Configure Access Gateway DNS

After deployment Access Gateway requires multiple DNS entries, for the gateway itself, testing and production.

This page:

  • Uses the generic address 192.168.A.B to represent the IP address of a Access Gateway deployment. This is an example only.

  • Uses the fictional company in examples.

Required configuration

Value Description


admin Initial IP address of Access Gateway.
Entered into the local /etc/hosts or Windows equivalent.
Used only when initially configuring Access Gateway.
Note: For AWS this is elastic IP, otherwise instance IP address of Access Gateway instance.

192.168.A.B admin


IP address of Access Gateway, entered into DNS typically as an A record.

During testing and initial deployment this value can be added to /etc/hosts but should be recorded in DNS for production environments. which might point to 192.168.A.B

gw [.yourdomain.tld] Access Gateway service listener.
Typically this value is entered as a DNS CNAME record pointing to the gw-admin[.yourdomain.tld]. CNAME record pointing to

DNS summary




Access Gateway domain The default endpoint used to provide Access Gateway authentication and authorization services.
Access Gateway admin domain The endpoint used to provide admin UI services. Use this domain to access the local admin app.
Access Gateway default cookie domain The default cookie domain used for Access Gateway.

Please note:

  • Host entries are only required for status checks.
  • Entries are for a specific given Access Gateway node and are not application domains.
  • Entries should always be pointing to the host IP for the Access Gateway node.

Once configured the Access Gateway Admin UI console should be reachable using the https://gw-admin.[yourdomain.tld] entry as well as the http://admin from a local browser.

See Show a running configuration to determine Access Gateway IP address.

Testing and production configuration

Name Description



For testing.

IP address of Access Gateway when entered into /etc/hosts

Example of a DNS name required for header application testing.

policy.[yourdomain.tld] For testing.

IP address of Access Gateway when entered into /etc/hosts

Example of a DNS name required for policy application testing.

peoplesoft.[yourdomain.tld] Production example.

Example of the DNS required for an application being protected by Access Gateway. This example would be used as the external (public) facing DNS name.

IP address of Access Gateway when entered into /etc/hosts for testing.

CNAME record pointing to [prefix]-admin[.yourdomain.tld] when entered into DNS for actual production use.

See also