Skip to content
  • There are no suggestions because the search field is empty.

Restrict access to logon page from the internet

Learn how to restrict internet access to the PowerSyncPro logon page using IIS, reverse proxies, and network security best practices.

Overview

The PowerSyncPro Server needs to be continuously reachable over HTTPS (TCP port 443) by the Migration Agents running on each endpoint. This continuous connectivity allows the PowerSyncPro Migration Agent to register endpoints, query assigned runbooks and batches, and report migration telemetry regardless of whether the user is on the corporate network or working remotely.

However, exposing the entire web root to the public internet creates a security risk: unauthorized external users could attempt to access administrative management routes (such as /sync/syncProfiles or the admin logon portal).

To secure the deployment while maintaining full agent functionality, PowerSyncPro uses an IIS Reverse Proxy. By configuring specific rewrite rules, only the /agent URL path is exposed to the public internet, while all administrative management routes return an HTTP 403 Forbidden response to external requests.

Recommended solution: PowerSyncPro automated installation script

Legacy guidance recommended manually deploying or replacing the web.config file using outdated utility scripts (PSP-Replace-WebConfig.ps1).

The current best practice is to execute the PowerSyncPro Automated Installation Script (PSP_AutoInstall.ps1) with the -ReverseProxyOnly parameter.

What the -ReverseProxyOnly flag automates:

  1. Prerequisite Provisioning: Automatically detects, installs, and enables required IIS features, including Microsoft URL Rewrite and Application Request Routing (ARR).
  2. Reverse Proxy & web.config Lockdown: Generates and deploys a standardized, hardened web.config that locks down the administrative console to localhost (127.0.0.1) while keeping /agent (and all subpaths /agent/*) publicly reachable.
  3. SSL/TLS Profile Hardening: Automatically hardens the operating system's TLS/SSL profile by disabling legacy ciphers and weak protocols (SSL 3.0, TLS 1.0, TLS 1.1) on the host running PowerSyncPro.
  4. Certificate Management: Binds your chosen publicly trusted SSL certificate (Let's Encrypt, BYOC PFX, or an Existing trusted certificate) to IIS port 443 and configures auto-renewal tasks where applicable.
  5. Utility Tooling Setup: Drops the WebConfig_Editor.ps1 management script into C:\Scripts for straightforward IP whitelist management.

Step-by-step implementation guide

Step 1: Download the automated installation script

  1. Log in to the central PowerSyncPro Server via RDP.
  2. Open an elevated PowerShell prompt (Run as Administrator).
  3. Download PSP_AutoInstall.ps1 from the official PowerSyncPro GitHub Repository and save it to C:\Temp.

Step 2: Run the script in reverse proxy mode

Execute the script using the -ReverseProxyOnly flag:

.\PSP_AutoInstall.ps1 -ReverseProxyOnly  

Note: If PowerSyncPro is running on custom backend Kestrel ports (non-default), the script automatically reads the active port from appsettings.json. You can also explicitly specify custom backend URLs or standalone proxy targets using -PSPBackendUrl.

Step 3: Configure certificate & complete lockdown

When prompted by the interactive setup menu, select your publicly trusted certificate source:
  • Let's Encrypt: Automated provisioning for public FQDNs (requires port 80 open for HTTP-01 challenge).
  • Bring Your Own Certificate (BYOC): Imports a .pfx file and configures private key permissions.
  • Existing Certificate: Uses a trusted SSL certificate already installed in the server's LocalMachine\My certificate store.
  • Self Signed Certificate: Generates a self singed certificate for the server, this certificate would be manually trusted on each endpoint.

The script will automatically configure IIS ARR proxy rules, write the protected web.config to C:\inetpub\wwwroot\web.config, apply TLS cipher hardening, and restart the IIS and PowerSyncPro services.

Verifying the endpoint lockdown

After the script completes, test connectivity to verify that administrative routes are blocked externally while the Migration Agent endpoint remains functional:

Test Target URL Path Expected Result
Public Agent Endpoint https://psp.company.com/agent 200 OK (Displays the PowerSyncPro Migration Agent Information Endpoint page)
Public Admin Logon https://psp.company.com/Account/Login 403 Forbidden (Access denied from external networks)
Local Admin Console http://localhost:5000 200 OK (Accessible only when logged into the server locally or via RDP)

Managing administrative access via subnet whitelisting

If your administrative team needs to access the PowerSyncPro console remotely without logging into the server via RDP, you can whitelist specific corporate management subnets or IP addresses using WebConfig_Editor.ps1 located in C:\Scripts.

Open an elevated PowerShell prompt on the server and use the following commands:

  • View Current Allowed Subnets:
C:\Scripts\WebConfig_Editor.ps1   
  • Add a Management Subnet or IP:
C:\Scripts\WebConfig_Editor.ps1 -AddAllowedAddress 10.0.0.0/8   
  • Remove a Management Subnet or IP:
C:\Scripts\WebConfig_Editor.ps1 -RemoveAllowedAddress 10.0.0.0/8   

This ensures that administrative access remains strictly restricted to trusted internal networks while the public internet can only communicate with /agent.