If the identity certificate of the Federation™ host or remote site is modified while
the reverse tunnel is disconnected, you must reset the tunnel by generating and applying a new
keyfile.
What you should know
A tunnel reset is not required if the Federation host certificate is replaced while the
tunnel is connected. The new host certificate is propagated to the remote system
automatically.
For security reasons, a reverse tunnel keyfile can only be used once. The tunnel
keyfile is only needed to establish the first connection from the remote site to the
host.
Procedure
Generate a new keyfile on the Federation host:
In Genetec Configuration desktop, sign in to the Federation host system.
Open the System task and click Roles
> Reverse Tunnel Server
> Properties.
Select the site with the broken tunnel and click Force re-enrollment of
this site ().
Click OK
> Apply.
The status of the site reverts to Not
registered.
Get the keyfile by doing one of the following:
If your workstation can access the remote site, click Copy keyfile to
clipboard ().
If your workstation cannot access the remote site, click Save keyfile
to disk (), and specify the file location.
A file named
<SiteName>.keyfile is saved to the folder that you
select.
Apply the new keyfile to the remote site:
In Config Tool, sign in to the remote system.
Open the System task and click Roles
> Reverse Tunnel
> Properties.
(Optional) Select an Encryption option.
Important:
By default, connections to a Security
Center SaaS Federation host require encryption.
Encrypt
Encrypt video in transit from the remote site to the Federation host.
Prefer encryption
Encrypt video in transit if both the remote site and the Federation host
support TLS. Use this option if you are not certain of the capabilities of the
Federation host.
Do not encrypt
Do not encrypt video in transit. Only use this option if the video is
encrypted through other methods.
(Optional) Turn on the Create agents on role servers
option.
By default, servers hosting Directory, Media Router, and Redirector roles all
require internet access for reverse tunneling.
When this option is enabled, only
servers listed on the Resources need outbound internet access
for reverse tunneling.
Enter the keyfile by doing one of the following:
If the keyfile was copied to the clipboard, paste it into the Tunnel
keyfile field.
Click Select file (), browse for the keyfile,
and click Open.
Click Apply.
The Connection status changes to
Connected.
After you finish
Sign in to the Federation host and confirm that the status of
the remote site is Online.