Managed Devices

A group of templates always applies to one or more UserGate devices. NGFW, LogAn devices are endpoint managed devices in the UGMC terminology.

To ensure compatibility between different versions of UGMC and managed devices, different versions of the synchronization protocol are used. To enable management of NGFW and LogAn devices from UGMC, the version of the synchronization protocol requested by managed devices must be no higher than that supported by UGMC.

Версия UGMC

NGFW version

LogAn version

6.x.x

UGMC is compatible with 6.x.x devices.

UGMC is not compatible with 7.x.x devices.

LogAn management is not supported.

7.0.x

UGMC is compatible with 6.x.x, 7.0.x devices.

For NGFW versions 6.x.x, the synchronization protocol version is lower than that supported by UGMC. In this case, UGMC will determine whether it is possible to convert the configuration to a lower version and, if conversion is possible, transfer the configuration to the endpoint. If conversion is not possible (the configuration contains parameters that are not available in earlier versions), a synchronization error will be displayed. The error will be shown for the corresponding device in the NGFW Management ➜ NGFW Devices section of the realm management console.

UGMC is not compatible with NGFW 7.1.x and higher. Because the device synchronization protocol version is higher than the protocol version supported by UGMC.

UGMC is compatible with 6.x.x, 7.0.x devices.

UGMC is not compatible with 7.1.x devices and higher. Because the device synchronization protocol version is higher than the protocol version supported by UGMC.

7.1.x

UGMC is compatible with 6.x.x, 7.0.x, 7.1.x devices.

Starting from version 7.1.x, there have been changes in the configuration of the following components:

  • Intrusion Detection and Prevention System;

  • L7 Applications;

  • VPN;

  • User authentication (PKI authentication mode added).

UGMC 7.1.x has limited support for synchronizing the settings of the above sections when working with NGFW versions lower than 7.1.x.

When synchronizing a configuration of UGMC 7.1.x to NGFW versions 6.1.x and 7.0.x previously connected to the MC version below:

  • IDPS: After upgrading the UGMC, the IDPS rules received from an earlier version of the UGMC will no longer be editable.

  • VPN: after updating UGMC, all settings in this section received from an earlier version of UGMC will no longer be editable.

  • All firewall rules that specify an application/IDPS profile will be forcibly disabled before synchronization (i.e., these rules will appear in the UGMC console, but will not work).

For NGFW versions 6.x.x and 7.0.x, the synchronization protocol version is lower than that supported by UGMC. In this case, UGMC will determine whether it is possible to convert the configuration to a lower version and, if conversion is possible, transfer the configuration to the endpoint. If conversion is not possible (the configuration contains parameters that are not available in earlier versions), a synchronization error will be displayed. The error will be shown for the corresponding device in the NGFW Management ➜ NGFW Devices section of the realm management console.

UGMC is compatible with 7.0.x, 7.1.x devices.

There is no device management for versions 6.x.x.