Gate443 — Documentation
Audience: the system administrator of the service to protect.
Contents#
- What Gate443 is
- Registration and free trial
- First sign-in and securing your account
- Contract and payments
- Company account
- Services
- Protecting your application: accept only Gate443
- Users
- User–service mappings
- Customising the access page
- Security (WAF) of your services
- Access logs and privacy
- Dashboard
- What your users see
- Step-by-step procedures
- Common issues
- Quick reference
1. What Gate443 is#
Gate443 is an access gateway that stands in front of your web applications (intranets, ERPs, portals) and makes them reachable from the Internet only to identified people. The application is never exposed directly: whoever wants in lands on Gate443, proves who they are with a six-digit code received by email, and from then on browses the application through the gateway. Your application's own login, if any, stays as it is: Gate443 is an extra layer, not a replacement.
Four objects explain the whole panel:
| Object | What it is |
|---|---|
| Service | The application to protect: a name and the real destination URL (e.g. https://intranet.internal.local). |
| User | The person who needs access: first name, last name, email. The email is the identity. |
| Mapping | The user ↔ service link. Without a mapping the user does not see the service. It can restrict the allowed IPs. |
| Contract | What you bought: how many services, users, white-label domains, caches. It sets the panel's ceilings, and the four bought / used / free counters show it on the Dashboard, in Contract and payments and at the top of Services. |
Every service has two addresses, both always valid:
- Default URL —
https://app.gate443.it/<your-company>/<service> - White-label domain (if the contract includes one) — the service lives at the root of a domain of yours, for example
https://portal.yourcompany.com/.
2. Registration and free trial#
You can activate Gate443 on your own from gate443.it:
- Fill in the company legal name (for the contract, it never appears anywhere), a short customer name (it ends up in your services' addresses:
app.gate443.it/<customer-name>/<service>, and the page shows it as you type), your name and your company email; accept the terms. It must be an email on your company's domain: free mailboxes (Gmail, Outlook…) and disposable ones are not accepted, and the trial is one per domain: if someone in your company already activated it, ask them for access or write to us. - You receive a six-digit code by email, valid for 15 minutes: type it on the same page and choose the panel password (at least 10 characters).
- The panel is ready. The welcome email tells you until when it is free.
What the trial includes: 1 protected service, 1 white-label domain, 1 static cache, 50 users, the firewall of your services. It is free for 7 days from registration (the welcome email and the Contract and payments page say until when). If you come from a reseller's link, the trial lasts one extra month.
What happens next. At the end of the free days the list price applies for that configuration (€29 the service, €10 the white-label, €5 the cache; amounts in euro, VAT included for purchases from Italy), starting with the month in which the trial ends, in full. If you added a card (§4) that month is charged the day after the trial ends, then every month on the 1st; if you did not, the services simply stop, no surprise charges: you reactivate them by adding the card, which collects the outstanding month right away. Until there is a card, the access page and the emails of your services carry a small "Gate443 free trial" mark.
If you come from a reseller. If you opened the site from a link like gate443.it/?ref=<code>, the form says so and your account is linked to that reseller: the only difference for you is that the trial lasts one extra month; price and service are the same. The code stays in your browser, so it also applies if you complete the registration later from the same device.
Every new registration also reaches the people who run the platform: if you need more services, users or a tailored offer, write to us and we adjust the contract.
3. First sign-in and securing your account#
The panel is at https://app.gate443.it/. You sign in with email and password; then the system always asks for a second factor:
| If your account has… | You are asked for |
|---|---|
| the authenticator app (OTP/TOTP) configured | the 6-digit code generated by the app |
| no app configured | a 6-digit code sent by email |
The code is valid for 5 minutes and allows 5 attempts. If you use the app but the phone is out of reach, "No app? Get a code by email" still sends a code to your mailbox.
The Account security page gathers everything about your own access:
- Change password — requires the current one; the new one needs at least 8 characters and must differ. If someone else assigned your initial password (for example whoever created your login) it is temporary: at first sign-in the panel takes you straight here and shows a notice at the top of every page until you replace it with your own.
- Authenticator app (OTP) — Enable OTP shows a QR code to scan with Google Authenticator, Authy, 1Password or similar; confirm with the generated 6-digit code. From then on the second factor is the app: faster and independent of email. The code by email always stays available as a fallback.
