<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is administering Server with Web Adaptor not recommended, but is often the only option?  in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/why-is-administering-server-with-web-adaptor-not/m-p/662381#M25282</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you haven't seen this already &lt;A class="link-titled" href="http://doc.arcgis.com/en/trust/security/arcgis-server-best-practices.htm" title="http://doc.arcgis.com/en/trust/security/arcgis-server-best-practices.htm"&gt;Server Implementation Guidance—Trust ArcGIS | ArcGIS&lt;/A&gt; if is worth a look.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I've been told is it &lt;EM&gt;is best&lt;/EM&gt; to disable the admin thru the web &lt;SPAN style="color: #0000ff;"&gt;&lt;SPAN style="color: #000000;"&gt;adaptor, i.e.&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.esri.com/external-link.jspa?url=http%3A%2F%2F" rel="nofollow" target="_blank"&gt;http://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;URL&amp;gt;/webadaptor/admin/login&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp; (or the https version of it), but that it is alright to use the machinename:port&amp;nbsp; &lt;SPAN style="color: #3366ff;"&gt;&lt;A style="color: #3366ff;"&gt;http://&amp;lt;machinename&amp;gt;:6080/arcgis/admin/login&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp; or &lt;SPAN style="color: #3366ff;"&gt;&lt;A style="color: #3366ff;"&gt;https://&amp;lt;machinename&amp;gt;:6443/arcgis/admin/login&amp;nbsp; &lt;SPAN style="color: #000000;"&gt;since this is typically within the firewall.&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;That does not mean that you can not connect as ad administrator thru the web adaptor using ArcCatalog or ArcMap, and is sometimes needed for certain tasks.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Aug 2017 15:13:35 GMT</pubDate>
    <dc:creator>RebeccaStrauch__GISP</dc:creator>
    <dc:date>2017-08-07T15:13:35Z</dc:date>
    <item>
      <title>Why is administering Server with Web Adaptor not recommended, but is often the only option?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/why-is-administering-server-with-web-adaptor-not/m-p/662379#M25280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've installed several web adaptors now, and I keep running into this paradox:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) When you install the web adaptor, the help documentation states&amp;nbsp;"&lt;A href="http://server.arcgis.com/en/server/latest/install/windows/configure-arcgis-web-adaptor-after-installation.htm"&gt;By default, administration of the site through ArcGIS Web Adaptor is disabled. This is the recommended option&lt;/A&gt;." I am assuming that's because of some sort of security risk, like the one described&amp;nbsp;&lt;A _jive_internal="true" href="https://community.esri.com/message/420398?commentID=420398#comment-420398?q=Why is enabling administrative access through web adaptor not r"&gt;here&lt;/A&gt;?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) However, if you want to make your services publishable through the web adaptor, as far as I know the only way to do that is to enable administration of the site through the web adaptor. In fact there's a help document that recommends you disable access through port 6080 and only use the web adaptor URL:&amp;nbsp;&lt;A class="link-titled" href="http://server.arcgis.com/en/server/latest/administer/windows/disabling-administrative-access-to-arcgis-server-on-port-6080.htm" title="http://server.arcgis.com/en/server/latest/administer/windows/disabling-administrative-access-to-arcgis-server-on-port-6080.htm"&gt;Disabling administrative access to ArcGIS Server on port 6080—ArcGIS Server Administration (Windows) | ArcGIS Enterprise&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my question is, what actually is the best practice for server administration through web adaptor? Does anyone have any insights on this? Does it depend on your server setup? If both methods have security risks, which is the least problematic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In our case, we have services that need to be kept inside the network, and services that need to be fully accessible for the public.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Aug 2017 00:18:09 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/why-is-administering-server-with-web-adaptor-not/m-p/662379#M25280</guid>
      <dc:creator>TabithaFraser</dc:creator>
      <dc:date>2017-08-04T00:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: Why is administering Server with Web Adaptor not recommended, but is often the only option?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/why-is-administering-server-with-web-adaptor-not/m-p/662380#M25281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think if you are using HTTPS, administration through web adapter is fine. If you allow HTTP (and probably a lot of folks do) and you&amp;nbsp;log into server manager using HTTP, your admin credentials are sent in clear text which would allow anyone, that cared enough, to get them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think they recommend disabling admin access through port 6080 when you are using web-tier auth. In which case you would have to authenticate at the web-tier (which is only done at the web adaptor). The only user that could authenticate through :6080 would be the primary site admin account. Web tier auth pretty much requires HTTPS unless you are behind a firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Aug 2017 19:35:59 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/why-is-administering-server-with-web-adaptor-not/m-p/662380#M25281</guid>
