<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Firewall Constraints and allowlisting for Synthetic Monitoring in Troubleshooting</title>
    <link>https://community.dynatrace.com/t5/Troubleshooting/Firewall-Constraints-and-allowlisting-for-Synthetic-Monitoring/ta-p/213876</link>
    <description>&lt;H2&gt;Summary&lt;/H2&gt;
&lt;DIV&gt;
&lt;DIV class="paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol"&gt;Dynatrace Synthetic Monitoring may require additional firewall, proxy, and allowlisting configuration to ensure Browser Monitors and HTTP Monitors can successfully access your applications and return results to Dynatrace.&lt;/DIV&gt;
&lt;DIV class="paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol"&gt;Because Browser Monitors use the same data-ingestion technology as Real User Monitoring (RUM), you should also review and implement the RUM firewall requirements described &lt;A class="fui-Link fai-bebop ___1v1lyro f2hkw1w f3rmtva f1ewtqcl f16muhyy f1k6fduh f1w7gpdv f1mo0ibp fjoy568 ff5ikls f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f33ey8m f9n3di6 f1ids18y f1tx3yz7 feiuef2 f1eh06m1 f54796x fhgqx19 f1olyrje f1p93eir f1nev41a f132whgj f1v74mp6 f1tsf1ni fnq52rx f16zlvvm" tabindex="0" href="https://docs.dynatrace.com/docs/observe/digital-experience/web-applications/initial-setup/firewall-constraints-for-rum" rel="noopener noreferrer" data-tabster="{&amp;quot;restorer&amp;quot;:{&amp;quot;type&amp;quot;:1}}" target="_blank"&gt;here&lt;/A&gt;.&lt;/DIV&gt;
&lt;DIV class="paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol"&gt;This article focuses on the additional network, connectivity, and allowlisting requirements specific to Synthetic Monitoring and provides troubleshooting guidance for common connectivity-related issues.&lt;/DIV&gt;
&lt;DIV class="paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol"&gt;&lt;STRONG&gt;Use this guide if your Browser Monitor or HTTP Monitor:&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf"&gt;Times out or fails to connect to the target application&lt;/LI&gt;
&lt;LI class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf"&gt;Returns connection refused or other network-related errors&lt;/LI&gt;
&lt;LI class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf"&gt;Fails authentication unexpectedly&lt;/LI&gt;
&lt;LI class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf"&gt;Works when tested manually but fails in Synthetic Monitoring&lt;/LI&gt;
&lt;LI class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf"&gt;Runs successfully but doesn't report results back to Dynatrace&lt;/LI&gt;
&lt;LI class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf"&gt;Fails only from specific public or private Synthetic locations&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV class="paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol"&gt;Common causes include:&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf"&gt;Firewall restrictions&lt;/LI&gt;
&lt;LI class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf"&gt;Missing IP allowlisting&lt;/LI&gt;
&lt;LI class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf"&gt;User-Agent filtering&lt;/LI&gt;
&lt;LI class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf"&gt;Proxy configuration issues&lt;/LI&gt;
&lt;LI class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf"&gt;DNS resolution problems&lt;/LI&gt;
&lt;LI class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf"&gt;Network routing or outbound connectivity limitations&lt;/LI&gt;
&lt;LI class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf"&gt;ActiveGate connectivity or communication issues&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-TOC indent="15" liststyle="disc" maxheadinglevel="5"&gt;&lt;/LI-TOC&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Issues&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Synthetic monitors fail to reach an application&lt;/H3&gt;
&lt;H4&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4&gt;Synthetic Monitor executes from a public location but fails to connect to an application&lt;/H4&gt;
&lt;P&gt;An affected synthetic monitor may show different failures, such as request timeouts, authentication failures, connection refusals, etc. The key is that the monitor is &lt;U&gt;permanently failing with the same outage.&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What can you do?&lt;BR /&gt;Confirm the following with the relevant Application team:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Should the application be available outside your network?&lt;/LI&gt;
&lt;LI&gt;If so, are there any limitations?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;We recommend allowing our traffic by either &lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Firewall-Constraints-and-allowlisting-for-Synthetic-Monitoring/ta-p/213876#toc-hId--582390901" target="_self"&gt;allowing access by User Agent string or IP address&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Synthetic Monitor executes from a private location but fails to connect to an application&lt;/H4&gt;
&lt;P&gt;In addition to the checks for public locations, here are some helpful tests you can try from your private location.&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H5&gt;Troubleshoot using Curl&lt;/H5&gt;