- Passkey — Windows Hello, Touch ID or a FIDO2 key: Add passkey and from then on you sign in without password and without code. You can register more than one (laptop and phone) and remove them individually.
Tip: register the passkey and keep the authenticator app active. The passkey is tied to a device; if that breaks, the app is the way back in without asking anyone.
The panel language is switched from the user menu at the top right (Italiano / English).
4. Contract and payments#
The Contract and payments page shows your subscription month by month: what it includes, the fee and the payment outcome. Amounts are in euro and, for purchases from Italy, VAT included. At the top, in the order they must be done, two things:
- Billing details — company name, full address, VAT number or tax code, SDI recipient code or PEC (for Italian e-invoicing one of the two is enough), administrative contact email. They are the contract data and must be filled in before the card: the button stays disabled until they are.
- Card — entered on a Stripe page, our payment provider: Gate443 never sees or stores card data. From then on the charge is automatic, on the 1st of every month, for that month's fee.
The months. Each row is a month: configuration bought, fee and payment status (due, paid, failed). The days from activation to the 1st of the following month are always free.
Your contract. The bought / used / free panel says, for services, users, white-label domains and caches, how much you can still create or enable. Two different criteria, worth knowing:
- For services, white-label and caches only active services count: a disabled one does not take a slot, and switching it back on requires a free slot.
- For users it counts whoever is associated with your company, even if disabled: it is the criterion the fee is calculated on, the same number you find next to the Users field when you change the contract. Disabling a person does not free the slot, removing them from the company does.
If the charge on the 1st fails. A failed charge (expired card, insufficient funds, card removed), or a month still due beyond the grace period (7 days from the 1st), suspends the contract's services: your users can no longer get in, the panel stays open and tells you why. To reactivate them:
- if needed, update the card (Add/Update the card): as soon as the card is saved the system tries to collect the outstanding months right away and, if it succeeds, the services switch back on at that very moment (the panel confirms it; if the charge fails, it tells you why);
- otherwise press Pay now and reactivate in the red notice at the top (the same Pay button appears in Services next to every suspended service): Stripe collects the outstanding months right away with the current card and, if it succeeds, the services switch back on immediately. With no saved card the panel takes you to add one.
If you pay by bank transfer, let us know: we register the payment and the services reactivate the same way.
Pausing the subscription. The Pause subscription button stops charges from next month; the services stay active until the end of the period already paid, then they are suspended. Reactivate subscription resumes the charges (with the saved card, or asking you for a new one).
Removing the card. Removes the card from Stripe. Beware: from the 1st of the following month the charge cannot happen and the services will be suspended, unless you add a new card first.
Changes. From the Change the contract panel you choose services, users (in packs of 50), white-label domains and caches; the fee is the list price and the panel shows it before you confirm.
- Upgrade (nothing decreases): the new configuration applies right away — you can create the extra service immediately — and the new fee starts next month. From then on you cannot reduce the contract until that month is paid: it prevents going up, using, and coming back down without paying. The panel shows it with a notice and the month to wait for.
- Downgrade (at least one item decreases): everything from next month; you cannot go below what you are using (active services, white-label, caches, users): disable or remove first, then reduce.
- During the free trial the downgrade lock does not apply: you can increase and reduce freely, since there is nothing to pay.
Free months stay free with the new configuration too. Nothing is recalculated backwards. For configurations outside the price list, write to us.
5. Company account#
The Company account page sums up your relationship with Gate443: registration date, contract start, acceptance dates of the contract terms and privacy policy (recorded at sign-up from the website; if missing, the Accept now button records them), whether and when you used the free trial, and how many services, users and logins there are.
Deleting the account. The button at the bottom closes the company's account for good: the subscription is cancelled immediately (no future charges), services and logins are switched off and your users no longer get in. Your password is required to confirm. The deletion is logical: data stays on file, the company name and email do not become available again and the free trial cannot be repeated. To reactivate later, write to us.
