Gate443 Documentation
Site Panel IT

Gate443 — Documentation

Audience: the system administrator of the service to protect.


Contents#

  1. What Gate443 is
  2. Registration and free trial
  3. First sign-in and securing your account
  4. Contract and payments
  5. Company account
  6. Services
  7. Protecting your application: accept only Gate443
  8. Users
  9. User–service mappings
  10. Customising the access page
  11. Security (WAF) of your services
  12. Access logs and privacy
  13. Dashboard
  14. What your users see
  15. Step-by-step procedures
  16. Common issues
  17. Quick reference

1. What Gate443 is#

Gate443 is an access gateway that stands in front of your web applications (intranets, ERPs, portals) and makes them reachable from the Internet only to identified people. The application is never exposed directly: whoever wants in lands on Gate443, proves who they are with a six-digit code received by email, and from then on browses the application through the gateway. Your application's own login, if any, stays as it is: Gate443 is an extra layer, not a replacement.

Four objects explain the whole panel:

ObjectWhat it is
ServiceThe application to protect: a name and the real destination URL (e.g. https://intranet.internal.local).
UserThe person who needs access: first name, last name, email. The email is the identity.
MappingThe user ↔ service link. Without a mapping the user does not see the service. It can restrict the allowed IPs.
ContractWhat you bought: how many services, users, white-label domains, caches. It sets the panel's ceilings, and the four bought / used / free counters show it on the Dashboard, in Contract and payments and at the top of Services.

Every service has two addresses, both always valid:

  1. Default URLhttps://app.gate443.it/<your-company>/<service>
  2. White-label domain (if the contract includes one) — the service lives at the root of a domain of yours, for example https://portal.yourcompany.com/.

2. Registration and free trial#

You can activate Gate443 on your own from gate443.it:

  1. Fill in the company legal name (for the contract, it never appears anywhere), a short customer name (it ends up in your services' addresses: app.gate443.it/<customer-name>/<service>, and the page shows it as you type), your name and your company email; accept the terms. It must be an email on your company's domain: free mailboxes (Gmail, Outlook…) and disposable ones are not accepted, and the trial is one per domain: if someone in your company already activated it, ask them for access or write to us.
  2. You receive a six-digit code by email, valid for 15 minutes: type it on the same page and choose the panel password (at least 10 characters).
  3. The panel is ready. The welcome email tells you until when it is free.

What the trial includes: 1 protected service, 1 white-label domain, 1 static cache, 50 users, the firewall of your services. It is free for 7 days from registration (the welcome email and the Contract and payments page say until when). If you come from a reseller's link, the trial lasts one extra month.

What happens next. At the end of the free days the list price applies for that configuration (€29 the service, €10 the white-label, €5 the cache; amounts in euro, VAT included for purchases from Italy), starting with the month in which the trial ends, in full. If you added a card (§4) that month is charged the day after the trial ends, then every month on the 1st; if you did not, the services simply stop, no surprise charges: you reactivate them by adding the card, which collects the outstanding month right away. Until there is a card, the access page and the emails of your services carry a small "Gate443 free trial" mark.

If you come from a reseller. If you opened the site from a link like gate443.it/?ref=<code>, the form says so and your account is linked to that reseller: the only difference for you is that the trial lasts one extra month; price and service are the same. The code stays in your browser, so it also applies if you complete the registration later from the same device.

Every new registration also reaches the people who run the platform: if you need more services, users or a tailored offer, write to us and we adjust the contract.

3. First sign-in and securing your account#

The panel is at https://app.gate443.it/. You sign in with email and password; then the system always asks for a second factor:

If your account has…You are asked for
the authenticator app (OTP/TOTP) configuredthe 6-digit code generated by the app
no app configureda 6-digit code sent by email

The code is valid for 5 minutes and allows 5 attempts. If you use the app but the phone is out of reach, "No app? Get a code by email" still sends a code to your mailbox.

The Account security page gathers everything about your own access:

Tip: register the passkey and keep the authenticator app active. The passkey is tied to a device; if that breaks, the app is the way back in without asking anyone.

The panel language is switched from the user menu at the top right (Italiano / English).


