Last updated: July 24, 2026
This guide explains how to secure communications to the MDM server using Secure Gateway, which acts as an intermediary so the MDM server is never directly exposed to the internet or accessible via its own FQDN/IP. Secure Gateway must be installed on a separate machine with port 9383 open. Admins configure NAT settings on the MDM server with the Secure Gateway's FQDN, then install and configure Secure Gateway with the MDM server name and HTTPS port, verifying it's running via services.msc.
As the devices to be managed are mobile and are always on the go, you need to expose your MDM server, to the external networks. This ensures the devices can contact the MDM server, ensuring continued management of devices. For those concerned with the security aspect of server exposure, you can use Secure Gateway. As the name suggests, Secure Gateway adds an additional layer of security ensuring all the incoming communications are directed to the Secure Gateway instead of MDM server. The Secure Gateway acting as intermediary, then routes the communication back to the MDM server. Secure Gateway ensures the MDM server is not directly exposed to the Internet, thus securing it from risks and threats. Secure Gateway also ensures the users cannot access the MDM server(web console) through the FQDN/IP of the machine running Secure Gateway. You can know more about configuring Secure Gateway in about 3 minutes through this demo video.

To verify the Secure Gateway has been installed and running successfully, go to services.msc and ensure ManageEngine Secure Gateway is running.
1. If there are issues with communication to/from the Secure Gateway, ensure the machine on which Secure Gateway is installed, is running and the network connectivity allows it to contact the MDM server.
2. Check if the Secure Gateway is running on the machine, as explained above.
3. If you are using third-party certificates, ensure the certificates have been correctly copied as explained here.
If you still face the issue, contact MDM Support(mdm-support@manageengine.com)
Secure Gateway acts as an intermediary so all incoming device communications are directed to it instead of the MDM server, which keeps the MDM server and its web console from being directly exposed to or accessible via the internet, reducing exposure to external threats.
Secure Gateway must be installed on a machine different from the one hosting the MDM server, and port #9383 must be open and accessible on that machine.
Open services.msc on the machine running Secure Gateway and verify that the ManageEngine Secure Gateway service is running; if there are communication issues, also confirm the machine is online, network connectivity to the MDM server is intact, and any third-party certificates were copied correctly.