Traveler WITHOUT MFA

Hello, I hope you’re well.

My environment: Server operating system: Windows Server 2019; Domino version: 14.0 FP3 HF17 (recently updated from version 12 following HCL recommendations).
Question: In my environment, I validate the SSL certificate with a reverse proxy on a Linux system.
Question: If I:

  1. Open a new port in the Domino documentation. For example: “XXXX”

  2. Create a new website where I specify that traffic from “*:XXXX” should be sent without MFA.

  3. In the reverse proxy, when I receive requests from /Traveler, I redirect them internally to the clean port “XXXX”
    Would this work?
    This way, I would have access via Webmail with MFA and the Traveler without MFA. And I wouldn’t have any issues with the HCL version on Android and iOS.

Thank you very much!

———————————————————-
Hola, espero estén bien.
Mi entorno: Sistema operativo del servidor: Windows Server 2019; Versión de Domino: 14.0 FP3 HF17 (actualizada recientemente desde la versión 12 siguiendo las recomendaciones de HCL).
Consulta:
En mi entorno validad el certificado SSL con un proxi reverso sobre un Linux.
Consulta, SI:
1_ Abro un nuevo puerto en el Documento del Domino. EJ: “XXXX “
2_ Genero un Nuevo WebSite donde establece que el tráfico “ *:XXXX “ va SIN MFA.
3_ En el proxi reverso cuando reciba las peticiones de /Traveler las desvíe internamente al puerto limpio “XXXX”
¿funcionaria?
De esta manera me quedaría el acceso via WebMail con MFA y el tranveler sin MFA. Y no tendría inconveniente con la HCL Verse en los Android y IOS.
¡Muchas gracias!

Hello Elias,

Good day!

Your scenario is possible, but you need to verify first whether your reverse proxy can simply exclude /traveler/* from mfa while keeping mfa enabled for Verse/iNotes. The simplest solution I can think of is to use different hostnames for webmail and traveler. We need to configure each internet site document on the authentication you want. What I can recommend is to create a case for this to further assist you on your inquiry. Thank you