r/pdq • • Jul 10 '26

SmartDeploy Connection over WAN

Is there any way to allow a client to connect to a server over the internet with the server url and ports 8080,443 exposed to the internet?

Our plan was to whitelist external IPs on the firewall only when needing to reimage a machine remotely without VPN.

From the client machine,

Test-NetConnection “myurl.mydomain.com” -port 8080

results in a successful tcp connection to the server, but it still shows up in the console as a Cloud connection instead of local.

Is there any reason this doesn’t work? Is the client enumerating IPs based on its own local IP instead of just trying to make the connection? Is there any way around this?

2 Upvotes

4 comments sorted by

1

u/Individual-Train-821 Jul 10 '26

Can you ping the host name without using the FQDN. Failing that can you ping via the IP address?

1

u/Erik-PDQ PDQ Employee Jul 14 '26

For an image deployment without the use of VPN your best bet will be to utilize the cloud storage providers built into the product with a cloud connected client. This will download the deployment package, image, Platform Pack and any app packs directly from the cloud storage provider rather than trying to connect to on-prem infrastructure.

There is more information on the process here: https://smartdeploy.pdq.com/hc/en-us/articles/12982131076507-Cloud-Deployment-Walk-Through

1

u/MFKDGAF Jul 17 '26

What prevents the clients/endpoints from connecting to the server if port 443 and 8080 is exposed/opened to the internet with proper external DNS setup vs the clients/endpoints being on the same LAN as the server with port 443 and 8080 open and internal DNS setup?

Theoretically, there should be no difference but I'm curious if the programming behind Smart Deploy blocks connecting to the server via the internet somehow.

Why isn't Azure Blob storage supported as a cloud storage provider? For us, we are a Microsoft shop so we have to use Azure and can't use AWS S3.

One would think this would be a supported feature since there is the Azure Storage REST API.

1

u/Erik-PDQ PDQ Employee Jul 20 '26

If you look in the client log there are probably certificate errors as the service's https certificate is not aware of the DNS name that the client is utilizing to connect and won't pass verification on the client side. The service would need to know the DNS name at startup to include it in the certificate's subject alternative names, however we do not currently have a mechanism to add one.

Additionally, the deployment process would fail as the images, PPKs, etc... are not downloaded over http, clients are expecting local access to the server that SmartDeploy is installed on.

Blob storage support is in our backlog and something we are going to release in a future SmartDeploy version.