6. Services#
The Services page lists your protected applications. At the top, the quota panel; when the quota is used up the New service button is disabled.
| Field | What to enter |
|---|---|
| Name | The name users will see. It generates the slug of the access URL and must be unique among your services, disabled ones included. |
| Destination URL (private) | The real address of the application, the one Gate443 contacts behind the scenes: it must be reachable from the Internet by the Gate443 server (§7). Never hand it to your users: opening it directly bypasses the gate. |
| Description | Optional, shown to the user. |
| Active | A disabled service does not answer: neither access page nor browsing. It does not take a slot. |
| Access URL (default) (public) | Not editable: https://app.gate443.it/<your-company>/<service>. Appears after the first save. This is the address to give your users. |
| White-label URL (public) | The alternative public address, on your own domain (e.g. portal.yourcompany.com): login and application at the root of that host, with your brand. It applies to any service type and can be set right when you create the service, with no need to save and reopen. Needs a free white-label in the contract and a DNS change (§15.3). The HTTPS certificate is automatic. |
| Dedicated SMTP server | White-label only, and only after the first save: the access codes of this service leave from your mail server, with one of your mailboxes as sender (e.g. noreply@yourcompany.com). Host, port, encryption, user and password, sender name and email; after saving, Send test email writes to you to verify. See the note below. |
| Static page cache | Images, CSS, JS and fonts are kept on disk and served without contacting your application again: faster browsing. Needs a free cache in the contract. Maximum space in MB (default 200). |
| Service type | Generic (everything protected, as always), WordPress — whole site, WordPress — back office only. The type fills in the protected paths and, for WordPress, enables the plugin (§7, WordPress sites). Choosing WordPress turns on and locks Custom domain and Forward the original Host: the public domain becomes the name in the destination URL and cannot be edited. A WordPress service therefore requires a white-label in the contract (§4): it cannot work at the default access URL app.gate443.it/<company>/<service>, and that address redirects to the domain. |
| Protected paths | One per line: /wp-admin protects that path and everything below it, !/wp-admin/admin-ajax.php excludes it, / means everything. Exclusions win. Empty = everything protected; the rest passes without login. If the root stays public, the access page lives at /_gate443/login. |
| Forward the original Host | Your application receives the custom domain instead of the destination URL host: it believes it is at its own address and does not redirect. It is an effect of white-label, so it counts as one white-label in the contract. On a generic service it is optional: turning it on also turns on the custom domain and proposes the destination URL name as the domain, editable. Always on for WordPress. Ignored on the default access URL. |
| Origin IP | Appears with Host forwarding. Once the public domain's DNS points to Gate443, the gateway can no longer reach your server by that name: here you enter the IP to connect to. Name, HTTPS and certificate remain those of the destination URL. Empty = normal DNS resolution. Not needed if the destination URL is already an IP. It is required when the custom domain is the same name as the destination URL — that is, always on WordPress services: the panel will not let you save without it. |
| WordPress plugin | WordPress types only. The zip, with token and rules already compiled, is downloaded from the service list, with the zip icon next to the pencil. Regenerate token is inside the service form. The plugin mirrors the saved service: if you change type or paths, save before downloading it. |
Private and public. The form tags the two kinds of address. The destination URL is private: it is where your application really lives, and only Gate443 should contact it (§7). The access URL and the white-label URL are public: they are the ones to hand out to users, who find the access page there and, after the code, your application.
Host forwarding and origin IP#
These two fields are linked, and they are the part of the form most open to misreading. They are worth reading together.
What Host forwarding does. Every HTTP request carries the name the user typed, in the Host header. Without forwarding, Gate443 presents your application with the name in the destination URL; with forwarding on, it presents the custom domain, i.e. what the user sees in the address bar. It does not change where Gate443 connects: only the name it announces.
It matters because almost every application builds its own links from that header. With forwarding on, the links that reach the browser are already the right ones; without it, the application may send the user back to its internal address.
On a generic service the domain stays editable, and that is not a contradiction. The question is fair: if I forward the Host, shouldn't that name necessarily be the server's own? It depends on what the application knows about itself.
- Applications that derive their addresses from the request — most business applications and web frameworks — accept any name you choose, and forwarding is precisely what makes them work on the domain you picked. Here the domain is rightly free.
- Applications with an address written into their own configuration — WordPress with
siteurlis the typical example — accept only that name: given another, they redirect to their own. This is why the domain is locked to the destination URL name on the WordPress type.
The only condition, on a generic service, is that your server accepts the name it receives. If it hosts several sites on the same machine and tells them apart by name, add the custom domain to the names it recognises, or leave forwarding off.
What the origin IP is for. When the field is empty, Gate443 behaves as it always has: it resolves through DNS the name in the destination URL and connects to the resulting address. Empty is fine in three cases out of four:
- the destination URL is already an IP (e.g.
http://203.0.113.10): there is nothing to resolve, and indeed the field does not appear; - the destination is a technical or internal name that still points to your server (the hosting one, or a private network name);
- the custom domain is different from the destination name: the latter's DNS has not moved and still leads to your server.
