IP address**.

Enter your GoodAccess Gateway IP or use **Autofill** if you are connected to GoodAccess.

<div><img src="/files/zIMOkEA3BkLKKW7d2MrJ" alt=""> <figure><img src="/files/76z4v1iFYdcr4VLjQ3vD" alt=""><figcaption></figcaption></figure></div>

Continue with **Preview and enforce** > **Enforce now**.

<div><figure><img src="/files/RhLjsroe2NefdcuRIgsj" alt=""><figcaption></figcaption></figure> <figure><img src="/files/zRLRwZbrU9hKPt5oX3xG" alt=""><figcaption></figcaption></figure></div>


# SalesForce

This guide will show you how to whitelist your GoodAccess IP address in SalesForce.

Click on **New** in the Login IP Ranges list, enter the GoodAccess Gateway IP to **IP Start** **Address** and **IP End Address**, and click **Save**.

{% hint style="info" %}
**The location of the IP Range configuration depends on your SalesForce license:**

#### **Enterprise, Unlimited, Performance or Developer Edition**

Go to **Setup** > **Profiles** (search for "Profiles" using the Quick Find box) and select the profile for which you want to apply the restrictions.

#### **Group or Personal Edition**

Go to **Setup** > **Session Settings** (search for "Session Settings" using the Quick Find box).

#### **Professional Edition**

The location of the IP Range configuration depends on whether you have the "Edit Profiles & Page Layouts" org preference enabled (add-on feature).

* Enabled - IP Ranges are located in individual **Profiles**
* Disabled - IP Ranges are located in **Session Settings**
  {% endhint %}


# SSH server

This guide will show you how to whitelist your GoodAccess IP address in SSH server.

{% hint style="danger" %}
Make sure **you've entered the correct IP address** to avoid any connection issues.
{% endhint %}

## Step 1 <a href="#step-1" id="step-1"></a>

To whitelist the IP, open **/etc/hosts.allow** file, enter **GoodAccess Gateway IP/32**, and **Save** the file.

```
sshd: 21.22.23.24/32, 33.34.35.36/32
```

*This line will allow all the comma separated IP blocks to your SSH port*

## Step 2

To block access from all other sources, open **/etc/hosts.deny** file, enter **"ALL"**, and **Save** the file.

```
sshd: ALL
```

{% hint style="info" %}
**Note:** There are several other ways to restrict access to SSH servers like IPTABLES firewall (restrict the access to TCP port 22), or SSH daemon config.
{% endhint %}


# WordPress

This guide will show you how to whitelist your GoodAccess IP address in WordPress.

## Step 1

* Open WordPress and navigate to administration by adding **/wp-login.php** to the URL (example: <https://wp.accessgood.test/wp-login.php>)
* Choose **Plugins** and **Add New**

<div><figure><img src="/files/HClHXQnDpRywKBnOmYAx" alt=""><figcaption></figcaption></figure> <figure><img src="/files/bcXEgKypX8aTkvVjT19z" alt=""><figcaption></figcaption></figure></div>

## Step 2

* On the right side, search for [**Secure Admin IP**](https://wordpress.org/plugins/secure-admin-ip/) and click **Install now**
* Return to **Plugins** and click **Activate**

<div><figure><img src="/files/mRtEM65heFftJBTt2U3j" alt=""><figcaption></figcaption></figure> <figure><img src="/files/rsYTnpF0cpMnSYnt0s4r" alt=""><figcaption></figcaption></figure></div>

## Step 3

* Choose **Settings** > **Secure Admin IP**
* **Whitelisted IP addresses** - Enter your GoodAccess Gateway IP
* Click **Save**

<div><figure><img src="/files/JnEsQYs2ALqKYKHac4Cu" alt=""><figcaption></figcaption></figure> <figure><img src="/files/TxgpabvF7Spi9kUqbrre" alt=""><figcaption></figcaption></figure></div>


# Zoho CRM

This guide will show you how to whitelist your GoodAccess IP address in Zoho CRM.

## Step 1

* ​[**Login to Zoho CRM**](https://www.zoho.com/crm/) using an account with **admin privileges**
* Go to **Setup** > **Zoho Directory** > **Security Policies**

<figure><img src="/files/UFjqh5uavzPaOmazUKcC" alt=""><figcaption></figcaption></figure>

## Step 2

* Choose **+Add Security policy** (top right corner) or edit **Default Policy**
* Go to **Allowed IPs** and click on **Add IP address**
* Enter **GoodAccess Gateway IP** or use the current IP if you are connected to GoodAccess

<div><figure><img src="/files/fMmSFaaqr54E1S5kzkGA" alt=""><figcaption></figcaption></figure> <figure><img src="/files/9EH0ZU5BFC5dVXXkGuua" alt=""><figcaption></figcaption></figure></div>


# Linux

These configuration guides will teach you how to install the GoodAccess Client Application to various Linux distributions.