4. Contract and payments#

The Contract and payments page shows your subscription month by month: what it includes, the fee and the payment outcome. Amounts are in euro and, for purchases from Italy, VAT included. At the top, in the order they must be done, two things:

  1. Billing details — company name, full address, VAT number or tax code, SDI recipient code or PEC (for Italian e-invoicing one of the two is enough), administrative contact email. They are the contract data and must be filled in before the card: the button stays disabled until they are.
  2. Card — entered on a Stripe page, our payment provider: Gate443 never sees or stores card data. From then on the charge is automatic, on the 1st of every month, for that month's fee.

The months. Each row is a month: configuration bought, fee and payment status (due, paid, failed). The days from activation to the 1st of the following month are always free.

Your contract. The bought / used / free panel says, for services, users, white-label domains and caches, how much you can still create or enable. Two different criteria, worth knowing:

If the charge on the 1st fails. A failed charge (expired card, insufficient funds, card removed), or a month still due beyond the grace period (7 days from the 1st), suspends the contract's services: your users can no longer get in, the panel stays open and tells you why. To reactivate them:

  1. if needed, update the card (Add/Update the card): as soon as the card is saved the system tries to collect the outstanding months right away and, if it succeeds, the services switch back on at that very moment (the panel confirms it; if the charge fails, it tells you why);
  2. otherwise press Pay now and reactivate in the red notice at the top (the same Pay button appears in Services next to every suspended service): Stripe collects the outstanding months right away with the current card and, if it succeeds, the services switch back on immediately. With no saved card the panel takes you to add one.

If you pay by bank transfer, let us know: we register the payment and the services reactivate the same way.

Pausing the subscription. The Pause subscription button stops charges from next month; the services stay active until the end of the period already paid, then they are suspended. Reactivate subscription resumes the charges (with the saved card, or asking you for a new one).

Removing the card. Removes the card from Stripe. Beware: from the 1st of the following month the charge cannot happen and the services will be suspended, unless you add a new card first.

Changes. From the Change the contract panel you choose services, users (in packs of 50), white-label domains and caches; the fee is the list price and the panel shows it before you confirm.

Free months stay free with the new configuration too. Nothing is recalculated backwards. For configurations outside the price list, write to us.


5. Company account#

The Company account page sums up your relationship with Gate443: registration date, contract start, acceptance dates of the contract terms and privacy policy (recorded at sign-up from the website; if missing, the Accept now button records them), whether and when you used the free trial, and how many services, users and logins there are.

Deleting the account. The button at the bottom closes the company's account for good: the subscription is cancelled immediately (no future charges), services and logins are switched off and your users no longer get in. Your password is required to confirm. The deletion is logical: data stays on file, the company name and email do not become available again and the free trial cannot be repeated. To reactivate later, write to us.


6. Services#

The Services page lists your protected applications. At the top, the quota panel; when the quota is used up the New service button is disabled.