One case remains, and it is the reason the field exists: custom domain and destination name are the same, i.e. the WordPress setup. Until you touch DNS everything works without an IP too. The moment you point that name at Gate443, the gateway trying to resolve it finds itself, and requests come back in through the front door instead of going out to your server. The origin IP tells the gateway which address to knock at; name, HTTPS and certificate stay those of the destination URL, exactly as a CDN does.
⚠️ The symptom would be unpleasant because it arrives later than the mistake: the service is configured and tested successfully, and stops working hours later, when DNS propagates. That is why, when the two names coincide, the field is required: the panel and the API refuse to save without it, and say why. It is not a formality, it is the only moment when someone still connects the two things.
📧 Get a dedicated SMTP server for white-label services. Without it, the codes leave from the Gate443 server with sendernoreply@your-domain: a domain sending through someone else's server easily lands in spam, because your domain's SPF and DKIM records do not authorise that server. With the dedicated server — typically the one already sending for your company (Microsoft 365, Google Workspace or your mail provider), with anoreply@mailbox created for this — sender, SPF and DKIM are all in your hands and the codes reach the inbox. For port 587 leave the encrypted connection off (STARTTLS is used); for 465 turn it on. After saving, use Send test email and check that the message does not land in spam. If you do not want a dedicated server, publish in your domain's DNS an SPF record that includes the Gate443 server and ask us for the DKIM key.
Useful notes:
- A white-label domain belongs to a single service; if it is already in use the panel says so.
- Saving a service empties its cache: the quickest way to show users the new assets after an update of your application.
- Deleting a service also deletes its mappings. If you only need a pause, disable it.
- After the code, the user returns to the page they asked for (e.g.
/wp-admin/), not to the service root.
7. Protecting your application: accept only Gate443#
This step is what makes the protection real. As long as your application answers anyone, whoever knows its real address can walk around the gate. The rule is: your application accepts connections only from Gate443's address and refuses everything else.
Gate443's address#
Requests to your application come from the Gate443 server:
IP: 4.232.160.186
Name: app.gate443.it (always resolves to the address in use)
Where your web server or firewall accepts a DNS name, prefer app.gate443.it to the IP: should the address ever change, you would not have to touch anything. In any case a change is announced in advance, with a period during which old and new address stay valid together.
What your application must expose#
- The destination URL must be reachable from
4.232.160.186, over HTTPS or HTTP. An internal or self-signed certificate on the origin is fine. - If the application uses WebSockets, they work: Gate443 forwards them.
- Gate443 adds to every forwarded request some headers your application can read:
| Header | Content |
|---|---|
X-Forwarded-For, X-Real-IP | the user's real IP (the connection comes from Gate443) |
X-Forwarded-Host, X-Forwarded-Proto | original host and scheme of the request |
X-Gate443-User, X-Gate443-UserId | name and identifier of the user who passed Gate443 (anonymous on the access page) |
Configuration examples#
Replace internal.company.com with your application's host and 8080 with the port it runs on.
nginx
server {
listen 443 ssl;
server_name internal.company.com;
location / {
allow 4.232.160.186; # Gate443
deny all;
proxy_pass http://127.0.0.1:8080;
}
}
Apache 2.4
<Location "/">
Require ip 4.232.160.186
</Location>
IIS — web.config (requires the IP and Domain Restrictions feature, not installed by default)
<system.webServer>
<security>
<ipSecurity allowUnlisted="false">
<add ipAddress="4.232.160.186" allowed="true" />
</ipSecurity>
</security>
</system.webServer>
Caddy
internal.company.com {
@others not remote_ip 4.232.160.186
respond @others 403
reverse_proxy 127.0.0.1:8080
}
Firewall, if you'd rather stop requests before they reach the web server:
# Linux, ufw
ufw default deny incoming
ufw allow from 4.232.160.186 to any port 443 proto tcp
# Windows, PowerShell
New-NetFirewallRule -DisplayName "Gate443 only" -Direction Inbound `
-LocalPort 443 -Protocol TCP -RemoteAddress 4.232.160.186 -Action Allow
The firewall filter is more solid (a refused request never even reaches the application); the web-server filter is handier if you don't manage the network. In the cloud (Azure, AWS, etc.) the same rule goes into the instance's Network Security Group or Security Group.
