<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Connect SAS Client to SAS Spanner from Different Private Network in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886442#M27012</link>
    <description>&lt;P&gt;The Port on which SAS Spawner Listens (one mentioned in the -service option) is opened between the PNs&amp;nbsp;&lt;/P&gt;&lt;P&gt;below if the Screenshot of Openssl to that port of the server from client server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lalit_Jalkhare_0-1690381433239.png" style="width: 400px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/86131i42C31D585238B72F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lalit_Jalkhare_0-1690381433239.png" alt="lalit_Jalkhare_0-1690381433239.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Also Test-Netconnection is successful on that port&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lalit_Jalkhare_1-1690381486789.png" style="width: 400px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/86133i0D78B62CD105FF2F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lalit_Jalkhare_1-1690381486789.png" alt="lalit_Jalkhare_1-1690381486789.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But the Protcol which is mentioned by out network team is "SSL on TCP port 145XX(on which SAS Spawner listens)" i am not sure if telnet will be alowed over this protocol or not. can you please help me with this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jul 2023 14:26:24 GMT</pubDate>
    <dc:creator>lalit_Jalkhare</dc:creator>
    <dc:date>2023-07-26T14:26:24Z</dc:date>
    <item>
      <title>Connect SAS Client to SAS Spawner from Different Private Network</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886410#M27008</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Hello, We have a SAS Connect spawner running on an RHEL server, and we connect to the SAS Spawner from a SAS Windows client in the same private network with a TCPUNIX.SCR file. It works fine. Now, I want to connect the SAS client from a different private network to the SAS Spawner. However, if I am using a TCPUNIX.SCR file to establish a connection, the firewall blocks it because I think the script uses telnet to log on to the spawner, and our firewall blocks all unencrypted flows. We cannot use scrip less&amp;nbsp;sign-on as our client is fully customized, and it uses customized frames to get the user ID and password of logon. So, is there a way to avoid using telnet or to make the sign-on process encrypted with SSL? We already use 'netencryptionalgorithm=ssl' to invoke our spawner. also please corect me if i am wrong if we use&amp;nbsp;netencryptionalgorithm=ssl to invoke the spawner then it mens our data tranfer is secured with SSL but only telnet is used for logon to the spawner that is our username and password will be exposed if we use telnet ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Our Spawner Process : -&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lalit_Jalkhare_0-1690376990054.png" style="width: 400px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/86117iFD2390C20D954346/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lalit_Jalkhare_0-1690376990054.png" alt="lalit_Jalkhare_0-1690376990054.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Our Client's Customized logon Frame&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lalit_Jalkhare_1-1690377075861.png" style="width: 400px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/86118iDAD4E3155C293BAF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lalit_Jalkhare_1-1690377075861.png" alt="lalit_Jalkhare_1-1690377075861.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;also we are able to ping the server&amp;nbsp; from our client from different Private Network.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lalit_Jalkhare_2-1690377272974.png" style="width: 400px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/86119i16C4E4571C191B12/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lalit_Jalkhare_2-1690377272974.png" alt="lalit_Jalkhare_2-1690377272974.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if i try to telnet the server port which SAS Spawner is listening the screen goes blank i am not sure if the connection is successful or not&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lalit_Jalkhare_4-1690377504865.png" style="width: 400px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/86121iCA6E537484A96BFE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lalit_Jalkhare_4-1690377504865.png" alt="lalit_Jalkhare_4-1690377504865.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lalit_Jalkhare_3-1690377453715.png" style="width: 400px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/86120iBB56AF7CD18D9017/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lalit_Jalkhare_3-1690377453715.png" alt="lalit_Jalkhare_3-1690377453715.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Below is the Error i get when trying to logon using script from client of different private network&lt;/P&gt;