&lt;P&gt;Use this command to confirm whether the connection issue relates to Dynatrace or the machine.&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;curl -vki &amp;lt;url you're testing&amp;gt;&lt;/PRE&gt;
&lt;P&gt;Or if you're using a proxy:&lt;/P&gt;
&lt;PRE&gt;curl -vki -U proxyUser:proxyPassword -x proxy:proxyPort &amp;lt;url you're testing&amp;gt; &lt;/PRE&gt;
&lt;P&gt;If the site is redirected to another page, you also need to add -L to follow redirects. For example,&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;curl -vki -L &amp;lt;url you're testing&amp;gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What can you do if the result of the command fails?&lt;/STRONG&gt;&lt;BR /&gt;If the curl command fails, the issue lies in the connection between the machine and the application you're testing. Here's what you can do to fix it:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Update your proxy or allow the IP access.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;If the result of the command is successful&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Check if the Dynatrace User-Agent string affects the behavior
&lt;OL&gt;
&lt;LI&gt;For HTTP Monitors, add&amp;nbsp;-H "User-Agent: DynatraceSynthetic/1.267.13.20230518-162314"&amp;nbsp;
&lt;PRE&gt;curl -vki &amp;lt;url you're testing&amp;gt; -H "User-Agent: DynatraceSynthetic/1.267.13.20230518-162314"​&lt;/PRE&gt;
&lt;/LI&gt;
&lt;LI&gt;For Browser Monitors, add&amp;nbsp;-H "User-Agent: &lt;SPAN&gt;Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/113.0.0.0 Safari/537.36 RuxitSynthetic/1.0 v0 t0 cfeatureHash=7efgijmoqtvx caes=1 ccux=1 sia=1 smf=1&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;"&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;PRE&gt;curl -vki &amp;lt;url you're testing&amp;gt; -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/113.0.0.0 Safari/537.36 RuxitSynthetic/1.0 v0 t0 cfeatureHash=7efgijmoqtvx caes=1 ccux=1 sia=1 smf=1"&lt;/PRE&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;&lt;BR /&gt;What can you do if the command's result fails?&lt;/STRONG&gt; You should &lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Firewall-Constraints-and-allowlisting-for-Synthetic-Monitoring/ta-p/213876#toc-hId--636531925" target="_self"&gt;allow/ allowlist our User-Agent string on your Application/ Firewall.&amp;nbsp;&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;Troubleshoot using PowerShell&lt;/H5&gt;
&lt;P&gt;If you're working on Windows, you may only have the option of PowerShell instead of curl. You can use Invoke-WebRequest.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Without proxy:&lt;/P&gt;
&lt;PRE&gt;Invoke-WebRequest -Uri "&amp;lt;url you're testing&amp;gt;"&lt;/PRE&gt;
&lt;P&gt;With proxy:&lt;/P&gt;
&lt;PRE&gt;Invoke-WebRequest -Proxy "&amp;lt;proxy-url&amp;gt;:&amp;lt;proxy-port&amp;gt;" -ProxyUseDefaultCredentials -Uri "&amp;lt;url you're testing&amp;gt;"&lt;/PRE&gt;
&lt;P&gt;With redirects following and printing raw response:&lt;/P&gt;
&lt;PRE&gt;Invoke-WebRequest -MaximumRedirection 10 -Uri "&amp;lt;url you're testing&amp;gt;" | Select-Object -Expand RawContent&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What can you do if the result of the command fails&lt;/STRONG&gt;&lt;BR /&gt;If the curl command fails, the issue lies in the connection between the machine and the application you're testing. Here's what you can do to fix it:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Update your proxy or allow the IP access.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;If the result of the command is successful&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Check if it's the Dynatrace User-Agent string by adding that header to the Invoke-WebRequest command
&lt;UL&gt;
&lt;LI&gt;For HTTP Monitors, add&amp;nbsp;-H "User-Agent: DynatraceSynthetic/1.267.13.20230518-162314"
&lt;PRE&gt;Invoke-WebRequest -Uri "&amp;lt;url you're testing&amp;gt;" -Headers @{"User-Agent"="DynatraceSynthetic/1.267.13.20230518-162314"}​&lt;/PRE&gt;
&lt;/LI&gt;
&lt;LI&gt;For Browser Monitors, add&amp;nbsp;-H "User-Agent: &lt;SPAN&gt;Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/113.0.0.0 Safari/537.36 RuxitSynthetic/1.0 v0 t0 cfeatureHash=7efgijmoqtvx caes=1 ccux=1 sia=1 smf=1&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;"&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;PRE&gt;Invoke-WebRequest -Uri "&amp;lt;url you're testing&amp;gt;" -Headers @{"User-Agent"="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/113.0.0.0 Safari/537.36 RuxitSynthetic/1.0 v0 t0 cfeatureHash=7efgijmoqtvx caes=1 ccux=1 sia=1 smf=1"}&lt;/PRE&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;What can you do if the command's result fails? &lt;/STRONG&gt;You should allow/ allowlist our &lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Firewall-Constraints-and-allowlisting-for-Synthetic-Monitoring/ta-p/213876#toc-hId--636531925" target="_self"&gt;User-Agent string on your Application/ Firewall.&amp;nbsp;&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;Troubleshoot using a Browser on the Synthetic ActiveGate&lt;/H5&gt;
&lt;P&gt;If it has a GUI, you can test Browser Monitors from your Synthetic ActiveGate. This is usually&amp;nbsp;the case for Windows ActiveGates, so I'll focus on those.&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Open a Chrome Browser on your Synthetic ActiveGate and navigate to the URL you're testing.