FieldWhat to enter
NameThe name users will see. It generates the slug of the access URL and must be unique among your services, disabled ones included.
Destination URL (private)The real address of the application, the one Gate443 contacts behind the scenes: it must be reachable from the Internet by the Gate443 server (§7). Never hand it to your users: opening it directly bypasses the gate.
DescriptionOptional, shown to the user.
ActiveA disabled service does not answer: neither access page nor browsing. It does not take a slot.
Access URL (default) (public)Not editable: https://app.gate443.it/<your-company>/<service>. Appears after the first save. This is the address to give your users.
White-label URL (public)The alternative public address, on your own domain (e.g. portal.yourcompany.com): login and application at the root of that host, with your brand. It applies to any service type and can be set right when you create the service, with no need to save and reopen. Needs a free white-label in the contract and a DNS change (§15.3). The HTTPS certificate is automatic.
Dedicated SMTP serverWhite-label only, and only after the first save: the access codes of this service leave from your mail server, with one of your mailboxes as sender (e.g. noreply@yourcompany.com). Host, port, encryption, user and password, sender name and email; after saving, Send test email writes to you to verify. See the note below.
Static page cacheImages, CSS, JS and fonts are kept on disk and served without contacting your application again: faster browsing. Needs a free cache in the contract. Maximum space in MB (default 200).
Service typeGeneric (everything protected, as always), WordPress — whole site, WordPress — back office only. The type fills in the protected paths and, for WordPress, enables the plugin (§7, WordPress sites). Choosing WordPress turns on and locks Custom domain and Forward the original Host: the public domain becomes the name in the destination URL and cannot be edited. A WordPress service therefore requires a white-label in the contract (§4): it cannot work at the default access URL app.gate443.it/<company>/<service>, and that address redirects to the domain.
Protected pathsOne per line: /wp-admin protects that path and everything below it, !/wp-admin/admin-ajax.php excludes it, / means everything. Exclusions win. Empty = everything protected; the rest passes without login. If the root stays public, the access page lives at /_gate443/login.
Forward the original HostYour application receives the custom domain instead of the destination URL host: it believes it is at its own address and does not redirect. It is an effect of white-label, so it counts as one white-label in the contract. On a generic service it is optional: turning it on also turns on the custom domain and proposes the destination URL name as the domain, editable. Always on for WordPress. Ignored on the default access URL.
Origin IPAppears with Host forwarding. Once the public domain's DNS points to Gate443, the gateway can no longer reach your server by that name: here you enter the IP to connect to. Name, HTTPS and certificate remain those of the destination URL. Empty = normal DNS resolution. Not needed if the destination URL is already an IP. It is required when the custom domain is the same name as the destination URL — that is, always on WordPress services: the panel will not let you save without it.
WordPress pluginWordPress types only. The zip, with token and rules already compiled, is downloaded from the service list, with the zip icon next to the pencil. Regenerate token is inside the service form. The plugin mirrors the saved service: if you change type or paths, save before downloading it.

Private and public. The form tags the two kinds of address. The destination URL is private: it is where your application really lives, and only Gate443 should contact it (§7). The access URL and the white-label URL are public: they are the ones to hand out to users, who find the access page there and, after the code, your application.

Host forwarding and origin IP#

These two fields are linked, and they are the part of the form most open to misreading. They are worth reading together.

What Host forwarding does. Every HTTP request carries the name the user typed, in the Host header. Without forwarding, Gate443 presents your application with the name in the destination URL; with forwarding on, it presents the custom domain, i.e. what the user sees in the address bar. It does not change where Gate443 connects: only the name it announces.

It matters because almost every application builds its own links from that header. With forwarding on, the links that reach the browser are already the right ones; without it, the application may send the user back to its internal address.

On a generic service the domain stays editable, and that is not a contradiction. The question is fair: if I forward the Host, shouldn't that name necessarily be the server's own? It depends on what the application knows about itself.

The only condition, on a generic service, is that your server accepts the name it receives. If it hosts several sites on the same machine and tells them apart by name, add the custom domain to the names it recognises, or leave forwarding off.

What the origin IP is for. When the field is empty, Gate443 behaves as it always has: it resolves through DNS the name in the destination URL and connects to the resulting address. Empty is fine in three cases out of four:

One case remains, and it is the reason the field exists: custom domain and destination name are the same, i.e. the WordPress setup. Until you touch DNS everything works without an IP too. The moment you point that name at Gate443, the gateway trying to resolve it finds itself, and requests come back in through the front door instead of going out to your server. The origin IP tells the gateway which address to knock at; name, HTTPS and certificate stay those of the destination URL, exactly as a CDN does.

⚠️ The symptom would be unpleasant because it arrives later than the mistake: the service is configured and tested successfully, and stops working hours later, when DNS propagates. That is why, when the two names coincide, the field is required: the panel and the API refuse to save without it, and say why. It is not a formality, it is the only moment when someone still connects the two things.
📧 Get a dedicated SMTP server for white-label services. Without it, the codes leave from the Gate443 server with sender noreply@your-domain: a domain sending through someone else's server easily lands in spam, because your domain's SPF and DKIM records do not authorise that server. With the dedicated server — typically the one already sending for your company (Microsoft 365, Google Workspace or your mail provider), with a noreply@ mailbox created for this — sender, SPF and DKIM are all in your hands and the codes reach the inbox. For port 587 leave the encrypted connection off (STARTTLS is used); for 465 turn it on. After saving, use Send test email and check that the message does not land in spam. If you do not want a dedicated server, publish in your domain's DNS an SPF record that includes the Gate443 server and ask us for the DKIM key.