Verification#
- From a PC outside your network open the destination URL directly: it must answer 403 or not answer at all.
- Open the service's Gate443 access URL, sign in with the code: the application must load normally.
- If step 2 fails with a Gate443 error ("origin unreachable"), the rule is blocking Gate443 too: double-check the address.
If your application runs on the same network as other, unprotected services, remember the rule applies to the protected application: the others stay as they are.
WordPress sites#
💶 White-label is a requirement, not an option. WordPress generates links, redirects and cookies towards its own domain: at the default access URL app.gate443.it/<company>/<service> a site cannot work. A WordPress service therefore costs one service plus one white-label domain of the contract (§4); the panel turns it on by itself and refuses to save a WordPress service without a domain. The default address remains, but redirects to the domain.
Gate443 can sit in front of a WordPress site in two ways, chosen with the Service type (§6):
- Whole site: no page is visible without the code. For intranets, staging, reserved areas. No webhooks, crawlers or external services towards the site: they would land on the access page.
- Back office only: the site stays public, but
wp-login.php,wp-admin(exceptadmin-ajax.php, which the site also uses for visitors) andxmlrpc.phpanswer only after the code. Site traffic still flows through Gate443, with WAF and cache.
Same address inside and out. The setup is the same in both cases and mirrors a CDN. The point to grasp is that the site domain does not change: it stays what it has always been, and your server stops being reachable directly.
- Destination URL = the site's address as it is today, e.g.
https://www.yoursite.com. Pick the WordPress type: Custom domain and Forward the original Host turn on by themselves and stay locked, and the public domain becomeswww.yoursite.com, same as the destination and not editable. It counts as one white-label in the contract (§4), and from there you can also set up the dedicated SMTP server. - Origin IP = your server's IP, the one
www.yoursite.comresolves to today. It is needed because at step 3 that name will stop leading to your server: Gate443 will keep calling itwww.yoursite.com, with the name's HTTPS and certificate, but will knock at this IP. - The DNS of
www.yoursite.commoves to Gate443 (§15.3). The HTTPS certificate on the gateway is automatic. WordPress receiveswww.yoursite.com, i.e. itssiteurl, and needs no change at all: no search-replace in the database, no lines inwp-config.php, emails with the right links. - Your server refuses anything that does not come from Gate443. This is the step that makes the protection real: without it, whoever finds the server's IP walks in. See the examples below and in §7.
In one line: the domain goes to the gateway, the gateway knocks at the server's IP, the server accepts only the gateway, and WordPress still believes it is at its own address.
If you prefer to write the destination URL as an IP (e.g. http://203.0.113.10), the public domain cannot be inferred: you type it by hand, and the Origin IP field is not needed.
The plugin is downloaded from the service list, with the zip icon next to the pencil, after saving the service.
The plugin. The zip is already compiled with a secret token and the service's rules. Upload it from Plugins → Add New → Upload Plugin and activate it; alternatively copy gate443.php into wp-content/mu-plugins/ (always active, cannot be deactivated from the WordPress panel). It does three things:
- recognises Gate443 requests by the token (
X-Gate443-Tokenheader) and only for those trusts theX-Forwarded-*headers: WordPress sees the public host, https and the visitor's real IP; - rejects (403), or redirects to the public domain, anyone reaching the protected paths another way: the origin's IP, an old DNS name;
- writes every back-office login to the PHP log with the Gate443 user.
If you regenerate the token from the panel, download and reinstall the plugin. WP-CLI and wp-cron.php are never blocked.
Plugin limits, and the web server rule (VPS). The plugin runs inside PHP: it does not see static files (wp-content/uploads, CSS, JS) and falls with the site if the site is compromised some other way. On shared hosting it is the right choice, because there is nothing else. On a VPS add the rule in the web server, which PHP cannot touch (the IP is the one in §7):
nginx, back office only:
location ~ ^/(wp-login\.php|xmlrpc\.php|wp-admin(?!/admin-ajax\.php)) {
allow 4.232.160.186;
deny all;
# ... your usual PHP handling (fastcgi_pass / try_files)
}
nginx, whole site: allow 4.232.160.186; deny all; directly in the server block, or in the firewall (ports 80/443 open to that IP only).