&lt;P&gt;&lt;U&gt;ERROR:&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TRACE:&amp;nbsp;&amp;nbsp;&amp;nbsp; Echo on;&lt;BR /&gt;TRACE:&amp;nbsp;&amp;nbsp;&amp;nbsp; Log 'NOTE: Script file 'tcpunix.scr' entered.';&lt;BR /&gt;NOTE: Script file 'tcpunix.scr' entered.&lt;BR /&gt;TRACE:&amp;nbsp;&amp;nbsp;&amp;nbsp; If not TCP then goto notcp;&lt;BR /&gt;TRACE:&amp;nbsp;&amp;nbsp;&amp;nbsp; If signoff then goto signoff;&lt;BR /&gt;TRACE:&amp;nbsp;&amp;nbsp;&amp;nbsp; Waitfor&amp;nbsp;&amp;nbsp;&amp;nbsp; 'login:',&lt;BR /&gt;TRACE:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 'Username:',&lt;BR /&gt;TRACE:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 'Scripted signon not allowed': noscript,&lt;BR /&gt;TRACE:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 120.0 seconds: noinit;&lt;BR /&gt;TRACE: noinit:&lt;BR /&gt;TRACE:&amp;nbsp;&amp;nbsp;&amp;nbsp; Log 'ERROR: Did not understand remote session banner.';&lt;BR /&gt;ERROR: Did not understand remote session banner.&lt;BR /&gt;TRACE: nolog:&lt;BR /&gt;TRACE:&amp;nbsp;&amp;nbsp;&amp;nbsp; Log 'ERROR: Did not receive userid or password prompt.';&lt;BR /&gt;ERROR: Did not receive userid or password prompt.&lt;BR /&gt;TRACE:&amp;nbsp;&amp;nbsp;&amp;nbsp; Abort;&lt;BR /&gt;NOTE: End of script file trace.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please let me know if there is a way to avoid using telnet or to secure the logon process using SSL.&lt;/P&gt;
&lt;P&gt;Manny Thanks already&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 13:46:14 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886410#M27008</guid>
      <dc:creator>lalit_Jalkhare</dc:creator>
      <dc:date>2023-07-26T13:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: Connect SAS Client to SAS Spanner from Different Private Network</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886415#M27009</link>
      <description>&lt;P&gt;You can give these ideas a try:&lt;/P&gt;
&lt;P&gt;1) Remove the '-cleartext' option. That makes everything be unencoded/encrypted.&lt;/P&gt;
&lt;P&gt;2) Add the '-netencrypt' option. This will force clients to use the encryption you specify.&lt;/P&gt;
&lt;P&gt;3) Make sure the port used is not the standard telnet port (23), but rather one that you specify and the firewall knows about. Firewalls may block the default port automatically.&lt;/P&gt;
&lt;P&gt;4) You will need to make sure communication can occur between your two private subnets.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 13:38:30 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886415#M27009</guid>
      <dc:creator>doug_sas</dc:creator>
      <dc:date>2023-07-26T13:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: Connect SAS Client to SAS Spanner from Different Private Network</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886425#M27010</link>
      <description>&lt;P&gt;I have made the changes suggested by you&amp;nbsp;&lt;/P&gt;&lt;P&gt;Spawner Process :-&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lalit_Jalkhare_0-1690379995242.png" style="width: 400px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/86123iEBD371FD2051C1C2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lalit_Jalkhare_0-1690379995242.png" alt="lalit_Jalkhare_0-1690379995242.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But Got the Same Error from the new client :(, also we are using a dedicated port for SAS Spawner not the default one, and both out&amp;nbsp;&lt;SPAN&gt;private subnets. can communicate&amp;nbsp;with each&amp;nbsp;other as we have other applications which uses HTTPS ports and we are able to access the server through&amp;nbsp;HTTPS ports&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;TRACE:&amp;nbsp;&amp;nbsp;&amp;nbsp; Echo on;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;TRACE:&amp;nbsp;&amp;nbsp;&amp;nbsp; Log 'NOTE: Script file 'tcpunix.scr' entered.';&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;NOTE: Script file 'tcpunix.scr' entered.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;TRACE:&amp;nbsp;&amp;nbsp;&amp;nbsp; If not TCP then goto notcp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;TRACE:&amp;nbsp;&amp;nbsp;&amp;nbsp; If signoff then goto signoff;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;TRACE:&amp;nbsp;&amp;nbsp;&amp;nbsp; Waitfor&amp;nbsp;&amp;nbsp;&amp;nbsp; 'login:',&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;TRACE:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 'Username:',&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;TRACE:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 'Scripted signon not allowed': noscript,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;TRACE:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 120.0 seconds: noinit;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;___________________________________________________&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;also&amp;nbsp; i trayed&amp;nbsp;to increase the wait time in tcpunix.scr script by 2-3 mins after that also no luck,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for your Reply please let me know if there is something else that we can try&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 14:05:22 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886425#M27010</guid>
      <dc:creator>lalit_Jalkhare</dc:creator>