Useful notes:


7. Protecting your application: accept only Gate443#

This step is what makes the protection real. As long as your application answers anyone, whoever knows its real address can walk around the gate. The rule is: your application accepts connections only from Gate443's address and refuses everything else.

Gate443's address#

Requests to your application come from the Gate443 server:

IP:   4.232.160.186
Name: app.gate443.it   (always resolves to the address in use)

Where your web server or firewall accepts a DNS name, prefer app.gate443.it to the IP: should the address ever change, you would not have to touch anything. In any case a change is announced in advance, with a period during which old and new address stay valid together.

What your application must expose#

HeaderContent
X-Forwarded-For, X-Real-IPthe user's real IP (the connection comes from Gate443)
X-Forwarded-Host, X-Forwarded-Protooriginal host and scheme of the request
X-Gate443-User, X-Gate443-UserIdname and identifier of the user who passed Gate443 (anonymous on the access page)

Configuration examples#

Replace internal.company.com with your application's host and 8080 with the port it runs on.

nginx

server {
    listen 443 ssl;
    server_name internal.company.com;

    location / {
        allow  4.232.160.186;   # Gate443
        deny   all;
        proxy_pass http://127.0.0.1:8080;
    }
}

Apache 2.4

<Location "/">
    Require ip 4.232.160.186
</Location>

IIS — web.config (requires the IP and Domain Restrictions feature, not installed by default)

<system.webServer>
  <security>
    <ipSecurity allowUnlisted="false">
      <add ipAddress="4.232.160.186" allowed="true" />
    </ipSecurity>
  </security>
</system.webServer>

Caddy

internal.company.com {
    @others not remote_ip 4.232.160.186
    respond @others 403
    reverse_proxy 127.0.0.1:8080
}

Firewall, if you'd rather stop requests before they reach the web server:

# Linux, ufw
ufw default deny incoming
ufw allow from 4.232.160.186 to any port 443 proto tcp

# Windows, PowerShell
New-NetFirewallRule -DisplayName "Gate443 only" -Direction Inbound `
  -LocalPort 443 -Protocol TCP -RemoteAddress 4.232.160.186 -Action Allow

The firewall filter is more solid (a refused request never even reaches the application); the web-server filter is handier if you don't manage the network. In the cloud (Azure, AWS, etc.) the same rule goes into the instance's Network Security Group or Security Group.

Verification#

  1. From a PC outside your network open the destination URL directly: it must answer 403 or not answer at all.
  2. Open the service's Gate443 access URL, sign in with the code: the application must load normally.
  3. If step 2 fails with a Gate443 error ("origin unreachable"), the rule is blocking Gate443 too: double-check the address.
If your application runs on the same network as other, unprotected services, remember the rule applies to the protected application: the others stay as they are.

WordPress sites#

💶 White-label is a requirement, not an option. WordPress generates links, redirects and cookies towards its own domain: at the default access URL app.gate443.it/<company>/<service> a site cannot work. A WordPress service therefore costs one service plus one white-label domain of the contract (§4); the panel turns it on by itself and refuses to save a WordPress service without a domain. The default address remains, but redirects to the domain.

Gate443 can sit in front of a WordPress site in two ways, chosen with the Service type (§6):

Same address inside and out. The setup is the same in both cases and mirrors a CDN. The point to grasp is that the site domain does not change: it stays what it has always been, and your server stops being reachable directly.

  1. Destination URL = the site's address as it is today, e.g. https://www.yoursite.com. Pick the WordPress type: Custom domain and Forward the original Host turn on by themselves and stay locked, and the public domain becomes www.yoursite.com, same as the destination and not editable. It counts as one white-label in the contract (§4), and from there you can also set up the dedicated SMTP server.
  2. Origin IP = your server's IP, the one www.yoursite.com resolves to today. It is needed because at step 3 that name will stop leading to your server: Gate443 will keep calling it www.yoursite.com, with the name's HTTPS and certificate, but will knock at this IP.
  3. The DNS of www.yoursite.com moves to Gate443 (§15.3). The HTTPS certificate on the gateway is automatic. WordPress receives www.yoursite.com, i.e. its siteurl, and needs no change at all: no search-replace in the database, no lines in wp-config.php, emails with the right links.
  4. Your server refuses anything that does not come from Gate443. This is the step that makes the protection real: without it, whoever finds the server's IP walks in. See the examples below and in §7.