Apache, .htaccess in the site root:
<FilesMatch "^(wp-login|xmlrpc)\.php$">
Require ip 4.232.160.186
</FilesMatch>
and in wp-admin/.htaccess:
<Files "admin-ajax.php">
Require all granted
</Files>
Require ip 4.232.160.186
With the rule in the web server the plugin remains useful for the real host, https and IP.
Things to know.
- WordPress Application Passwords allow writing through
/wp-jsonwithout going throughwp-login.php. Disable them, or add/wp-jsonto the protected paths if the site does not use it for visitors. - A cache plugin serving static HTML does not interfere. A security plugin with IP blocking would see every visitor with Gate443's IP until the Gate443 plugin is active: activate it first.
- If you use
httpsbetween Gate443 and the origin with a Let's Encrypt certificate validated over HTTP, the validation goes through the gateway: the whole site type already excludes/.well-known/acme-challenge/from login. With internalhttpthe issue does not arise.
Verification.
- From a phone on mobile data:
https://www.yoursite.com/shows the site (back office only) or the access page (whole site);https://www.yoursite.com/wp-admin/leads to the access page. - Directly on the origin's IP:
http://<ip>/wp-login.phpmust answer 403 (plugin or web server) or not answer at all (firewall). - After the code: WordPress login, save a post, upload an image. No link in the page source may contain the origin's IP.
8. Users#
The page you will use most. For each person: first name, last name, email, status.
- Creating a user. If the email already exists in Gate443 (because that person also works for another company using the service), the existing user is added to your company and keeps the accesses they have elsewhere: a message says so explicitly.
- Disabling immediately blocks every access, keeping history and mappings. It is the right operation for a temporary absence.
- Removing from the company detaches the user and deletes their mappings here. The confirmation message says whether the person remains a user of other companies or is deleted altogether.
Search and status filter help with long lists. How many users you can have depends on the contract (50 included per service).
9. User–service mappings#
A user sees a service only if mapped to it. On the Mappings page pick the user and tick the services they must access.
Allowed IPs (optional, per service, comma-separated, IPv4 only, up to 50): if you list them, that user on that service signs in only from those addresses. The code by email is still always required: the address says where from one may enter, the code says who is entering. Empty list = no restriction. Use it to tie an access to the office or the company network (§15.2).
The whole chain must be active. If the user, the service or the mapping is disabled, access does not happen. No exceptions.
10. Customising the access page#
Every service has its own access page, which you brand from the Customisation page: pick the service from the menu and set colours (primary, secondary, background), background image, logo, favicon, title, subtitle and the Privacy and Cookie Policy links. The preview updates as you edit.
The page shows the service's access link: the address to hand to your users.
Branding also applies to the email with the code: it adopts the logo, colour and title set here. On services with a white-label domain the sender becomes a mailbox on your domain (noreply@portal.yourcompany.com): for those emails to be delivered you must authorise Gate443's mail server in your domain's SPF and DKIM records (we provide the values). It is the most frequent cause of "I don't receive the code".
Image limits: logo ~450 KB, favicon ~150 KB, background ~1.8 MB.
11. Security (WAF) of your services#
Besides the platform-wide protection, in Security (WAF) you have your own lists, which apply only to your services (access page and browsing, both on the default URL and on white-label domains):
- Whitelisted IPs — always get in. Blacklisted IPs — never do. IPv4, IPv6 and CIDR networks (
203.0.113.0/24) are accepted, up to 500 entries per list. - Whitelisted / blacklisted countries — two-letter ISO codes (
IT,CH,US), plus the special entryALL= every country. An explicit code always beatsALL:blacklist ALL + whitelist ITlets people in only from Italy. Geolocation is offline: no data about your visitors leaves for external services.
Evaluation order: whitelisted IP → blacklisted IP → whitelisted country → blacklisted country → ALL. The same address or country cannot be on both lists.
Blocked accesses by your rules appear at the bottom of the page, with IP, country, reason and path.
Whoever matches one of your blocking rules sees a clear message ("Access is not allowed from this address or country") and never even reaches the access page.
12. Access logs and privacy#
Access logs lists who got in, when, from which IP and to which service, with filters by action (Code sent, Sign-in succeeded, Sign-in failed, Browsing), dates and address. You see the data in clear: full emails and IPs.
You decide the retention policy, and it is a choice to make with your privacy officer:
| Setting | Meaning |
|---|---|
| Keep logs for N days | Beyond N days logs delete themselves. 0 = never delete. |
| IP anonymisation — Off | IPs stay in clear. |
| IP anonymisation — After N days | Once N days have passed, recorded IPs are masked (IPv4: last octet to zero; IPv6: /48). |
| IP anonymisation — Immediate | The IP is never written in clear and the user-agent is not recorded. |
Whoever runs the platform sees your logs only with anonymised emails and IPs.