&lt;OL&gt;
&lt;LI&gt;If you can't reach it, the problem is that the machine itself can't reach the URL.&lt;BR /&gt;Allow/ allowlist the IP or update your proxy settings.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;If you can access Dynatrace from the ActiveGate, &lt;A href="https://www.dynatrace.com/support/help/platform-modules/digital-experience/synthetic-monitoring/browser-monitors/configure-browser-monitors#recorded-clickpath" target="_self"&gt;playback&lt;/A&gt; the monitor in the Browser.
&lt;OL&gt;
&lt;LI&gt;If it fails, it may be the User Agent string. As mentioned above, you can confirm this using curl or PowerShell.&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;Open the Browser that the ActiveGate uses to execute the monitors. The default path is&amp;nbsp;C:\Program Files\dynatrace\synthetic\Chrome-bin\chrome.exe.
&lt;OL&gt;
&lt;LI&gt;If this fails, compare the difference in version to the Chrome Browser installed on the machine.&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;Sometimes, the service user who starts Chrome doesn't have enough permissions to reach the site. Please do the following to check if that is the case:&amp;nbsp;
&lt;OL&gt;
&lt;LI&gt;On the Synthetic ActiveGate, download and unzip PsExec &lt;A href="https://docs.microsoft.com/en-us/sysinternals/downloads/psexec" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/sysinternals/downloads/psexec&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Open a command prompt as administrator (Start -&amp;gt; cmd.exe -&amp;gt; Run as administrator) and navigate to the folder you extracted PSExec&lt;/LI&gt;
&lt;LI&gt;To start Chromium impersonating the "Local Service" user, run PsExec with the following command:&amp;nbsp;
&lt;PRE&gt;PsExec.exe -i -u "NT Authority\LocalService" "C:\Program Files\dynatrace\synthetic\Chrome-bin\chrome.exe"​&lt;/PRE&gt;
&lt;P&gt;(If you installed the synthetic location in a non-standard path, you'll need to adapt the path to chrome.exe)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;Then navigate to the URL you're testing.&amp;nbsp;&lt;SPAN&gt;If this fails, you may wish to try setting up &lt;A href="https://docs.dynatrace.com/docs/observe/digital-experience/synthetic-monitoring/general-information/synthetic-authentication#http-bm" target="_self"&gt;Kerberos authentication for your browser monitor&lt;/A&gt; or &lt;A href="https://community.dynatrace.com/t5/Troubleshooting/Firewall-Constraints-and-allowlisting-for-Synthetic-Monitoring/ta-p/213876#toc-hId--512414842" target="_self"&gt;logging in to the Dynatrace Synthetic service as a domain user.&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN&gt;Synthetic Monitor data is not returned to, or seen by, Dynatrace&lt;/SPAN&gt;&lt;/H3&gt;
&lt;H4&gt;&lt;STRONG&gt;For SaaS tenants &lt;/STRONG&gt;&lt;/H4&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;Confirm that the monitor is enabled.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Confirm that there are no maintenance windows during the data gap. This can be confirmed on the browser&lt;A href="https://docs.dynatrace.com/docs/observe/digital-experience/synthetic-monitoring/analysis-and-alerting/synthetic-details-for-browser-monitors#synthetic-details-for-browser-monitors" target="_self"&gt;&amp;nbsp;monitor details page&lt;/A&gt; or the &lt;A href="https://docs.dynatrace.com/docs/observe/digital-experience/synthetic-monitoring/analysis-and-alerting/synthetic-details-for-http-monitors-classic#metric-visualizations" target="_self"&gt;HTTP Monitors details page.&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;If it's on a private location&lt;/SPAN&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;Check for &lt;A href="https://community.dynatrace.com/t5/Troubleshooting/How-to-check-Synthetic-Monitor-Websocket-errors-in-logs/ta-p/211647" target="_self"&gt;WebSocket errors in the logs&lt;/A&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Confirm that no Antivirus or anti-malware applications are running. If there are, try disabling them and restarting the Dynatrace Synthetic/ VUC service. If this resolves the issue, modify the Antivirus or anti-malware application to allow Chromium and the Synthetic module to run without interference. You can find suggestions for rules &lt;A href="https://docs.dynatrace.com/docs/observe/digital-experience/synthetic-monitoring/private-synthetic-locations/system-and-hardware-requirements-for-private-synthetic#operating-system-requirements" target="_self"&gt;here.