In one line: the domain goes to the gateway, the gateway knocks at the server's IP, the server accepts only the gateway, and WordPress still believes it is at its own address.

If you prefer to write the destination URL as an IP (e.g. http://203.0.113.10), the public domain cannot be inferred: you type it by hand, and the Origin IP field is not needed.

The plugin is downloaded from the service list, with the zip icon next to the pencil, after saving the service.

The plugin. The zip is already compiled with a secret token and the service's rules. Upload it from Plugins → Add New → Upload Plugin and activate it; alternatively copy gate443.php into wp-content/mu-plugins/ (always active, cannot be deactivated from the WordPress panel). It does three things:

If you regenerate the token from the panel, download and reinstall the plugin. WP-CLI and wp-cron.php are never blocked.

Plugin limits, and the web server rule (VPS). The plugin runs inside PHP: it does not see static files (wp-content/uploads, CSS, JS) and falls with the site if the site is compromised some other way. On shared hosting it is the right choice, because there is nothing else. On a VPS add the rule in the web server, which PHP cannot touch (the IP is the one in §7):

nginx, back office only:

location ~ ^/(wp-login\.php|xmlrpc\.php|wp-admin(?!/admin-ajax\.php)) {
    allow 4.232.160.186;
    deny  all;
    # ... your usual PHP handling (fastcgi_pass / try_files)
}

nginx, whole site: allow 4.232.160.186; deny all; directly in the server block, or in the firewall (ports 80/443 open to that IP only).

Apache, .htaccess in the site root:

<FilesMatch "^(wp-login|xmlrpc)\.php$">
    Require ip 4.232.160.186
</FilesMatch>

and in wp-admin/.htaccess:

<Files "admin-ajax.php">
    Require all granted
</Files>
Require ip 4.232.160.186

With the rule in the web server the plugin remains useful for the real host, https and IP.

Things to know.

Verification.

  1. From a phone on mobile data: https://www.yoursite.com/ shows the site (back office only) or the access page (whole site); https://www.yoursite.com/wp-admin/ leads to the access page.
  2. Directly on the origin's IP: http://<ip>/wp-login.php must answer 403 (plugin or web server) or not answer at all (firewall).
  3. After the code: WordPress login, save a post, upload an image. No link in the page source may contain the origin's IP.

8. Users#

The page you will use most. For each person: first name, last name, email, status.

Search and status filter help with long lists. How many users you can have depends on the contract (50 included per service).


9. User–service mappings#

A user sees a service only if mapped to it. On the Mappings page pick the user and tick the services they must access.

Allowed IPs (optional, per service, comma-separated, IPv4 only, up to 50): if you list them, that user on that service signs in only from those addresses. The code by email is still always required: the address says where from one may enter, the code says who is entering. Empty list = no restriction. Use it to tie an access to the office or the company network (§15.2).

The whole chain must be active. If the user, the service or the mapping is disabled, access does not happen. No exceptions.


10. Customising the access page#

Every service has its own access page, which you brand from the Customisation page: pick the service from the menu and set colours (primary, secondary, background), background image, logo, favicon, title, subtitle and the Privacy and Cookie Policy links. The preview updates as you edit.

The page shows the service's access link: the address to hand to your users.

Branding also applies to the email with the code: it adopts the logo, colour and title set here. On services with a white-label domain the sender becomes a mailbox on your domain (noreply@portal.yourcompany.com): for those emails to be delivered you must authorise Gate443's mail server in your domain's SPF and DKIM records (we provide the values). It is the most frequent cause of "I don't receive the code".

Image limits: logo ~450 KB, favicon ~150 KB, background ~1.8 MB.


11. Security (WAF) of your services#

Besides the platform-wide protection, in Security (WAF) you have your own lists, which apply only to your services (access page and browsing, both on the default URL and on white-label domains):

Evaluation order: whitelisted IP → blacklisted IP → whitelisted country → blacklisted country → ALL. The same address or country cannot be on both lists.

Blocked accesses by your rules appear at the bottom of the page, with IP, country, reason and path.

Whoever matches one of your blocking rules sees a clear message ("Access is not allowed from this address or country") and never even reaches the access page.