{% hint style="info" %}
**System requirements:**

* **Desktop Environment:** Modern desktop environment (e.g., **GNOME**, **KDE**, or similar).
* **Init System:** `systemd`
* **Web Browser:** Modern web browser with Deep Link support (e.g., Firefox, Chrome, etc.).
* **Dependencies:** `libc6`, `libstdc++`, `dmidecode`, `ping`
* **Privileges:** Admin rights (sudo) within the OS (required to install and run GoodAccessService).
* **Architecture:** Only **x86\_64 (amd64)** is currently supported.
  {% endhint %}

Choose one of the install options depending on your Linux distribution:

* [DEB repository](/configuration-guides/linux/deb-repository) - Ubuntu, Debian, Mint, etc.
* [RPM repository](/configuration-guides/linux/rpm-repository) - Fedora, Redhat, Rocky, CentOS (Stream), etc.
* [Manual installation](/configuration-guides/linux/manual-installation) - All mentioned above


# DEB repository

This guide will show you how to install the GoodAccess Client Application using the GoodAccess DEB repository.

## Step 1 - Adding the repository to the OS

Add the GoodAccess repository to the OS using the following script.

{% code fullWidth="false" %}

```
sudo wget -O /etc/apt/sources.list.d/goodaccess.list https://goodaccess-storage.b-cdn.net/applications/prod/linux/repos/deb/goodaccess.list
```

{% endcode %}

<figure><img src="/files/exB4b0Ars4nMR5qLvwKs" alt="Linux terminal displaying the script from Step 1."><figcaption><p>Linux terminal displaying the script from Step 1</p></figcaption></figure>

## Step 2 - Adding the GPG public key to the OS

Add the GPG public key to the OS using the following script.

Used to validate packages from our repository.

{% code fullWidth="false" %}

```
sudo wget -O /etc/apt/trusted.gpg.d/goodaccess.gpg https://goodaccess-storage.b-cdn.net/applications/prod/linux/repos/deb/goodaccess.gpg
```

{% endcode %}

<figure><img src="/files/SeRnEM7YeeHSmCg93Wrw" alt="Linux terminal displaying the script from Step 2."><figcaption><p>Linux terminal displaying the script from Step 2</p></figcaption></figure>

## Step 3 - Updating the list of packages from all repositories

Update the list of packages from all repositories using the following script.

```
sudo apt update
```

<figure><img src="/files/kekTw0AkWY9IlU4n9zSY" alt="Linux terminal displaying the script from Step 3."><figcaption><p>Linux terminal displaying the script from Step 3</p></figcaption></figure>

## Step 4 - Installing the "goodaccess" client package

Install the "goodaccess" client package using the following script.

The installer also installs missing dependencies (libc6, libstdc++, iputils-ping, dmidecode).

```
sudo apt install goodaccess
```

<figure><img src="/files/ehIgG3hd0GdDcOecFsUO" alt="Linux terminal displaying the script from Step 4."><figcaption><p>Linux terminal displaying the script from Step 4</p></figcaption></figure>

You have now successfully installed the GoodAccess Client Application.

{% hint style="info" %}
**If you are experiencing problems:**

* check our [Linux Troubleshooting](/configuration-guides/linux/linux-troubleshooting)
* or [contact our technical support](https://www.goodaccess.com/contact)
  {% endhint %}


# RPM repository

This guide will show you how to install the GoodAccess Client Application using the GoodAccess RPM repository.

## Step 1 - Adding the repository to the OS

Add the GoodAccess repository to the OS using the following script.

```
sudo wget -O /etc/yum.repos.d/goodaccess.repo https://goodaccess-storage.b-cdn.net/applications/prod/linux/repos/rpm/goodaccess.repo
```

<figure><img src="/files/lnkVyfBsb4KTpio1pyOv" alt="Linux terminal displaying the script from Step 1."><figcaption><p>Linux terminal displaying the script from Step 1</p></figcaption></figure>

## Step 2 - Updating the list of packages from all repositories

Update the list of packages from all repositories using the following script.

```
sudo dnf update
```

<figure><img src="/files/IdMCI0ra4UTA9E0pBag7" alt="Linux terminal displaying the script from Step 2."><figcaption><p>Linux terminal displaying the script from Step 2</p></figcaption></figure>

## Step 3 - Installing the "goodaccess" client package

Install the "goodaccess" client package using the following script.