      <dc:date>2023-07-26T14:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: Connect SAS Client to SAS Spanner from Different Private Network</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886434#M27011</link>
      <description>&lt;P&gt;The CONNECT spawner does not use HTTP or HTTPS so it would not be using 80/443. The spawner is using the port defined by the name 'sasspawn' (because you used the option "-service sasspawn").&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sure whatever port sasspawn translates to is open in your firewall. You may be able to see information from the spawner output. If not, you could add the '-debug' or '-trace/-verbose' options to get more information from the spawner.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 14:16:43 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886434#M27011</guid>
      <dc:creator>doug_sas</dc:creator>
      <dc:date>2023-07-26T14:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: Connect SAS Client to SAS Spanner from Different Private Network</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886442#M27012</link>
      <description>&lt;P&gt;The Port on which SAS Spawner Listens (one mentioned in the -service option) is opened between the PNs&amp;nbsp;&lt;/P&gt;&lt;P&gt;below if the Screenshot of Openssl to that port of the server from client server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lalit_Jalkhare_0-1690381433239.png" style="width: 400px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/86131i42C31D585238B72F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lalit_Jalkhare_0-1690381433239.png" alt="lalit_Jalkhare_0-1690381433239.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Also Test-Netconnection is successful on that port&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lalit_Jalkhare_1-1690381486789.png" style="width: 400px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/86133i0D78B62CD105FF2F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lalit_Jalkhare_1-1690381486789.png" alt="lalit_Jalkhare_1-1690381486789.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But the Protcol which is mentioned by out network team is "SSL on TCP port 145XX(on which SAS Spawner listens)" i am not sure if telnet will be alowed over this protocol or not. can you please help me with this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 14:26:24 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886442#M27012</guid>
      <dc:creator>lalit_Jalkhare</dc:creator>
      <dc:date>2023-07-26T14:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: Connect SAS Client to SAS Spanner from Different Private Network</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886445#M27013</link>
      <description>&lt;P&gt;The spawner protocol is based off of Telnet and uses telnet packets to tell the spawner to switch into encrypted mode. You cannot debug this using openssl or PowerShell commands since they do not provide the correct telnet packets. The only client that does provide the correct information is SAS processing a SIGNON statement.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are probably going to need to open a tech support track so that they can get CONNECT spawner trace logs from you and work with you on a solution.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 14:33:48 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886445#M27013</guid>
      <dc:creator>doug_sas</dc:creator>
      <dc:date>2023-07-26T14:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Connect SAS Client to SAS Spanner from Different Private Network</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886528#M27015</link>
      <description>&lt;P&gt;Thanks for your reply, i have raised a service request with SAS team to move forward.&lt;/P&gt;&lt;P&gt;also i checked with our network team they said our protocol templates block unencrypted flows (like telnet) on Application layer lever may be that is the issue.&lt;/P&gt;&lt;P&gt;it will be grateful if you can answer me on below questions :-&lt;/P&gt;&lt;P&gt;1. if we used script base sign on then on application layer level Telnet is used to login to spawner ?&lt;/P&gt;&lt;P&gt;2. if we go with Script less sign on which protocol on application layer will be used like SSH, telnet,SSL etc. ?&lt;/P&gt;&lt;P&gt;3. is there a way to encrypt telnet connection with SSl while logon to SAS Spawner&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 19:31:48 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886528#M27015</guid>
      <dc:creator>lalit_Jalkhare</dc:creator>
      <dc:date>2023-07-26T19:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: Connect SAS Client to SAS Spanner from Different Private Network</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886572#M27017</link>
      <description>&lt;P&gt;I highly recommend you try scriptless SIGNONs as it avoids the complication of using scripts, telnet, and having firewall rules for telnet ports.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With scriptless&amp;nbsp;SIGNONs you connect directly to the SASApp Connect server using the default port number 7551 avoiding telnet completely. You can check your actual port number in SMC:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SASKiwi_0-1690430327926.png" style="width: 400px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/86160i80705AA1F157435F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SASKiwi_0-1690430327926.png" alt="SASKiwi_0-1690430327926.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 04:33:03 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886572#M27017</guid>