12. Access logs and privacy#

Access logs lists who got in, when, from which IP and to which service, with filters by action (Code sent, Sign-in succeeded, Sign-in failed, Browsing), dates and address. You see the data in clear: full emails and IPs.

You decide the retention policy, and it is a choice to make with your privacy officer:

SettingMeaning
Keep logs for N daysBeyond N days logs delete themselves. 0 = never delete.
IP anonymisation — OffIPs stay in clear.
IP anonymisation — After N daysOnce N days have passed, recorded IPs are masked (IPv4: last octet to zero; IPv6: /48).
IP anonymisation — ImmediateThe IP is never written in clear and the user-agent is not recorded.

Whoever runs the platform sees your logs only with anonymised emails and IPs.


13. Dashboard#

Your company at a glance: total and active users, services, sign-ins over the last 7 days, the Your contract panel (bought / used / free), activity over the last 14 days (successful sign-ins and codes sent, per day) and the most used services over the last 30 days.


14. What your users see#

Worth knowing, because it is what you will explain to the people working with you.

  1. The user opens the service link (the default URL or your white-label domain) and sees the access page with your branding.
  2. They enter their email.
  3. They receive a 6-digit code and type it in the same window. The code is single-use, valid for 5 minutes and bound to the source IP and the browser window: forwarding it to a colleague or opening it on another device does not work, by design. If the mapping restricts network addresses and the request comes from an IP not allowed, access is refused even before the email.
  4. They browse the application through Gate443, with the session valid for one hour and extended on every activity.

Things to anticipate:


15. Step-by-step procedures#

15.1 Putting the first service online#

  1. Account security — change the password, enable the authenticator app.
  2. Contract and payments — fill in the billing details and, if you want to continue after the trial, add the card.
  3. Services → New service — name and destination URL of your application.
  4. On your server — accept only 4.232.160.186 (§7) and verify.
  5. Users — enter the people.
  6. Mappings — link every user to the services they need.
  7. Customisation — branding on the access page and the link to hand out.
  8. Access logs — set retention and anonymisation.

15.2 Restricting access to the office with a fixed IP#

  1. Have your network provider confirm the office's static public IP (not the internal IP: the one the office presents itself with on the Internet).
  2. Mappings → user → in the service's Allowed IPs field enter the address; several addresses separated by commas.
  3. Save and verify: from the office the user receives the code as usual; from any other network access is refused. With a dynamic IP this feature is not suitable.

15.3 Publishing a service on your own domain (white-label)#

  1. Services → open the service, enable Custom domain and type the domain (e.g. portal.yourcompany.com). A free white-label in the contract is needed.
  2. In your domain's DNS create an A record to 4.232.160.186, or a CNAME to app.gate443.it.
  3. Wait for propagation and the first certificate issuance (usually 1–2 minutes): HTTPS is automatic.
  4. Email: for the codes to leave from noreply@portal.yourcompany.com without ending up in spam, add Gate443's mail server to the domain's SPF records and configure DKIM with the values we provide. Do it before handing out the link, not after the first report.
  5. The old /<your-company>/<service> address keeps working.

15.4 Someone has left the company#

15.5 A user does not receive the code#

  1. Access logs → filter by that user and look for Code sent. If it is there, the system sent it: the problem is downstream (spam, filters, mailbox).
  2. If it is not there, check that user, service and mapping are all active and that, if the mapping restricts IPs, the user is on an allowed network.
  3. If the service is white-label, check your domain's SPF/DKIM: the most frequent cause.
  4. If nothing adds up, write to us with the user's email and the time of the attempt.

15.6 Protecting the back office of a WordPress site#

  1. Services → New service: name, destination URL = the site's address as it is today (e.g. https://www.yoursite.com), Service type = WordPress — back office only (or whole site). Custom domain and Host forwarding turn on by themselves, with the public domain equal to the destination. Origin IP = your server's IP. Save.
  2. Move the DNS record of www.yoursite.com to Gate443 (§15.3).
  3. Still in the service: Download plugin, upload it to WordPress and activate it (or copy it into mu-plugins). On a VPS, also add the web server rule (§7, WordPress sites).
  4. Users and mappings for whoever administers the site (§8, §9).
  5. Verify as in §7: the site is visible, wp-admin asks for the code, the origin's IP answers 403.