The installer also installs missing dependencies (libc6, libstdc++, iputils-ping, dmidecode).

```
sudo dnf install goodaccess
```

<figure><img src="/files/59kWTq1I3ALvBrN50QND" alt="Linux terminal displaying the script from Step 3."><figcaption><p>Linux terminal displaying the script from Step 3</p></figcaption></figure>

You have now successfully installed the GoodAccess Client Application.

{% hint style="info" %}
**If you are experiencing any problems:**

* check our [Linux Troubleshooting](/configuration-guides/linux/linux-troubleshooting)
* or [contact our technical support](https://www.goodaccess.com/contact)
  {% endhint %}


# Manual installation

This guide will show you how to manually install the GoodAccess Client Application using downloaded packages.

## 1. DEB package - Debian, Mint, Ubuntu, etc.

[Download the DEB installation package](https://link.goodaccess.com/download-linux-deb) and install it using the following script.

Replace "x.x.xx-x" in the script with the version number of the file you downloaded.

```
sudo apt install ./goodaccess_x.x.xx-x_amd64.deb
```

## 2. RPM package - CentOS, Fedora, Redhat, Rocky, etc.

[Download the RPM installation package](https://link.goodaccess.com/download-linux-rpm) and install it using the following script (admin rights required).

Replace "x.x.xx-x" in the script with the version number of the file you downloaded.

```
sudo rpm -ivh ./goodaccess-x.x.xx-x.x86_64.rpm
```

You have now successfully installed the GoodAccess Client Application.

{% hint style="info" %}
**If you are experiencing any problems:**

* check our [Linux Troubleshooting](/configuration-guides/linux/linux-troubleshooting)
* or [contact our technical support](https://www.goodaccess.com/contact)
  {% endhint %}


# Linux Troubleshooting

These guidelines will show you how to troubleshoot any issue you may encounter.

{% hint style="info" %}
In case you aren't able to resolve your issue with the following guidelines, please [contact our technical support](https://www.goodaccess.com/contact).
{% endhint %}

<details>

<summary>Tray Icon missing</summary>

* Install Gnome Extension "[Tray Icons: Reloaded](https://extensions.gnome.org/extension/2890/tray-icons-reloaded/)"

</details>

<details>

<summary>I can't connect</summary>

Using the following script, check if the GoodAccessService is running and enabled after boot.

* active (running)
* loaded (enabled)

```
systemctl status goodaccess
```

<img src="/files/dOnhWA7GcjgC3K9NYvfE" alt="Linux terminal displaying the script with highlighted important information." data-size="original">

</details>


# FAQ

In this section you will find Frequently Asked Questions and their answers.

{% content-ref url="/pages/zq7bi3UXwingcEq2Q7W9" %}
[Business](/faq-and-troubleshooting/faq/business)
{% endcontent-ref %}

{% content-ref url="/pages/AMmXsp91KYN1FQPUJBuA" %}
[Technical](/faq-and-troubleshooting/faq/technical)
{% endcontent-ref %}


# Business

In this section you will find business-related Frequently Asked Questions and answers.

{% hint style="info" %}
In case you can't find an answer to your question, please [contact us](https://www.goodaccess.com/contact).
{% endhint %}

<details>

<summary>What payments methods do you support?</summary>

We support PayPal and credit/debit card payments (VISA, Mastercard, American Express, Apple Pay, Google Pay). It is also possible to arrange a Wire transfer with our [sales representative](https://www.goodaccess.com/contact) (annual payments only).

We do not accept any payments in cryptocurrencies.

</details>

<details>

<summary>What are the available Gateway locations?</summary>

You may find the list of all available locations [here](https://www.goodaccess.com/goodaccess-gateway-locations#where-are-ga-gateways).

</details>

<details>

<summary>How do I get an additional IP or Gateway?</summary>

You may purchase an additional IP/Gateway in [Control Panel > Network > Gateways > Buy more Gateways](https://app.goodaccess.com/gateways/).

</details>

<details>

<summary>Where do I find my invoices?</summary>

You can find your invoices in [Control Panel > Account (top right corner) > Payments & Subscriptions](https://account.goodaccess.com/payments/).

You can appoint another person to the Admin or Accountant role if you need them to have access to your invoices.

</details>

<details>

<summary>How do I change the account/billing details?</summary>

You can change your account/billing details in [Control Panel > Account (top right corner) > Account Info](https://account.goodaccess.com/).

</details>

<details>

<summary>How do I change an account owner?</summary>

To change an account owner, please [contact us](https://www.goodaccess.com/contact).