      <dc:creator>SASKiwi</dc:creator>
      <dc:date>2023-07-27T04:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Connect SAS Client to SAS Spanner from Different Private Network</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886588#M27019</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/13976"&gt;@SASKiwi&lt;/a&gt;&amp;nbsp;Thanks for your Reply, our SAS Spawner run on a Unix Server and We have Defined Spawner to use on port 14555 so just to be clear our Spawner will listen on port 14555 right or it will listen on default port 7551 because port 7551 is not opened between our sever and client PNs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also can you tell from where i can launch SMC to check the port SAS Spawner is using ?&lt;/P&gt;&lt;P&gt;Manny thanks in advance for your time.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 07:09:51 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886588#M27019</guid>
      <dc:creator>lalit_Jalkhare</dc:creator>
      <dc:date>2023-07-27T07:09:51Z</dc:date>
    </item>
    <item>
      <title>Re: Connect SAS Client to SAS Spanner from Different Private Network</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886618#M27022</link>
      <description>&lt;P&gt;Scripted SIGNONs and scriptless SIGNONs all go to whatever port you tell them to go to in the SIGNON statement. The spawner listens on the port specified by the '-service' option (with the default being the 'telnet' service which is usually mapped to port 23).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Scriptless SIGNONs will start SAS using the command designated by the spawners '-sascmd' option (or execute the command 'sas' if the option is not present) whereas scripted follows logic in the script file.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is all assuming you are not using information in the metadata server for the CONNECT spawner. If you were, I would expect to see the spawner option '-sasspawnercn' on the command line which references the spawner definition in metadata.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 11:52:00 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886618#M27022</guid>
      <dc:creator>doug_sas</dc:creator>
      <dc:date>2023-07-27T11:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: Connect SAS Client to SAS Spanner from Different Private Network</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886624#M27023</link>
      <description>&lt;P&gt;The CONNECT protocol from client to spawner starts out using telnet-like protocol to negotiate CONNECT options including encryption. The negotiation is done by the spawner sending telnet bytes to the client asking the client if it supports a specific option&amp;nbsp; and the client responding with telnet bytes indicating whether it does or not. One of the last options negotiated is the type of encryption. Since you added the '-netencrypt' option, the negotiation will fail if the client is not supporting the specified encryption.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once the encryption has been negotiated, everything from then on is encrypted including the processing of the script or the handshake for a scriptless connection.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 13:03:04 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886624#M27023</guid>
      <dc:creator>doug_sas</dc:creator>
      <dc:date>2023-07-27T13:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: Connect SAS Client to SAS Spanner from Different Private Network</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886627#M27024</link>
      <description>&lt;P&gt;Okey, Thanks alot for the clear Explanation, so it means anyways we will need our Firewall to allow telnet to do the negotiations whether we go with Script or Script less Signon. Please correct me if i am wrong&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 13:14:22 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886627#M27024</guid>
      <dc:creator>lalit_Jalkhare</dc:creator>
      <dc:date>2023-07-27T13:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: Connect SAS Client to SAS Spanner from Different Private Network</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886628#M27025</link>
      <description>&lt;P&gt;If your firewall is looking at the negotiation data and preventing it from passing through then you will either need to change the firewall behavior or create a SSH tunnel from the client machine to the spawner machine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are some links that may help with the SSH tunneling:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://support.sas.com/documentation/cdl/en/secref/69831/HTML/default/viewer.htm#p0sv5ora53jf71n1v6dk3rdmdety.htm" target="_blank"&gt;https://support.sas.com/documentation/cdl/en/secref/69831/HTML/default/viewer.htm#p0sv5ora53jf71n1v6dk3rdmdety.htm&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://support.sas.com/resources/papers/proceedings11/359-2011.pdf" target="_blank"&gt;https://support.sas.com/resources/papers/proceedings11/359-2011.pdf&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 27 Jul 2023 13:20:12 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886628#M27025</guid>
