3.3 Starting and Stopping the Access Gateway

The Access Gateway has two processes that can be stopped and started: the Access Gateway and the Embedded Service Provider within the Access Gateway. Normally, you do not need to stop and start these services. However, if you need to change certain configuration options, you can be prompted to update the Access Gateway or to restart the Embedded Service Provider.

The following sections explain how to update, stop, start, and schedule a restart of the various Access Manager components:

3.3.1 Updating the Access Gateway

When a configuration change has been made, but not applied, the Access Gateway is in an Update status on the Access Gateways page. If the Access Gateway is a member of a cluster, the cluster is in an Update All status. You can click Update to apply the configuration change to a single Access Gateway or Update All to apply the configuration change to all members of a cluster.

If the changes have been saved to browser cache, but not to the configuration store, the changes are lost if your session times out before you apply the changes. The Access Gateway remains in an Update status, but when you click Update, there are no changes to apply. If you prefer to update members of a cluster one at a time, it is best to save the changes to the configuration datastore before applying them. Click Edit, then click Save.

When you click Update, three options are displayed:

  • When you have modified services of the Access Gateway, the update option for All Configuration is available. Depending upon what has been modified, updating might cause logged in users to lose data and their connections.

  • When the ESP logging settings have been modified on the Identity Server, the update option for Logging Settings is available. The Logging Settings option causes no interruption in services.

  • If a policy is modified that the server has enabled for a protected resource or a protected resource has a policy enabled or disabled and the policy changes are the only modifications that have occurred, the update option for Policy Settings is available. The Policy Settings option causes no interruption in services.

When you make the following configuration changes, the Update All option is the only option available and your site will be unavailable while the update occurs:

  • The Identity Server configuration that is used for authentication is changed. To access this option, click Access Gateways > Edit > Reverse Proxy/Authentication, then select a different value for the Identity Server Cluster option.

  • A different reverse proxy is selected to be used for authentication. To access this option, click Access Gateways > Edit > Reverse Proxy/Authentication, then select a different value for the Reverse Proxy option.

  • The protocol or port of the authenticating reverse proxy is modified. To access this option, click Access Gateways > Edit > Reverse Proxy/Authentication > [Name of Reverse Proxy], then change the SSL options or the port options.

  • The published DNS name of the authentication proxy service is modified. To access this option, click Access Gateways > Edit > Reverse Proxy/Authentication > [Name of Reverse Proxy] > [Name of First Proxy Service], then modify the Published DNS Name option.

3.3.2 Restarting the Access Gateway Service Provider

To stop and start the Access Gateway service provider:

  1. In the Administration Console, click Access Manager > Access Gateways, select the Access Gateway, then click Actions.

  2. Click Service Provider > Restart Service Provider, then click OK.

    In a few seconds, the Health icon of the Access Gateway should turn green.

3.3.3 Starting the Access Gateway Service Provider

When an Access Gateway is removed from a cluster configuration, the Embedded Service Provider is stopped. It should remain stopped until you have reconfigured the Access Gateway. When you have finished the reconfiguration, you should start the Embedded Service Provider.

  1. In the Administration Console, click Devices > Access Gateways, select the Access Gateway, then click Actions.

  2. Click Service Provider > Start Service Provider, then click OK.

    In a few seconds, the Health icon of the Access Gateway should turn green.

3.3.4 Stopping the Access Gateway Service Provider

Stopping the Embedded Service Provider is a quick way to make the Access Gateway inaccessible to users.

  1. In the Administration Console, click Devices > Access Gateways, select the Access Gateway, then click Actions.

  2. Click Service Provider > Stop Service Provider, then click OK.

    In a few seconds, the status icon of the Access Gateway should turn red.

3.3.5 Restarting the Access Gateway Appliance

For a Gateway Appliance, the Restart option is really a reboot option. The Access Gateway is stopped, the operating system is rebooted, then the Access Gateway is started.

Immediately Rebooting the Gateway Appliance

  1. In the Administration Console, click Devices > Access Gateways, select the Access Gateway.

  2. Click Restart.

    In a few minutes, the status icon of the Access Gateway should turn green.

Scheduling a Reboot of the Gateway Appliance

Rebooting the Access Gateway makes all protected resources unavailable until the Access Gateway returns to a server status of green. Scheduling this event allows you to pick the best time for your resources to be momentarily unavailable.

  1. In the Administration Console, click Devices > Access Gateways, select the Access Gateway, then click Actions.

  2. Click Schedule Reboot.

    The following field displays information about the command you are scheduling.

    Type: Displays the type of command that is being scheduled, such as Access Gateway Shutdown, Access Gateway Reboot, Access Gateway Upgrade, Device Configuration.

  3. Fill in the following fields:

    Name Scheduled Command: (Required) Specifies a name for this scheduled command. This name is used in log and trace files.

    Description: (Optional) Provides a field to describe the reason for the command.

    Date & Time: The drop-down menus allow you to select the day, month, year, hour, and minute when the command should execute.

  4. Click OK.

3.3.6 Stopping the Access Gateway Appliance

You should stop the Access Gateway Appliance only when you plan to turn off the power. After you have stopped the Access Gateway Appliance, you must have physical access to the machine to start it.

Immediately Stopping the Gateway Appliance

  1. In the Administration Console, click Devices > Access Gateways, select the Access Gateway, then click Stop.

  2. To confirm the shutdown, click OK.

The machine is physically turned off.

Scheduling the Shutdown of the Gateway Appliance

Scheduling a shutdown allows you to pick the best time for the Access Gateway to be unavailable.

  1. In the Administration Console, click Devices > Access Gateways, select the Access Gateway, then click Actions.

  2. Click Schedule Shutdown.

    The type field displays information about the command you are scheduling, such as Access Gateway Shutdown, Access Gateway Restart, Access Gateway Upgrade, Device Configuration

  3. Fill in the following fields:

    Name Scheduled Command: (Required) Specifies a name for this scheduled command. This name is used in log and trace files.

    Description: (Optional) Provides a field to describe the reason for the command.

    Date & Time: The drop-down menus allow you to select the day, month, year, hour, and minute when the command should execute.

  4. Click OK.

    The machine is turned off when the scheduled command executes.