Genesys Engage on-premises

 View Only

Discussion Thread View
  • 1.  CME Application restriction

    Posted 01-23-2020 03:28
    Hi Team,

    Is there is any way by which we can restrict CME access from any desktop or server.

    we tried to remove access from default application but it will cause problem to GA application where we are giving application name.

    Even tried to create separate application for GA but if we login cme with that application then it gets logged in.

    #ArchitectureandDesign

    ------------------------------
    Shrinivas Gadas
    Reliance Jio Infocomm Ltd
    ------------------------------


  • 2.  RE: CME Application restriction

    Posted 01-23-2020 03:45
    I would recommend achieving this with the help of a server's firewall application by blocking the CME port access for the desktop or server. Hope this helps.

    Regards,
    Anil Bajaj

    ------------------------------
    Anil Bajaj
    Moksa Technologies Pvt. Ltd.
    ------------------------------



  • 3.  RE: CME Application restriction

    Posted 01-23-2020 05:14
    Thanks Anil,

    We have raised this with internal team however is there is any way in Genesys by which we can handle this rather than firewall exception.

    ------------------------------
    Shrinivas Gadas
    Reliance Jio Infocomm Ltd
    ------------------------------



  • 4.  RE: CME Application restriction

    Posted 01-23-2020 07:40
    No Srinivas, As per my understanding there is no way we can disable access to CME application from desktop or server.

    ------------------------------
    Anil Bajaj
    Moksa Technologies Pvt. Ltd.
    ------------------------------



  • 5.  RE: CME Application restriction

    GENESYS
    Posted 01-23-2020 09:55
    Edited by Rafael Marciano BELISRCIANO 01-23-2020 09:59
    Hi Shrinivas,


    It's a little tricky, and will require some (a lot) of work depending how your environment is configured.

    One way I used in the past was:

    I made a backup of Config Server DB (in case something went wrong, I could revert it back to its original state).

    1 - From CME, using the default account, I accessed the Configuration folder's properties, and removed the privileges of all users but the default account for this particular folder. Make sure to take notes of the original settings there before removing all privileges (if you don't want to remove it, you can put "No Access" instead).

    2 - BUT once you do that, these changes will be PROPAGATED to the Tenant, and everyone's access will be removed as well.

    3 - Then, I accessed the Tenant's properties (still from CME) and put the privileges back to all users according to the settings you originally had in the Configuration Folder, making sure the "Propagate" checkbox is checked..

    That will prevent users from accessing CME and still grant access to GA / GAX.

    With that being said, I would strongly recommend you to test it in a Dev / Test environment, because if you have any custom access groups configured, or if you had made changes in the permissions for the default access groups, the steps I wrote above will remove all of these custom permissions and replace the privileges by the ones you set at the Tenant level (Step 3).

    So, basically, it is possible to do it, but if you have a complex Security Schema already implemented in your environment, that might be taken into account before doing it.


    Hope that helps.

    ------------------------------
    Rafael Marciano
    ------------------------------



  • 6.  RE: CME Application restriction

    Posted 01-23-2020 10:32
    Thanks Rafael ,

    I will check this in lower environment and update soon.


    ------------------------------
    Shrinivas Gadas
    Reliance Jio Infocomm Ltd
    ------------------------------



  • 7.  RE: CME Application restriction

    Posted 01-24-2020 05:54
    Thanks a lot Rafael ,

    We are done provided configuration in lower environment and Its working as per requirement.

    Thank you so much for in details configuration information.


    ------------------------------
    Shrinivas Gadas
    Reliance Jio Infocomm Ltd
    ------------------------------



  • 8.  RE: CME Application restriction

    Posted 01-24-2020 09:32
    Firewall.
    Block the access to the ConfigServer port from any except the Genesys Servers and Agents / supervisors positions.
    If you supervisor use CME, Remove the app!

    And use the log from ConfigServer for found the transgressor.


    ------------------------------
    Rodrigo Hernandez
    ------------------------------



Need Help finding something?

Check out the Genesys Knowledge Network - your all-in-one access point for Genesys resources