Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Register now to learn Fabric in free live sessions led by the best Microsoft experts. From Apr 16 to May 9, in English and Spanish.

Reply
Abhaykumar
Employee
Employee

Error installing personal gateway

We are facing the following issue while installing PowerBI Personal Gateway on a machine:

GatewayInstallError.jpg

The machine has restricted outbound/inbound access to allow connections to only few domains. It seems, during installation, the installer is trying to connect to a domain not allowed by enforced restrictions. We have exception for powerbi.com and able to connect to it from the machine.

 

  1. Is the complete executable for Personal Gateway available that can be installed without it connecting to any other domain. After installation we can configure it to connect to powerbi.com.
  2. According to https://support.powerbi.com/knowledgebase/articles/649846-power-bi-personal-gateway , under Ports section, it is mentioned that Gateway communicates on TCP ports 443, 5671, 5672, 9350 thru 9354. Will gateway work if only port 443 is allowed to connect and other non-standard ports are blocked?
2 REPLIES 2
Greg_Deckler
Super User
Super User

Not sure about if it will work with only 443, but it is only outbound ports that need to be open, it does not require any inbound ports. Not sure why your security folks would configure their firewalls to block outbound ports but security folks tend to be intractable and singularly unreasonable, particularly ones that don't actually know what they are doing and thus just "block everything" by default because "it's more secure that way". Blocking outbound ports is, theorectically, a way to mitigate the damage of an exploit once it has found a foothold within your system. Of course, modern day exploits tend to use well known and almost certainly open ports (like 80, 443) in order to "phone home" these days so the real benefit of this is pretty questionable. Might save you from an exploit by an idiot hacker but if they are an idiot hacker, they probably didn't get past your defenses to implant some malware in the first place.

 

Stepping off of soap box...

 

I believe that the installer is most likely trying to contact a site to see if there are any updates to the installer package. That IP Address is registered to Akamai which is a Content Delivery Network (CDN). So, perhaps just open up that IP or Akamai IP's in order to get the installation to go through.

 

 


@ me in replies or I'll lose your thread!!!
Instead of a Kudo, please vote for this idea
Become an expert!: Enterprise DNA
External Tools: MSHGQM
YouTube Channel!: Microsoft Hates Greg
Latest book!:
The Definitive Guide to Power Query (M)

DAX is easy, CALCULATE makes DAX hard...

Thanks @Greg_Deckler for the reply. We tried talking to the security guys. They are talking about a lengthy process to get any other port opened or connecting to akamai domain. Meanwhile, we wanted to explore if we can get the complete installer and skip connecting to akamai. We can at least test if other ports are required to be opened or not go for the process if that is absolutely necessary.

Let us know, if by any chance, the complete installer can be got that we can copy to the server and install.

Thanks.

Helpful resources

Announcements
Microsoft Fabric Learn Together

Microsoft Fabric Learn Together

Covering the world! 9:00-10:30 AM Sydney, 4:00-5:30 PM CET (Paris/Berlin), 7:00-8:30 PM Mexico City

PBI_APRIL_CAROUSEL1

Power BI Monthly Update - April 2024

Check out the April 2024 Power BI update to learn about new features.

April Fabric Community Update

Fabric Community Update - April 2024

Find out what's new and trending in the Fabric Community.

Top Solution Authors
Top Kudoed Authors