HyWorks Application Publishing

HySecure supports integration of HyWorks so that it becomes accessible over WAN. In order to achieve publishing of HyWorks application, "HyWorks Controller" and "HyWorks Application Server" type of applications are to be created, on the HySecure Gateway.

Detailed steps are given below.

  1. Create a new app of type "HyWorks Controller -- Primary". Any name can be specified. Server address must be same as the same value specified in HyWorks Controller setting. If the HyWorks controller host address specified on HyWorks management as hostname, provide the hostname here. Port number of HyWorks services is 38866. Leave all other options unchecked with default value

  2. Create a new app of type "HyWorks- Application Server". Any name can be specified. Server address must be same as the same value specified in HyWorks Controller setting. If the HyWorks controller standby host address specified on HyWorks management as hostname, provide the hostname here. Leave all other options as default.

  3. Publish HyWorks - Application Server application for each Microsoft RDS Server in the HyWorks cluster.

  4. Create 1 application group for each VPN Domain (sub-organization) containing only following types of applications:

    • HyWorks Controller -- Primary
    • HyWorks Controller -- Secondary
    • HyWorks -- Application Server: All application servers part of this organization.
  5. Create one application group for each sub-org.

  6. Create one Access control for each VPN domain. Make sure that the Access control has the following details:

    1. Access control name

    2. HySecure Domain

    3. Select authorization server as common LDAP server.

    4. Access control type: Application Access

    5. Select User Group

    6. Select the common LDAP group listed in the control

    7. Select Application Group

    8. Select the application group name

  7. Create one ACL for each sub-org. Each sub-org must have access only to their own application-group created on HySecure. That means user of sub-org A cannot access RDS server of sub-org B