      <dc:creator>MatthewLofgren</dc:creator>
      <dc:date>2017-08-04T19:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: Why is administering Server with Web Adaptor not recommended, but is often the only option?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/why-is-administering-server-with-web-adaptor-not/m-p/662381#M25282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you haven't seen this already &lt;A class="link-titled" href="http://doc.arcgis.com/en/trust/security/arcgis-server-best-practices.htm" title="http://doc.arcgis.com/en/trust/security/arcgis-server-best-practices.htm"&gt;Server Implementation Guidance—Trust ArcGIS | ArcGIS&lt;/A&gt; if is worth a look.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I've been told is it &lt;EM&gt;is best&lt;/EM&gt; to disable the admin thru the web &lt;SPAN style="color: #0000ff;"&gt;&lt;SPAN style="color: #000000;"&gt;adaptor, i.e.&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.esri.com/external-link.jspa?url=http%3A%2F%2F" rel="nofollow" target="_blank"&gt;http://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;URL&amp;gt;/webadaptor/admin/login&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp; (or the https version of it), but that it is alright to use the machinename:port&amp;nbsp; &lt;SPAN style="color: #3366ff;"&gt;&lt;A style="color: #3366ff;"&gt;http://&amp;lt;machinename&amp;gt;:6080/arcgis/admin/login&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp; or &lt;SPAN style="color: #3366ff;"&gt;&lt;A style="color: #3366ff;"&gt;https://&amp;lt;machinename&amp;gt;:6443/arcgis/admin/login&amp;nbsp; &lt;SPAN style="color: #000000;"&gt;since this is typically within the firewall.&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;That does not mean that you can not connect as ad administrator thru the web adaptor using ArcCatalog or ArcMap, and is sometimes needed for certain tasks.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2017 15:13:35 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/why-is-administering-server-with-web-adaptor-not/m-p/662381#M25282</guid>
      <dc:creator>RebeccaStrauch__GISP</dc:creator>
      <dc:date>2017-08-07T15:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: Why is administering Server with Web Adaptor not recommended, but is often the only option?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/why-is-administering-server-with-web-adaptor-not/m-p/662382#M25283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I see the confusion here. Matthew above is correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You mention the DOC here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://server.arcgis.com/en/server/latest/administer/windows/disabling-administrative-access-to-arcgis-server-on-port-6080.htm"&gt;http://server.arcgis.com/en/server/latest/administer/windows/disabling-administrative-access-to-arcgis-server-on-port-6080.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This workflow would only apply if you're leveraging Windows users and roles and Web tier authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assume:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a. The Primary Site Admin (PSA) credentials are kept under clock and key,&lt;/P&gt;&lt;P&gt;b. Web tier authentication is used&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When using web tier auth and when the PSA account credentials are not shared amongst users, then&amp;nbsp;only members in the enterprise user and role store who are themselves members of an ArcGIS Server ADMIN role can administer the GIS Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If admin access via the web adaptor is disabled, only the PSA can admin the server - which we're assuming nobody has these credentials. So...you'd HAVE to allow users to admin the machine through the web adaptor - otherwise users wouldn't be able to authenticate correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If my GIS Server is publicly accessible, I don't like using windows users and roles and web tier authentication. I'd disable admin access via the web adaptor and enable internally at the GIS tier.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In ANY condition, as is alluded to earlier, administrative access should be via HTTPS - if via the GIS tier that's port 6443. In general and in any web site/application, it's preferable that any information passed through a form use HTTPS. Otherwise, it's very easy for a man in the middle to intercept whatever data is passed - including user credentials.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Aug 2017 16:40:48 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/why-is-administering-server-with-web-adaptor-not/m-p/662382#M25283</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2017-08-08T16:40:48Z</dc:date>
    </item>
  </channel>
</rss>