</details>

<details>

<summary>Do you have a partner or affiliate program?</summary>

Yes, we do, for more information please visit the below links:

* [Affiliate](https://www.goodaccess.com/affiliate)
* [Partner](https://www.goodaccess.com/partners)

</details>

<details>

<summary>Do you have a plan for fewer than 5 users?</summary>

Yes, you can use the service with fewer than 5 users. Please check out our offer for [small teams](https://www.goodaccess.com/small-teams).

</details>

<details>

<summary>How do I downgrade a subscription plan?</summary>

To downgrade a subscription plan of your Team, please [contact us](https://www.goodaccess.com/contact).

Please note that by downgrading the subscription plan, your Team loses access to all Features not included in the new plan and their configurations.

</details>

<details>

<summary>How do I request a refund?</summary>

To request a refund of a service, please [contact us](https://www.goodaccess.com/contact).

</details>

<details>

<summary>How do I close/cancel my account?</summary>

You can close your account in [Control Panel > Account (top right corner) > Account Info](https://account.goodaccess.com/).

You can only close your account when your service has expired or has been canceled. If your service is still active please [contact us](https://www.goodaccess.com/contact).

Please note that by closing your account, we lose all your information and contact history, in keeping with GDPR rules.

</details>


# Technical

In this section you will find Frequently Asked Questions and answers related to the technical aspects of GoodAccess.

{% hint style="info" %}
If you can't find an answer to your question, please [contact us](https://www.goodaccess.com/contact).
{% endhint %}

<details>

<summary>What is a Team Name?</summary>

Team Name is a unique identifier for a group of users (employees) who share access to the same resources and have common settings, policies, and permissions. A Team Name is chosen by the Team Owner when setting up a new Team.

You may find the Team Name in the email invitation to the Team or you can ask your Team Admin.

</details>

<details>

<summary>How to reset my password?</summary>

Passwords can be reset via the [Forgot Password?](https://identity.goodaccess.com/#forgotten_password) link directly on the login page.

</details>

<details>

<summary>How do I reset my MFA?</summary>

To reset your Multi-factor Authentication (MFA), ask your Team Admin or [contact our technical support](https://www.goodaccess.com/contact).

Team Admin can reset user's MFA in [Control Panel > Members > Edit button of the Member](https://app.goodaccess.com/team-members/). This action is not performed immediately but requires the user to take action upon receiving an email and precisely navigate to setting up a new MFA; the old MFA is invalidated after the new one is set up.

</details>

<details>

<summary>Where do I get the OpenVPN Configuration file and credentials / CA Certificate /  Setup files?</summary>

{% hint style="warning" %}
**This feature is available upon email request by the Team Owner only.**
{% endhint %}

{% hint style="danger" %}
**Security Warning**

By downloading the setup files and using a third-party application, you **will bypass security features** such as [Device Posture Check (DPC)](/configuration-guides/features/zero-trust-access-control/device-posture-check), PIN protection, [Multi-Factor Authentication (MFA)](/configuration-guides/features/mfa), [Geo Restrictions](/configuration-guides/features/zero-trust-access-control/geo-restrictions), and other enforced controls.

**This action reduces the overall security of the perimeter** and may expose the environment to **increased risk**.
{% endhint %}

The Team Owner or Admin can download the OpenVPN configuration file and credentials / CA Certificate / Setup Files in [Control Panel > Members > Edit button of the Member](https://app.goodaccess.com/team-members/).\
They also have the option to send the OpenVPN configuration file and credentials via email directly to the Member.

The Team Owner is informed of every download or sending of these files

</details>

<details>

<summary>How do I invite a Control Panel Admin?</summary>

You can invite Admins and other roles in your [Control Panel > Settings > Admins & Roles](https://app.goodaccess.com/admin-roles/).

</details>

<details>

<summary>Is the IP address static and dedicated only to me?</summary>

Yes, we provide a public Static IP (IPv4) address which is dedicated only to your Team for the whole duration of your prepaid service.

</details>

<details>

<summary>Do I need any hardware (HW)?</summary>

GoodAccess is designed to be a hassle-free solution for secure remote access, and it does not require any hardware investments or maintenance, making it a cost-effective option for businesses of all sizes.

\
For more details please visit our [What is GoodAccess?](/getting-started/1.-what-is-goodaccess) section and [Architecture overview](/getting-started/2.-architecture-overview).

</details>

<details>

<summary>How can I make my server accessible via the GoodAccess static IP?</summary>

Connect your server to GoodAccess as client and enable [Port Forwarding](/configuration-guides/features/port-forwarding) on the Gateway to forward traffic to the server. This makes your server accessible via the GoodAccess static IP address and the port.