16. Common issues#

SymptomMost likely causeWhat to do
The user enters the email and no service appearsNo active mapping, or user or service disabledCheck the chain in Mappings
"Network address changed. Request a new code"The IP changed between the request and entering the code (VPN, mobile network)Request a new code staying on the same network
The user is sent back to the login while browsingThe IP changed during the session: intended behaviourSign in again; if it recurs, check the network's stability
"Invalid code" repeatedlyCode expired (5 min), already used, or entered in another windowNew code, entered in the same tab
"Too many sign-in attempts from this address"Per-IP request limit exceededWait the minutes shown in the message
"Access is not allowed from this address or country"One of your WAF rules blocks the userSecurity (WAF) → check blacklists and countries; the whitelist takes precedence
The application loads directly even without Gate443Your server still accepts everyoneApply the rule in §7
Gate443 says the origin is unreachableThe rule on your server also blocks 4.232.160.186, or the destination URL is wrongDouble-check address and URL
The protected site looks broken or styles are missingStatic cache with stale content after an updateServices → save the service: the cache is emptied
The white-label domain gives a certificate errorDNS not yet propagated, or domain not enabled on the serviceCheck the DNS record and that the service is active; wait a few minutes
"All services in your contract are in use"Quota used up (active services count)Disable a service you don't use, or write to us to extend the contract
"A service with this name or URL already exists"Duplicate name, disabled ones includedChoose another name or delete the old service
The services show as "suspended"Charge on the 1st failed, or month unpaid beyond the grace periodPress Pay (in Services or Contract and payments), updating the card first if needed; for a bank transfer let us know
I cannot add the cardIncomplete billing detailsFill in company name, full address and VAT number or tax code
"A company email is needed for the free trial"Free mailbox (Gmail, Outlook…)Use an email on your company's domain; if you have none, write to us
"The free trial is one per company: the domain … already used it"Someone with your same company email already activated a trialAsk your administrator for access, or write to us for an exception
Services suspended with "free trial ended"The free days are over and there is no cardAdd the card in Contract and payments: the outstanding month is collected right away and the services restart
I saved the card but the services stay suspendedThe immediate charge of the outstanding months failed (the message says so)Check the card (funds, 3-D Secure authorisation), then Pay now and reactivate
"You upgraded recently: you can reduce the contract after the payment of month …"After an upgrade the downgrade is locked until that month is paidWait for the charge on the 1st (or pay with Pay now). There is no lock during the free trial
"You cannot go below what you use"The reduction would go below active services, white-label, caches or usersDisable or remove first, then reduce
"Superadmin only" when changing the contractPanel not up to dateReload the page; if it persists, write to us
My users find the codes in spamThe codes leave from a server your domain does not authorise (SPF/DKIM)Set up the service's dedicated SMTP server (§6), or publish SPF/DKIM for the Gate443 server
"Sending failed" when testing the dedicated SMTP serverWrong host, port or credentials; port 465 without encrypted connection (or vice versa); service not yet saved with domain and white-label enabledFix the settings and save the service first, then try again
Users get into the application without a codeYou handed out the destination URL (private) instead of the access URLGive users the access URL or the white-label one, and close your server to everyone but Gate443 (§7)
"Your password is temporary" appears at sign-inYour password was set by whoever created your loginAccount security → Change password: the notice disappears on its own

17. Quick reference#

WhatValue
Panelhttps://app.gate443.it/
Access URL of a servicehttps://app.gate443.it/<your-company>/<service> or https://<your-domain>/
Gate443's IP (to allow on your server)4.232.160.186 — name app.gate443.it
User code validity5 minutes, 5 attempts
Panel 2FA code validity5 minutes, 5 attempts
Browsing session1 hour, extended on every activity
Panel passwordat least 8 characters (10 at registration)
Allowed IPs per mappingup to 50, IPv4 only
Entries per WAF listup to 500
Users included50 per service
Grace period on the month's payment7 days from the 1st
Free trial7 days from registration (+1 month from a reseller's link); then the current month is paid

Irreversible operations: deleting a service (with its mappings), removing a user who has no other companies, clearing WAF events. Almost always there is the alternative: disable.

For everything else: gate443.it · support via MiriuM.