      <dc:creator>doug_sas</dc:creator>
      <dc:date>2023-07-27T13:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: Connect SAS Client to SAS Spanner from Different Private Network</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886703#M27027</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/446079"&gt;@lalit_Jalkhare&lt;/a&gt;&amp;nbsp; - SAS Management Console (SMC) is usually a PC-installed client tool. If you don't have it installed currently then install it from your SAS Software Depot using the SAS Deployment Wizard.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 20:02:59 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886703#M27027</guid>
      <dc:creator>SASKiwi</dc:creator>
      <dc:date>2023-07-27T20:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: Connect SAS Client to SAS Spanner from Different Private Network</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886722#M27028</link>
      <description>&lt;P&gt;Hello I tried Logon with A Script less method from the client, After Entering the User Name and password in the Prompt Screen it just keeps on Loading for 3-5 mins&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lalit_Jalkhare_0-1690490982391.png" style="width: 400px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/86181iD42102C1AE3808B5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lalit_Jalkhare_0-1690490982391.png" alt="lalit_Jalkhare_0-1690490982391.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then i receive the below Error.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lalit_Jalkhare_1-1690491007645.png" style="width: 400px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/86182iF494227E8B28E693/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lalit_Jalkhare_1-1690491007645.png" alt="lalit_Jalkhare_1-1690491007645.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SAS Spawner Process:-&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lalit_Jalkhare_0-1690492200261.png" style="width: 400px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/86188iDE9B3BE4E57195FF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lalit_Jalkhare_0-1690492200261.png" alt="lalit_Jalkhare_0-1690492200261.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Spawner is Running on the Server and Below SIGNON Code i used to Signon to the Server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lalit_Jalkhare_2-1690491133882.png" style="width: 400px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/86185i43C549597BEE122E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lalit_Jalkhare_2-1690491133882.png" alt="lalit_Jalkhare_2-1690491133882.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;TOOLremo contains the name of the Server and sasspawn is the port service on which our Spawner is listening.&amp;nbsp;Also &amp;nbsp;NetEncrptionAlgorith=SSl Option has been Already Defined the Code of Client.&amp;nbsp;&lt;/P&gt;&lt;P&gt;and the same port is opened between both our Server and Client Network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Above code Just Works Fine from the Client Server which is in same PN of the Server in which SAS Spawner runs.&lt;/P&gt;&lt;P&gt;but when i try to logon from the client from Different PN it fails with above mentioned Error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you Please help me to resolve this issue&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 21:10:09 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886722#M27028</guid>
      <dc:creator>lalit_Jalkhare</dc:creator>
      <dc:date>2023-07-27T21:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: Connect SAS Client to SAS Spanner from Different Private Network</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886744#M27032</link>
      <description>&lt;P&gt;So it works OK over one PVN but not another? The SAS log errors suggest the TCP socket you are trying is blocked. This is most likely a port rule issue. Try testing the port via the problematic PVN.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 00:05:50 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886744#M27032</guid>
      <dc:creator>SASKiwi</dc:creator>
      <dc:date>2023-07-28T00:05:50Z</dc:date>
    </item>
    <item>
      <title>Re: Connect SAS Client to SAS Spanner from Different Private Network</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886798#M27037</link>
      <description>&lt;P&gt;SAS Management Console (SASMC) is a java program that runs on Windows/Linux/UNIX.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is not a PC program like Enterprise Guide.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 11:55:51 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886798#M27037</guid>
      <dc:creator>doug_sas</dc:creator>