</details>

<details>

<summary>How to connect via RDP using GoodAccess?</summary>

You may connect to RDP using either a GoodAccess private or public IP address of the Gateway. We recommend using a private IP for higher security.

You may also add RDP into your Systems to ease access for your Members with a shortcut in GoodAccess Client Application.

**GoodAccess private IP address:**

* Each Team Member is assigned with a unique private IP address while connected to GoodAccess. All Members share same virtual LAN when connected to the same Gateway.
* Connected Members can use the private IP addresses to access another connected Member's device using RDP or other local tools.

**GoodAccess public IP address:**

* Enable [Port Forwarding](/configuration-guides/features/port-forwarding) on the Gateway to forward traffic to your Member. This makes your Member's device accessible via GoodAccess static IP address and the port.

</details>

<details>

<summary>What VPN protocols do you support?</summary>

We currently support OpenVPN and IKEv2 protocols.<br>

We are also working on implementing the WireGuard protocol which will be available during 2026.

</details>

<details>

<summary>How many devices can connect under one account?</summary>

One account can be connected with three devices at the same time.

</details>

<details>

<summary>My operating system (OS) is not supported. How can I connect?</summary>

{% hint style="warning" %}
**This feature is available upon request by the Team Owner only.**
{% endhint %}

You may also connect to GoodAccess Gateway on any device supporting an **OpenVPN Client** function with the use of manual configuration.

Your [OpenVPN Configuration file and credentials / CA Certificate / Setup files](#where-to-get-openvpn-configuration-file-and-credentials-ca-certificate-setup-files) can be used for example by:

* System-Native VPN Clients
* 3rd-Party VPN Clients (e.g., [OpenVPN Connect Client](https://openvpn.net/client/))

If you need any help with the setup, please [contact our technical support](https://www.goodaccess.com/contact).

</details>

<details>

<summary>How do I remove or change the location of the Gateway?</summary>

You may remove or change the location of your Gateway in [Control Panel > Network > Gateways > Edit button of the Gateway](https://app.goodaccess.com/gateways/).

Please note you may only change the location of your Gateway five times per month.

You can find a list of all available locations under this [link](https://www.goodaccess.com/goodaccess-gateway-locations#where-are-ga-gateways).

</details>

<details>

<summary>Do you support Port Forwarding?</summary>

Yes we do. For more information please visit our [Port Forwarding guide](/configuration-guides/features/port-forwarding).

</details>

<details>

<summary>Can I set up a rDNS/PTR record?</summary>

Yes, a reverse DNS (PTR) record can be set up for your Static IP. Please [contact our technical support](https://www.goodaccess.com/contact).

</details>

<details>

<summary>Do you have bandwidth limit?</summary>

No, we do not impose any bandwidth limits. You can use as much data as you need without restrictions.

</details>

<details>

<summary>Do you have a TTL (Time-to-Live) for established sessions?</summary>

Our connection sessions do not have a predefined TTL. As long as the client maintains a stable connection and no disruptions occur along the network path between the client and the Gateway, the session can remain active indefinitely.

</details>

<details>

<summary>Does it work with IPv6?</summary>

We do support the IPv6 protocol; however, we do not provide dedicated IPv6 addresses. You will get a real dedicated (static) IPv4 address.

</details>

<details>

<summary>Do you keep logs?</summary>

We do keep some logs for security and troubleshooting purposes, but the logs are only kept for a limited period.

The logs that we keep include connection logs, which record when a member connects or disconnects from the VPN service, and session logs, which record the user's IP address, device type, and the amount of data transferred during the session. These logs are used for troubleshooting issues with the service, ensuring the service's performance, and detecting and preventing unauthorized access.

However, we have a strict privacy policy and do not collect or store any personal information, browsing history, or user activity logs. GoodAccess does not sell or share any user data with third parties.

You can benefit from this feature as it ensures compliance with GDPR.&#x20;

For more information please refer to our [Privacy Policy](https://www.goodaccess.com/legal).

</details>

<details>

<summary>Do you have a high-availability solution?</summary>

Yes, we offer a high-availability solution for our customers in the form of a backup Gateway.

A single Gateway should be sufficient for most users. However, if you require 100% uptime (an enterprise high availability solution), we recommend using another geographically separated Gateway as a backup in the event of network maintenance or unpredictable network outages.

Choosing a Gateway closer to your Team is also useful to ensure better network latency.

</details>

<details>

<summary>Do you have a bug bounty hunter program?</summary>

Yes, we do have a bug bounty hunter program. You can send your findings to [security@goodaccess.com](mailto:support@goodaccess.com) where our specialists will evaluate the severity of the bug and reward you accordingly with gift cards.

