With the Antcas Tunnel, a simple and secure remote access can be set up for end customers. The service is available free of charge for all licensed servers. Alternatively, an own
Cloudflare Tunnel can be configured and managed in Antcas Control.
The configuration of the tunnel is fully automated. The setup can be done both in the Project Management and in the
Project Configurator, analogous to the assignment of communication ports. After selecting a randomly generated address, it may take a few moments until the visualization is accessible via the tunnel. Before activation, the current version of the Cloudflare Tunnel service is automatically downloaded and installed on the server. Subsequently, the configuration is created and activated automatically.
Note: The availability of the service cannot be guaranteed as it is based on Cloudflare's infrastructure and thus depends on their availability. It is therefore recommended to set up a local access in addition to the Antcas Tunnel. For this purpose, for example, the local SSL certificate can be used. This ensures that access remains possible even if the tunnel service is temporarily unavailable.
If the use of the Antcas Tunnel is not permitted or not desired, it can be deactivated under
Infrastructure
Network
Remote Access
The server requires a connection to Cloudflare and to the
Antcas Hub for setup and operation. If no connection to the Antcas Hub is established within 90 days, the tunnel settings are automatically removed. The connection can be established via an HTTP proxy or a SOCKS5 proxy if needed.
If the server is behind a restrictive firewall, it must be ensured that outgoing connections to Cloudflare are possible. In particular, TCP and UDP port 7844 must be released. Further information can be found at:
https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/troubleshoot-tunnels/connectivity-prechecks/
Please also note the terms of use of Cloudflare:
After the initial setup of the tunnel, the VoIP connection may already work if the endpoint is in the same network as the server. However, if an attempt is made to establish the connection from outside the local network, the connection setup usually fails unless additional configuration has been performed.
For reliable operation of VoIP telephony, a STUN or TURN Server must therefore be configured. When using a STUN server, additional firewall or port forwarding rules may be required depending on the network environment. A TURN server, on the other hand, enables connection setup even without port forwarding and is therefore recommended for most installations via Antcas Tunnel.