Antcas Hub

The Remote Access enables access via the portal Antcas Hub (https://antcas.cloud) from Antcas.

Note: To grant access to the Antcas Hub portal, you must have your company registered with Antcas. After that, you can apply for access to the service.

Functionality

The server maintains contact with the website hub.antcas.com via WebSocket. The connection is initiated by the server itself. Detected changes are transmitted. The TCP port can be configured, but it is not guaranteed that this will actually be used. This is especially true for a port change and Core 1.

Configuration

The configuration is done under Infrastructure Network Remote Access.

Note: The linking requires an internet connection from the server. In addition, a real-time connection must be active.

  1. Set the interface to Hub Mode or Legacy Mode (not recommended) there.
  2. Enter a name and optionally the location for the server under Name so that you can manage multiple servers.
  3. Now you only need to link the server with the portal. Click on Link... for this purpose
  4. Follow the instructions in the portal. You may need to log in and repeat the process in a new window.
  5. After the ID has been registered, you can click on Save. The server should appear in the portal after no more than 10 seconds.
  6. Be sure to check if remote access can be established. Possibly port forwarding is still missing (see below).

If the server does not appear, check the internet connection from the server.

Legacy Mode

Legacy mode is the previous method and connects via TCP/IP. For remote access to establish a connection, the outgoing TCP ports 443 and from 10'000 to 29'999 must be activated (LAN to WLAN). The server selects a random port when connecting. If remote maintenance is not used, the port is closed again after two minutes. Incoming rules do not need to be considered. Since the portal has several addresses, it is difficult to restrict communication based on addresses.

Note: This mode is no longer recommended as it is slower and less secure than the newer Hub Mode. If the connection fails in Hub Mode, it switches to Legacy Mode.

Hub Mode

The hub mode connects via TCP/IP and UDP/IP. The connection setup after the TCP handshake is established using WireGuard, the outgoing UDP port can be configured under Remote Access. This mode also allows access to the network via VPN. Further details on the VPN can be found in the Antcas Hub section under the chapter Remote Maintenance.

Note: The VPN to the portal is always active in hub mode. However, the use of user access and their IP assignment must be activated.

If this mode has been selected, a new network interface named remote appears. This uses the IPv6 address in the range fd26:2626:2626:2626::/64 to communicate with the portal. No access to other networks is possible from the portal on this address.

Note: The use of hub mode is explicitly recommended.

A random IPv4 address in the range 10.26.0.0/16 and an IPv6 address in the range fd26:26:26:26::/64 are used for communication with the VPN. These address ranges should not be reused in the server's network, as this can otherwise lead to conflicts. Without configuration of the network interface remote, it is only possible to access the server itself. To reach the server, an IP address of another interface of the server must be called. The addresses of the interface itself are blocked by the portal for security reasons. To access another network, the NAT settings can be adjusted in the network interface remote.

Note: IPv6 NAT only works with Core 2 or higher.

The interface has two endpoints each. The first enables direct access via the portal and is always active. The second connection is only opened when a user requests VPN access. Then the connection is started. To test the function, after a user has established a connection, the address 10.26.26.26 or fd26:26:26:26:26:26:26:26 can be pinged. Under Remote Access, the status of the ping from direct access is displayed. This is performed every minute to check the connection.

Note: The server itself cannot be reached via the displayed IP address. This has been deactivated for security reasons. If a NAT has been activated, another IP of the server can be pinged instead.

Updates

If this option was enabled under the Advanced tab, updates can be installed via the portal. This option is not recommended for larger updates.

Antcas Tunnel

Enables a tunnel connection without port forwarding. All information about this can be found in the chapter Antcas Tunnel.

Antcas DynDNS

Information on the DynDNS service can be found in the chapter DynDNS.

Note: Use Antcas DynDNS only if the service is actually needed, otherwise you will disclose the public IP of the installation.

Indicator Symbol

There is a symbol at the bottom right in the editor that displays the status of remote access. When opened, further details are displayed. These show the current status. For example, if the Hub Mode has been activated and the status shows Legacy Mode, then no connection can be established via UDP. The following states of the indicator are possible:

Symbol Description
Displayed when there is no connection to the websocket yet. The status of remote access is unknown.
Remote access is disabled.
The connection could not be established. Possible causes are:
  • No internet connection
  • DNS cannot be resolved
  • Firewall blocks the connection
  • Antcas Hub offline
  • The firewall of Antcas Hub has rejected the connection
The connection could not be established via the websocket. Now a connection is being established by polling. It may break off completely after a timeout. This state should definitely be observed for longer.
The connection could be established via real-time websocket. Functions such as Push, Antcas SMS or hyperglobal variables are possible.

Telephony

Under the Remote Access settings is the Telephony tab. The properties are necessary for visualization and are further explained in the Telephony chapter under WebRTC.

Proxy

The proxy settings are intended for use in restrictive or particularly protected networks. They enable the establishment of a secure connection via an intermediary proxy server.

The configuration affects communication with the portal as well as Cloud Mail, Cloud Uploads, the procurement of certificates and updates. Remote maintenance is not affected by this and takes place independently of the proxy settings defined here.

Warning: The DynDNS services and identification may not work correctly if the same public IP address is not used.

The protocols HTTP, SOCKS5 and SOCKS5 with hostname resolution via the proxy are supported. In the latter variant and HTTP, DNS resolution is not performed locally on the device but by the proxy server.

Note: When establishing a connection, an attempt is first made to establish the connection via the configured proxy. If this is not successful, another connection attempt is automatically made without a proxy.

Addresses

The portal uses several domains for communication, among others. These are listed here. The list may expand depending on the services.

Address Description IP
antcas.cloud Main Address IPv4, IPv6
hub.antcas.com Alternative Address IPv4, IPv6
service.antcas.com Communication Address IPv4
*.my.antcas.com DynDNS Addresses Depending on Configuration
my.antcas.com Access for End Customers IPv4, IPv6
find.antcas.com Antcas Searcher IPv4, IPv6
find4.antcas.com Antcas Searcher IPv4
find6.antcas.com Antcas Searcher IPv6
antcasmail.com Antcas Cloud Mail IPv4, IPv6
antcas.com Web Server for Updates IPv4, IPv6
setup.antcas.com Future Web Server for Updates IPv4, IPv6