</details>

<details>

<summary>Do you offer residential IPs?</summary>

No, we do not. We provide commercial IP addresses from datacenters.

</details>

<details>

<summary>What is SCIM?</summary>

SCIM, or System for Cross-domain Identity Management, is an open standard that enables the automation of **user provisioning**.

Simply put, if you use a third-party identity provider with SCIM enabled, any action affecting users (add, edit, delete) is automatically synchronized with GoodAccess Members. \
\
It allows you to manage all user provisioning on the third-party identity provider side.&#x20;

</details>

<details>

<summary>What is a Persistent connection?</summary>

Persistent connection allows you to connect a Windows device to the GoodAccess Gateway without dependency on the current Windows User. It means that the device will stay connected even though you are logged out from your Windows account. This is essential in cases like connecting an RDP Server/System as a Member to the GoodAccess Gateway. This feature is available on Windows only.

</details>


# Troubleshooting

These guidelines will show you how to troubleshoot any issue you may encounter.

{% hint style="info" %}
In case you aren't able to resolve your issue with the following guidelines, please [contact our technical support](https://www.goodaccess.com/contact).
{% endhint %}

<details>

<summary>I can't log in to GoodAccess</summary>

* Make sure you are entering the correct Team Name and Username
  * Double-check for any typos or case sensitivity issues
* If your Team uses Single Sign-On, ensure you're selecting the correct Identity Provider
* Make sure you are an active Member of the Team
  * You can verify your membership status with your GoodAccess Admin
* [Reset your password](https://identity.goodaccess.com/)

</details>

<details>

<summary>I can't connect with the GoodAccess Client Application (error code 8001, 8002, 8003,..)</summary>

* Change the VPN protocol in the App's settings (OpenVPN/IKEv2)
* Restart your device/router
* Make sure you are not using any other VPN, proxy, or anonymizer at the same time
* Uninstall the application and [download and install the latest version](https://www.goodaccess.com/download)
* Make sure GoodAccess is not blocked by antivirus or firewall
* Try to connect with different device or internet connection

</details>

<details>

<summary>Frequent disconnects</summary>

* Change the VPN protocol in the App's settings (OpenVPN/IKEv2)
* Make sure you are not using any other VPN, proxy or anonymizer at the same time
* Verify the stability of your regular internet connection
* Restart your device/router

</details>

<details>

<summary>IP didn't change</summary>

You may check your IP at [Google](https://www.google.com/search?q=what+is+my+ip), [Whats My IP](https://whatsmyip.com/), or another tool.

* Make sure the GoodAccess Client Application is connected
* Make sure you are not using any other VPN, proxy, or anonymizer at the same time
* Change the VPN protocol in the App's settings (OpenVPN/IKEv2)
* Restart your device/router

If your team uses [Split Tunneling](/configuration-guides/features/split-tunneling), you will not see your IP changing unless the website you are using to verify the IP is configured to work with this feature.

</details>

<details>

<summary>No internet access after a successful connection</summary>

* [Check if your IP has changed](#ip-didnt-change)
* Change the VPN protocol in the App's settings (OpenVPN/IKEv2)
* Restart your device/router
* Make sure you are not using any other VPN, proxy, or anonymizer at the same time
* Uninstall the application and [download and install the latest version](https://www.goodaccess.com/download)

</details>

<details>

<summary>Website access blocked</summary>

When accessing an IP whitelisted website:

* [Check if your IP has changed](#ip-didnt-change)

When the access is blocked by a public website:

* Try to access the website without GoodAccess
* Make sure the website is accessible from the location of your GoodAccess Gateway - some public websites may use filters that restrict access from certain countries.

When the "You have been protected!" message by GoodAccess appears:

* It means the website was detected as malicious and blocked by our [Threat Blocker](/configuration-guides/features/threat-blocker) feature. If you believe this is a mistake, or you own the website, please [contact our technical support](https://www.goodaccess.com/contact) with any additional information and we will review the case.

</details>

<details>

<summary>Can't access our System</summary>

* [Check if your IP has changed](#ip-didnt-change)
* Make sure the System is working for others, alternatively contact your Admin

If your team uses [Zero Trust Access Control](/configuration-guides/features/zero-trust-access-control/access-cards), ask your admin to check if you are assigned the correct Access Card.