&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;If you can't find a cause, open a chat or create a ticket.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;For Managed tenants&lt;/STRONG&gt;&lt;/H4&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;Confirm that the monitor is enabled.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Confirm that there are no maintenance windows during the data gap. This can be confirmed on the browser&lt;A href="https://docs.dynatrace.com/docs/observe/digital-experience/synthetic-monitoring/analysis-and-alerting/synthetic-details-for-browser-monitors#synthetic-details-for-browser-monitors" target="_self"&gt;&amp;nbsp;monitor details page&lt;/A&gt; or the &lt;A href="https://docs.dynatrace.com/docs/observe/digital-experience/synthetic-monitoring/analysis-and-alerting/synthetic-details-for-http-monitors-classic#metric-visualizations" target="_self"&gt;HTTP Monitors details page.&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Confirm that&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.dynatrace.com/managed/managed-cluster/basic-concepts/managed-deployment-scenarios#scenario-4-globally-distributed-high-availability-with-automatic-recovery" target="_blank" rel="nofollow noopener noreferrer"&gt;the Cluster ActiveGate URL is publicly available&lt;/A&gt;. It can be limited to access from&amp;nbsp;public location IP addresses if necessary.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;select the Test connection to URL button under Settings/Public endpoints in the Cluster Management Console.&lt;BR /&gt;This tests four types of public connectivity to the Cluster ActiveGate: Synthetic, internal and external users for RUM, and external OneAgent comms.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;If Synthetic fails, the Cluster ActiveGate is not publicly available, &lt;/STRONG&gt;and you'll need to update your&amp;nbsp;Firewall or Load balancer settings to allow access. You can ignore this if you have limited access to specific IPs.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Confirm that the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.dynatrace.com/t5/Dynatrace-tips/Public-endpoint-for-the-Cluster-ActiveGate/m-p/202652" target="_blank" rel="nofollow noopener noreferrer"&gt;Synthetic endpoints&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;are all open&lt;BR /&gt;beacon/[uuid]&lt;BR /&gt;Synthetic health checks /beacon/synthetic/[uuid]&lt;BR /&gt;HTTP Monitors /beacon/synthetic/httpresults[uuid]&lt;BR /&gt;screenshots /beacon/synthetic/screenshot/[uuid]&lt;BR /&gt;Browser Monitors /beacon/synthetic/browser/[uuid]&lt;BR /&gt;Multiprotocol monitors /beacon/synthetic/multi-protocol/[uuid] &lt;BR /&gt;Credentials /beacon/synthetic/credentials/[uuid]&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;Run a health check. This can be run from anywhere if you're not limiting access to specific IPs.&amp;nbsp;
&lt;PRE&gt;https://&amp;lt;Cluster AG Public Url&amp;gt;:&amp;lt;port&amp;gt;/beacon/synthetic/&amp;lt;environment UUID&amp;gt;?healthcheck&amp;amp;tenantId=&amp;lt;environment UUID&amp;gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and the response should be JSON file like this&lt;/P&gt;
&lt;PRE&gt;{"ts":1680601930205,"activeGateId":nnnn,"activeGateVersion":"1.261.166.20230308-123141","activeGateWorkingMode":"MANAGED","tenantAvailable":false,"syntheticLicenseAvailable":false,"rumLicenseAvailable":false,"rumConfigRevision":-1,"imgAvailable":false,"hmResultsAvailable":false,"failureScreenshotInterval":3600000,"clusterVersion":"","clusterUUID":"","jsAgentVersion":"","protoVersion":1,"httpMonitorsResultsPath":"","screenshotsPath":"","mpmResultsAvailable":false,"credentialsPath":""}&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;If you can't find a cause, open a chat or create a ticket.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Solutions&lt;/H2&gt;
&lt;P&gt;Once you've done the checks and determined the root cause of the problem, here are some possible solutions that you can apply&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Allow/ Allowlist by User Agent string&lt;/H3&gt;
