Skip to main content
Hints and Tips Created Edited

Firewall NX API Server Connection Issue Guideline

 

image-20250122-071639.png

Normal Connection Status

 

Problem

When the user click the Connect button, but Status does not change.

 

Cause

Installed firewall on the users' computer can block "http Request" from internal(company) to external or refuse websocket connection.

image-20250122-072158.png

MIDAS API Connection schematic diagram

 

Solution

Please ask your Network Security department to allow the outbound connections required by MIDAS API and related online services.

Depending on your company's security policy, domain-based allowlisting, IP-based allowlisting, or both may be required.

 

1. URL / Domain Allowlist

Please allow access to the following domains required for MIDAS API and related online product functions.

URL / Domain Port Protocol Purpose
moa-engineers.midasit.com 443 HTTPS, WSS MIDAS API and online product feature integration
moa.midasit.com 443 HTTPS Web-based product features and service integration
moa-slaas.midasit.com 443 HTTPS Execution of web-based product features

 

2. MIDAS API Server IP Allowlist

If your company's security policy restricts outbound connections by destination IP address, please allow the IP address corresponding to your region.

The following IP addresses are used for moa-engineers.midasit.com.

IP Address Port Protocol Remarks
43.203.33.189 443 TCP moa-engineers.midasit.com / Africa, Antarctica, Asia, South Korea, Oceania
52.56.240.109 443 TCP moa-engineers.midasit.com / Europe, United Kingdom
100.25.210.56 443 TCP moa-engineers.midasit.com / North America, South America, United States
13.203.131.36 443 TCP moa-engineers.midasit.com / India

Note: These regional IP addresses apply only to moa-engineers.midasit.com.

 

3. Proxy / SSL Inspection

If your company uses a web proxy, SSL inspection, or SSL interception, communication with the MIDAS API server may still be blocked even after the required domain or IP address has been added to the allowlist.

In this case, please ask your Network Security department to check whether moa-engineers.midasit.com can be excluded from SSL inspection.

Please also verify that WSS (WebSocket Secure) communication over port 443 is permitted.

If WebSocket communication itself is blocked by the company's network policy, adding the domain or IP address to the allowlist alone will not resolve the connection issue.

 

Previous Experiences

  • Customer A Company

We proceeded to a SSL bypass to the URL provided by Midas.
We use a web proxy by which all user requests pass through. This web proxy performs SSL interception and certain hosts refuse this type of practice so it ends up getting blocked. We then excluded the URL from the SSL interception and it solved the issue"

 

  • Customer B Company

I’m part of the 'Some Company' Cybersecurity Architecture team and I assisted engineers in resolving the issue. The issue was related to the SSL inspection on our firewalls. Like many large companies, we perform SSL inspection on most of our traffic. We needed to exclude the API server(moa-engineers.midasit.com). access from SSL inspection, which resolved the issue.

0
Was this article helpful?