</details>

<details>

<summary>Wrong geolocation</summary>

When your location displays differently than your GoodAccess Gateway:

* [Check if your IP has changed](#ip-didnt-change)

When Google search results give a wrong location or language:

* It is because Google makes best effort to customize user experience in many countries and regions around the world. Google tries to look up your device IP in their database to determine the approximate location. However there are no IPs in the world that haven't been used before, so every IP has its history. Therefore you may get the wrong default location or language in Google search and all its services (Maps, News, etc.). This also affects any 3rd-party websites using Google APIs for getting location based on a signed account or IP address.&#x20;
* The first thing to do is report this problem to Google so they can update their databases. You can do this via <https://support.google.com/websearch/contact/ip>. Meanwhile you can set this manually on your device:

  1\. Open the Google

  2\. Open Settings > Search settings in bottom right

  3\. Under Region Settings at the bottom of the page, select the corresponding region

</details>

<details>

<summary>Speed issues</summary>

1. Test the speed at <https://www.speedtest.net/> without GoodAccess. Before starting the test click on "Change Server" and select server in the same location as your GoodAccess Gateway.
2. Repeat the same test with GoodAccess using same test server and compare the results.

When the difference is too big:

* Change the VPN protocol in the App's settings (OpenVPN/IKEv2)
* Restart your device
* Restart your router

The VPN connection can be slower than the regular internet connection because of several reasons. The encryption used by the VPN takes up some of the available bandwidth, meaning there is less space for data to travel, which can slow things down. The stronger the encryption, the slower the VPN connection. Another factor is the distance between the user and the VPN server, especially in long distances like connecting from the UK to the US. This is because the data has to travel through multiple network infrastructures and international peering, which can cause delays. The speed of the regular internet connection also matters. The faster the internet connection, the more data the VPN server and client have to process in a short period of time, meaning the VPN will affect a faster internet connection more than a slower one.

</details>


# Windows

Stay up-to-date with the latest changes and enhancements in our Product Changelog for Windows.

## \[4.7.19] - 2026-07-21

#### Fixed

* General stability and performance improvements.

## \[4.7.18] - 2026-06-10

#### Changed

* Updated the OpenVPN TAP adapter to support DCO for enhanced protocol performance.

#### Fixed

* General stability and performance improvements.

## \[4.7.16] - 2026-05-21

#### Fixed

* General stability and performance improvements.

## \[4.7.13] - 2026-05-18

#### Added

* Localization support for Czech, French, German, Italian, Japanese, Polish, Portuguese (Brazil), and Spanish.

#### Changed

* Tray enhancements.
* Recommended Gateway enhancements.

#### Fixed

* General stability and performance improvements.

## \[4.7.8] - 2026-05-06

#### Fixed

* Issue with handling gateway changes while connected.
* General stability and performance improvements.

## \[4.7.4] - 2026-04-27

#### Fixed

* General stability and performance improvements.

## \[4.7.1] - 2026-04-20

#### Changed

* Logging system updated.

#### Fixed

* Bug affecting the automatic updates.

## \[4.7.0] - 2026-04-20

#### Added

* Automatic application updates - the app can now update itself in the background.

#### Fixed

* General stability and performance improvements.

## \[4.6.12] - 2025-10-02

#### Added

* Option to change the OpenVPN management port upon request (resolves port collision issues).

#### Changed

* API handling approach updated for better reliability.

## \[4.6.11] - 2025-08-06

#### Added

* Major upgrade to the underlying technology powering our UI application.
* Unified graphics alignment across all platforms.
* Unified Windows builds: `.exe` and `.msi` files are now platform-independent — they work on both AMD and ARM architectures.
* Antivirus detection support for Windows Server.
* Registry comparison now supports: Equal, Greater, or Less conditions.
* PIN reset: Team admins can now reset user PINs directly from the Control Panel.
* Device Posture Check can now detect the SMBv1 protocol.
* "Open Logs" option has been added to the settings, allowing quick access to the logs folder.
* Logs entries now include the system's time zone for better clarity.
* Logs are now automatically cleared after 14 days to save disk space.

## \[4.6.5] - 2025-06-25

#### Fixed

* Issues related to Always On functionality.
* Problems affecting Persistent behavior.
* UI/UX bugs.
* PIN-related problems.
* General performance improvements.

## \[4.6.0] - 2025-02-26

#### Added

* PIN & biometrics authentication.
* Recommended Gateway feature.

#### Fixed

* Device Posture Check data optimization.

## \[4.5.0] - 2024-10-23

#### Added

* Device Approval feature.
* Geo Restrictions feature.

## \[4.4.2] - 2024-05-07

#### Fixed

* Bug fixes and performance improvements.

## \[4.4.0] - 2024-04-10

#### Added

* Device Posture Check feature.

#### Changed

* Login to the application using the website only.

