ConnectWise ScreenConnect On-Premise, DNS Proxy problems

Answer these questions to help the Community help you with Security questions.

What is the domain name?
not publishing for security reasons

Have you searched for an answer?
Yes

Please share your search results url:

When you tested your domain, what were the results?
the website works, but machine check-ins and remote access to clients does not

Describe the issue you are having:
We have a self-hosted version of ConnectWise Screen connect. We want to use WAF to block out of country and other specific agents, so we have to enable DNS proxy for that to work, but the DNS proxy breaks the machine check-in and remote access using port 8041. I saw something about creating an origin rule, but I cannot find specifics on how to create this to allow traffic to work?

What error message or number are you receiving?

What steps have you taken to resolve the issue?

  1. I have disabled DNS proxy, site works and agent checkin/remote access works
  2. I have explored origin rule creation but it is not clear how to do this
  3. i have checked for other posts regarding creation and none of them have positive end results or instructions to share.

Was the site working with SSL prior to adding it to Cloudflare?
Yes

What are the steps to reproduce the error:

  1. enable DNS proxy for subdomain
  2. sign in as authenticated user
  3. check client status or try to remote connect to a machine

Have you tried from another browser and/or incognito mode?
yes, not relevant

Please attach a screenshot of the error:

Welcome to the Cloudflare Community. :logodrop:

TL;DR: You cannot do what you are attempting with the Cloudflare products you are using.

Mapping a port with an origin rule means that HTTPS traffic sent to TCP 443 of the Cloudflare proxy will be sent to the specified TCP port on the origin server. It does not cause the Cloudflare proxy to listen on any additional ports.

The Cloudflare proxy only passes HTTP and HTTPS traffic without a Spectrum plan.

Have you searched any ConnectWise communities to see if anyone has discussed their use of Cloudflare in their own deployments?

This topic was automatically closed 15 days after the last reply. New replies are no longer allowed.