      <dc:date>2023-07-28T11:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: Connect SAS Client to SAS Spanner from Different Private Network</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886801#M27038</link>
      <description>&lt;P&gt;For test purposes, be more explicit about your SIGNON rather than default to variables since they may not contain what you think.&lt;/P&gt;
&lt;P&gt;Try&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;options netencralg=ssl;
%let testrem=&amp;lt;spawner-host-FQDN&amp;gt; &amp;lt;spawner-port-number&amp;gt;;
SIGNON testrem USER=_PROMPT_ password=_PROMPT_;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, turn on trace logging on the spawner so that you can see if a connection is made and a server is spawned. This will help you know if the client was able to get to the spawner or not and if it did, whether it was able to spawn a server. If the spawner does not show a connection being made, then the firewall is preventing access or there is no route from the client to the spawner.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 12:09:11 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886801#M27038</guid>
      <dc:creator>doug_sas</dc:creator>
      <dc:date>2023-07-28T12:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: Connect SAS Client to SAS Spanner from Different Private Network</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886816#M27041</link>
      <description>&lt;P&gt;Hello I tried, the Code Provided By you To SIGNON to the Spawner,&lt;/P&gt;&lt;P&gt;Which i start the login process on the client the screen keeps on roiling and on the server i can see in Netstat that the coneection with client server is established on Spawner port, but after 1-2 minutes the netstat status becomes&amp;nbsp; FIN_WAIT1 and then the connection is closed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sever - Client Connection Established then closed :-&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lalit_Jalkhare_1-1690553733703.png" style="width: 400px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/86210iC13EDCED37DFE98C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lalit_Jalkhare_1-1690553733703.png" alt="lalit_Jalkhare_1-1690553733703.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Port opened between Server and Client :-&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lalit_Jalkhare_3-1690554101021.png" style="width: 400px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/86212iDB7FC591CC8FA00F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lalit_Jalkhare_3-1690554101021.png" alt="lalit_Jalkhare_3-1690554101021.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And then i receive below Error on the client&amp;nbsp;&lt;/P&gt;&lt;P&gt;ERROR: A communication subsystem partner link setup request failure has occurred.&lt;BR /&gt;ERROR: Cannot read TCP socket. System message is ''.&lt;BR /&gt;ERROR: Remote signon to TOOLREMO canceled.&lt;BR /&gt;NOTE ETL: Log Remote Session :ERROR: A communication subsystem partner link setup request failure has occurred.&lt;BR /&gt;NOTE ETL: Log Remote Session :ERROR: Cannot read TCP socket. System message is ''.&lt;BR /&gt;NOTE ETL: Log Remote Session :ERROR: Remote signon to TOOLREMO canceled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;________________________________________________________________________________________________________&lt;/P&gt;&lt;P&gt;also i checked with my network team the are Saying the firewall is able to establish a telnet connection between Server and client over the Spawner port but it will Only allow the packets/communications which are secured will SSL as soon as it will detect any unencrypted communication it will terminate the connection.&lt;/P&gt;&lt;P&gt;i am thinking maybe is the client is not able to negotiate the encryption algorithm used be the Spawner. can you help me to understand how exactly the encryption negotiations actually works in SAS Spawner and client so that i can check with the Network team.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Manny thanks Already for all the help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 14:23:57 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886816#M27041</guid>
      <dc:creator>lalit_Jalkhare</dc:creator>
      <dc:date>2023-07-28T14:23:57Z</dc:date>
    </item>
    <item>
      <title>Re: Connect SAS Client to SAS Spanner from Different Private Network</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886818#M27042</link>
      <description>&lt;P&gt;So I take it you did not see a connection in the log put out by the spawner? I did not see a spawner log in your response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The data sent to the spawner will not be encrypted at the start since it has to negotiate encryption first. If the firewall does not like that,&amp;nbsp;SSH tunneling will be your only answer to getting through the firewall.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 14:29:12 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Connect-SAS-Client-to-SAS-Spawner-from-Different-Private-Network/m-p/886818#M27042</guid>
      <dc:creator>doug_sas</dc:creator>
      <dc:date>2023-07-28T14:29:12Z</dc:date>
    </item>
  </channel>
</rss>

