XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Remote XCP-NG Connection Doesn't Show Console in XO

    Scheduled Pinned Locked Moved Solved Xen Orchestra
    11 Posts 3 Posters 4.6k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • SoarinS Offline
      Soarin
      last edited by

      Hello! I connected my friend's laptop XCP-NG up to my XenOrchestra so we can control his VMs remotely, I opened port 443 to his XCP-NG which allowed me to connect the server to my XO but I've noticed we can't see the console. Is there another port to be opened for the console to be streamed?

      Thank you!

      1 Reply Last reply Reply Quote 0
      • olivierlambertO Offline
        olivierlambert Vates 🪐 Co-Founder CEO
        last edited by olivierlambert

        XOA should be inside the same network. Accessing XOA from outside is OK (eg with port forwarding), but it's NOT if XOA has to go through the NAT itself.

        Why? Because some operations aren't passing directly through XAPI, but via different URL handlers. Eg when you request a console, XAPI will return the host local IP address (private range) to XO. So your XO will try to connect to this private IP outside this network and it will fail.

        In short: use XOA in the same network or use a tunnel/VPN to enjoy all features (console, export etc.)

        SoarinS 1 Reply Last reply Reply Quote 1
        • SoarinS Offline
          Soarin @olivierlambert
          last edited by

          @olivierlambert I see, thank you for the clarification. Already setting up a site-to-site for this, would that work?

          1 Reply Last reply Reply Quote 1
          • olivierlambertO Offline
            olivierlambert Vates 🪐 Co-Founder CEO
            last edited by olivierlambert

            Using a tunnel/VPN?

            • OpenVPN
            • Wireguard
            • GRE tunnel (with IPSEC if you want it to be secure)
            • PPTP (obsolete)
            • XO Proxies (recommended)

            There's a lot of solutions.

            Another way would be for us, in the future, to use our XO proxies to solve this without having to create tunnels. I think it might happen because there's a lot of use cases for this usage 🙂

            SoarinS 1 Reply Last reply Reply Quote 0
            • SoarinS Offline
              Soarin @olivierlambert
              last edited by

              @olivierlambert I'd love that proxy idea, but right now setting up a site-to-site OpenVPN setup right now. Thank you for the quick replies as always! ☺

              bullerwinsB 1 Reply Last reply Reply Quote 0
              • olivierlambertO Offline
                olivierlambert Vates 🪐 Co-Founder CEO
                last edited by

                You are welcome 🙂

                SoarinS 1 Reply Last reply Reply Quote 1
                • SoarinS Offline
                  Soarin @olivierlambert
                  last edited by

                  @olivierlambert Got it connected via the VPN and it works flawlessly now ☺

                  1 Reply Last reply Reply Quote 1
                  • olivierlambertO Offline
                    olivierlambert Vates 🪐 Co-Founder CEO
                    last edited by

                    Enjoy XO!

                    1 Reply Last reply Reply Quote 1
                    • bullerwinsB Offline
                      bullerwins @Soarin
                      last edited by

                      @Soarin Hi! Would you mind sharing what config did you use for openvpn?
                      Did you install openvpn in the xcp-ng host? in a vm?

                      1 Reply Last reply Reply Quote 1
                      • olivierlambertO Offline
                        olivierlambert Vates 🪐 Co-Founder CEO
                        last edited by

                        Note that the preferred way now is to use XO proxies in such scenarios: https://xen-orchestra.com/blog/xo-proxy-a-concrete-guide/

                        bullerwinsB 1 Reply Last reply Reply Quote 0
                        • bullerwinsB Offline
                          bullerwins @olivierlambert
                          last edited by

                          @olivierlambert I just saw Tom post about that. Already investigating about it. Thanks!
                          https://infosec.exchange/@tomlawrence/109404324178466606

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post