13. Dashboard#
Your company at a glance: total and active users, services, sign-ins over the last 7 days, the Your contract panel (bought / used / free), activity over the last 14 days (successful sign-ins and codes sent, per day) and the most used services over the last 30 days.
14. What your users see#
Worth knowing, because it is what you will explain to the people working with you.
- The user opens the service link (the default URL or your white-label domain) and sees the access page with your branding.
- They enter their email.
- They receive a 6-digit code and type it in the same window. The code is single-use, valid for 5 minutes and bound to the source IP and the browser window: forwarding it to a colleague or opening it on another device does not work, by design. If the mapping restricts network addresses and the request comes from an IP not allowed, access is refused even before the email.
- They browse the application through Gate443, with the session valid for one hour and extended on every activity.
Things to anticipate:
- There is no link to click in the email, only the code: it prevents a mail client or an antispam from "opening" the access on their behalf.
- If they change network during the session (from Wi-Fi to mobile data, for example), the session expires and they must sign in again.
- After 5 wrong attempts on the same code a new one must be requested.
- There is no generic access page on
app.gate443.it: every user must use their own service's link. Have them bookmark it. - If a user makes too many attempts in a short time, the system stops them for a few minutes and says so clearly, with the minutes to wait.
15. Step-by-step procedures#
15.1 Putting the first service online#
- Account security — change the password, enable the authenticator app.
- Contract and payments — fill in the billing details and, if you want to continue after the trial, add the card.
- Services → New service — name and destination URL of your application.
- On your server — accept only
4.232.160.186(§7) and verify. - Users — enter the people.
- Mappings — link every user to the services they need.
- Customisation — branding on the access page and the link to hand out.
- Access logs — set retention and anonymisation.
15.2 Restricting access to the office with a fixed IP#
- Have your network provider confirm the office's static public IP (not the internal IP: the one the office presents itself with on the Internet).
- Mappings → user → in the service's Allowed IPs field enter the address; several addresses separated by commas.
- Save and verify: from the office the user receives the code as usual; from any other network access is refused. With a dynamic IP this feature is not suitable.
15.3 Publishing a service on your own domain (white-label)#
- Services → open the service, enable Custom domain and type the domain (e.g.
portal.yourcompany.com). A free white-label in the contract is needed. - In your domain's DNS create an
Arecord to4.232.160.186, or aCNAMEtoapp.gate443.it. - Wait for propagation and the first certificate issuance (usually 1–2 minutes): HTTPS is automatic.
- Email: for the codes to leave from
noreply@portal.yourcompany.comwithout ending up in spam, add Gate443's mail server to the domain's SPF records and configure DKIM with the values we provide. Do it before handing out the link, not after the first report. - The old
/<your-company>/<service>address keeps working.
15.4 Someone has left the company#
- Temporary absence → disable the user.
- Permanent departure → Remove from company; read the confirmation message.
15.5 A user does not receive the code#
- Access logs → filter by that user and look for Code sent. If it is there, the system sent it: the problem is downstream (spam, filters, mailbox).
- If it is not there, check that user, service and mapping are all active and that, if the mapping restricts IPs, the user is on an allowed network.
- If the service is white-label, check your domain's SPF/DKIM: the most frequent cause.
- If nothing adds up, write to us with the user's email and the time of the attempt.
15.6 Protecting the back office of a WordPress site#
- Services → New service: name, destination URL = the site's address as it is today (e.g.
https://www.yoursite.com), Service type = WordPress — back office only (or whole site). Custom domain and Host forwarding turn on by themselves, with the public domain equal to the destination. Origin IP = your server's IP. Save. - Move the DNS record of
www.yoursite.comto Gate443 (§15.3). - Still in the service: Download plugin, upload it to WordPress and activate it (or copy it into
mu-plugins). On a VPS, also add the web server rule (§7, WordPress sites). - Users and mappings for whoever administers the site (§8, §9).
- Verify as in §7: the site is visible,
wp-adminasks for the code, the origin's IP answers 403.