## \[4.3.0] - 2024-01-31

#### Added

* Forced Always-On.
* Real-time communication between Control Panel and Client Application.

#### Fixed

* Device inventory issues when internet connection is down.

## \[4.2.0] - 2023-12-04

#### Added

* Advanced device inventory - collecting more data to show in Control Panel.
* Change gateway while connected - reconnect to chosen gateway.

#### Changed

* Always On unification.

#### Fixed

* Persistent - log out after PC start.

## \[4.1.0] - 2023-07-17

#### Added

* Home screen animation.
* Settings features description.

#### Changed

* Internet connection handling improving.
* Updating libraries - security reasons.
* Storage of data.

#### Fixed

* Reconnection issues.
* UUID format for device inventory.

## \[4.0.1] - 2023-06-12

#### Fixed

* Run the client without administrator rights - some devices require administrator rights to run because they have issues with registry manipulation.

## \[4.0.0] - 2023-06-05

#### **Added**

* Options to change between light/dark mode.
* Whitelabeling for partners.
* Favorite systems shorcuts on home screen.
* System shorcut tooltip for long named systems.
* Search for systems shortcuts.

#### **Changed**

* Brand new graphic design.
* Background service runs on new version of .NET Core 6.

#### **Fixed**

* Connection stabilization.

## \[3.4.2] - 2023-04-25

#### Added

* Get device information for device inventory.
* Optional argument for persistent (MSI only).

## \[3.4.0] - 2022-12-16

#### Added

* Persistent connection. When persistent is enabled, the VPN will remain connected even after you log out or switch Windows user accounts (the connection runs as a service).
* Registry reading for the MSI package. Set up default protocol, team name, and auto updates during installation.

#### Fixed

* Reconnecting with OpenVPN protocol.

## \[3.3.4] - 2022-11-15

#### Added

* Application reacts to the Windows taskbar theme and changes color of the tray icon based on the taskbar theme.
* Error codes for better indication of errors.

#### Changed

* The way the application gets data => problem when 90% of the team cannot even verify team.
* Error and warning messages.

#### Fixed

* When the application is connected and update downloaded, the application sends a disconnect request before installation (bug - connection stayed after installation).
* Disabled mouse third and fourth button for forward and back action.
* Service dropped and started when application is running. Service dropped exception.

## \[3.3.2] - 2022-11-04

#### Fixed

* Background service working bug fix.

## \[3.3.1] - 2022-11-02

#### Changed

* Change tap adapter. This new adapter allows us to access up to 1 Gbit/s speed.

#### Fixed

* Check connection for larger teams - problem with IP range.
* UX bug with shortcuts carousel - teams using many systems shortcuts.

## \[3.3.0] - 2022-10-31

#### Added

* Always-on feature - app remembers the last status of connection.
* No internet connection detection.
* Control connection from the tray icon.

#### Changed

* Notification system.


# macOS

Stay up-to-date with the latest changes and enhancements in our Product Changelog for macOS.

## \[4.7.14] - 2026-05-18

#### Added

* Localization support for Czech, French, German, Italian, Japanese, Polish, Portuguese (Brazil), and Spanish.

#### Changed

* Recommended Gateway enhancements.

#### Fixed

* General stability and performance improvements.

## \[4.7.0] - 2025-11-26

#### Added

* Automatic application updates - the app can now update itself in the background.
* General Improvements

## \[4.6.5] - 2025-09-24

#### Added

* PIN reset: Team admins can now reset user PINs directly from the Control Panel
* "Open Logs" option has been added to the settings, allowing quick access to the logs folder
* Logs entries now include the system's time zone for better clarity
* Logs are now automatically cleared after 14 days to save disk space

## \[4.6.4] - 2025-06-26

#### Fixed

* Unification of the graphic design.
* PIN-related problems.

## \[4.6.3] - 2025-05-28

#### Fixed

* Issue with OpenVPN connection.
* Issue with AlwaysON feature.

## \[4.6.2] - 2025-05-21

#### Fixed

* Logging out of the app too often.

## \[4.6.1] - 2025-04-16

#### Changed

* No OpenVPN installation.

## \[4.6.0] - 2025-02-05

#### Added

* PIN & biometrics authentication.
* Recommended Gateway feature.

#### Changed

* Update window includes link to download new version.

#### Fixed

* Helper installation request now occurs only when creating a connection using OpenVPN.

## \[4.5.1] - 2024-12-18

#### Fixed

* Issue with opening application window after macOS startup.

## \[4.5.0] - 2024-11-05

#### Added

* Device Approval feature.
* Geo Restrictions feature.