16. Common issues#
| Symptom | Most likely cause | What to do |
|---|---|---|
| The user enters the email and no service appears | No active mapping, or user or service disabled | Check the chain in Mappings |
| "Network address changed. Request a new code" | The IP changed between the request and entering the code (VPN, mobile network) | Request a new code staying on the same network |
| The user is sent back to the login while browsing | The IP changed during the session: intended behaviour | Sign in again; if it recurs, check the network's stability |
| "Invalid code" repeatedly | Code expired (5 min), already used, or entered in another window | New code, entered in the same tab |
| "Too many sign-in attempts from this address" | Per-IP request limit exceeded | Wait the minutes shown in the message |
| "Access is not allowed from this address or country" | One of your WAF rules blocks the user | Security (WAF) → check blacklists and countries; the whitelist takes precedence |
| The application loads directly even without Gate443 | Your server still accepts everyone | Apply the rule in §7 |
| Gate443 says the origin is unreachable | The rule on your server also blocks 4.232.160.186, or the destination URL is wrong | Double-check address and URL |
| The protected site looks broken or styles are missing | Static cache with stale content after an update | Services → save the service: the cache is emptied |
| The white-label domain gives a certificate error | DNS not yet propagated, or domain not enabled on the service | Check the DNS record and that the service is active; wait a few minutes |
| "All services in your contract are in use" | Quota used up (active services count) | Disable a service you don't use, or write to us to extend the contract |
| "A service with this name or URL already exists" | Duplicate name, disabled ones included | Choose another name or delete the old service |
| The services show as "suspended" | Charge on the 1st failed, or month unpaid beyond the grace period | Press Pay (in Services or Contract and payments), updating the card first if needed; for a bank transfer let us know |
| I cannot add the card | Incomplete billing details | Fill in company name, full address and VAT number or tax code |
| "A company email is needed for the free trial" | Free mailbox (Gmail, Outlook…) | Use an email on your company's domain; if you have none, write to us |
| "The free trial is one per company: the domain … already used it" | Someone with your same company email already activated a trial | Ask your administrator for access, or write to us for an exception |
| Services suspended with "free trial ended" | The free days are over and there is no card | Add the card in Contract and payments: the outstanding month is collected right away and the services restart |
| I saved the card but the services stay suspended | The immediate charge of the outstanding months failed (the message says so) | Check the card (funds, 3-D Secure authorisation), then Pay now and reactivate |
| "You upgraded recently: you can reduce the contract after the payment of month …" | After an upgrade the downgrade is locked until that month is paid | Wait for the charge on the 1st (or pay with Pay now). There is no lock during the free trial |
| "You cannot go below what you use" | The reduction would go below active services, white-label, caches or users | Disable or remove first, then reduce |
| "Superadmin only" when changing the contract | Panel not up to date | Reload the page; if it persists, write to us |
| My users find the codes in spam | The codes leave from a server your domain does not authorise (SPF/DKIM) | Set up the service's dedicated SMTP server (§6), or publish SPF/DKIM for the Gate443 server |
| "Sending failed" when testing the dedicated SMTP server | Wrong host, port or credentials; port 465 without encrypted connection (or vice versa); service not yet saved with domain and white-label enabled | Fix the settings and save the service first, then try again |
| Users get into the application without a code | You handed out the destination URL (private) instead of the access URL | Give users the access URL or the white-label one, and close your server to everyone but Gate443 (§7) |
| "Your password is temporary" appears at sign-in | Your password was set by whoever created your login | Account security → Change password: the notice disappears on its own |
17. Quick reference#
| What | Value |
|---|---|
| Panel | https://app.gate443.it/ |
| Access URL of a service | https://app.gate443.it/<your-company>/<service> or https://<your-domain>/ |
| Gate443's IP (to allow on your server) | 4.232.160.186 — name app.gate443.it |
| User code validity | 5 minutes, 5 attempts |
| Panel 2FA code validity | 5 minutes, 5 attempts |
| Browsing session | 1 hour, extended on every activity |
| Panel password | at least 8 characters (10 at registration) |
| Allowed IPs per mapping | up to 50, IPv4 only |
| Entries per WAF list | up to 500 |
| Users included | 50 per service |
| Grace period on the month's payment | 7 days from the 1st |
| Free trial | 7 days from registration (+1 month from a reseller's link); then the current month is paid |
Irreversible operations: deleting a service (with its mappings), removing a user who has no other companies, clearing WAF events. Almost always there is the alternative: disable.
For everything else: gate443.it · support via MiriuM.