&lt;P&gt;Synthetic Monitors can be recognised by the User Agent string they add in the request headers. This string can be used in Firewalls, etc., to identify Synthetic traffic and allow it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For Browser monitors, we add&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;RuxitSynthetic/1.0&lt;/PRE&gt;
&lt;P&gt;and some extra parameters after that. You can find the full list &lt;A href="https://docs.dynatrace.com/docs/observe/digital-experience/synthetic-monitoring/browser-monitors/configure-browser-monitors#expand--default-user-agent" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;For HTTP Monitors, we add&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;DynatraceSynthetic/{version}&lt;/PRE&gt;
&lt;P&gt;The version changes with each release, so you may wish to use DynatraceSynthetic/instead. The complete list is&lt;SPAN&gt;&amp;nbsp;&lt;A href="https://docs.dynatrace.com/docs/observe/digital-experience/synthetic-monitoring/http-monitors-classic/configure-http-monitors-classic#setup" target="_self"&gt;here&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&amp;nbsp;&lt;/H3&gt;
&lt;H3&gt;Allow/ Allowlist location IPs&lt;/H3&gt;
&lt;P&gt;IPs can be used to identify Synthetic traffic and allow it to pass through Firewalls, etc.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can find the IPs used by our public locations using the Frequency and Locations page in the WebUI or the &lt;A href="https://docs.dynatrace.com/docs/discover-dynatrace/references/dynatrace-api/environment-api/synthetic/synthetic-locations/get-all-locations" target="_self"&gt;Synthetic locations API—GET all locations&amp;nbsp;API call.&amp;nbsp;&lt;/A&gt;Further details are available&amp;nbsp;&lt;A href="https://docs.dynatrace.com/docs/observe/digital-experience/synthetic-monitoring/general-information/public-synthetic-locations#ip-addresses" target="_self"&gt;here.&lt;/A&gt;&amp;nbsp;&lt;SPAN&gt;These are individual IPs, so the subnet mask is&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class="c-mrkdwn__code" data-stringify-type="code"&gt;/32&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;for all of them.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We don't list private location IPs, but you can find them in the WebUI in Deployment Status&amp;gt; ActiveGates. You can then filter for either the location you're interested in or all Synthetic ActiveGates and open each ActiveGate details tile to check the IP addresses.&lt;/P&gt;
&lt;H3&gt;&amp;nbsp;&lt;/H3&gt;
&lt;H3&gt;Add/update Proxy configuration.&lt;/H3&gt;
&lt;P&gt;If you need to connect to your application through a proxy or bypass it, you may need to add some further configuration to your proxy to allow access from the machine/ location.&lt;/P&gt;
&lt;P&gt;If the necessary change has already been made to the proxy, we provide information on setting up ActiveGate to use different proxy connection scenarios &lt;A href="https://docs.dynatrace.com/docs/observe/digital-experience/synthetic-monitoring/private-synthetic-locations/setting-up-proxy-for-private-synthetic" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;In addition to this, if you need only to add the proxy settings for Monitors (both HTTP and Browser) or S3 (screenshot storage), you can&amp;nbsp;add the following flags to ActiveGate Synthetic user.properties file&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;default Linux path:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;/var/lib/dynatrace/synthetic/config/user.properties&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;default Windows path:&amp;nbsp;C:\ProgramData\dynatrace\synthetic\config\&lt;EM&gt;user.properties&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;PRE&gt;com.vuc.proxy.s3.enabled=false
com.vuc.proxy.monitor.enabled=true&lt;/PRE&gt;
&lt;P&gt;The above snippet would enable Monitors to use the proxy settings specified in custom.properties, but S3 would bypass the proxy and use a direct connection.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is no separate setting for Browser and HTTP Monitors; however, &lt;A href="https://docs.dynatrace.com/docs/observe/digital-experience/synthetic-monitoring/private-synthetic-locations/setting-up-proxy-for-private-synthetic#proxy-auto-configuration-pac-files" target="_self"&gt;Browser Monitors can use PAC files&lt;/A&gt;, which can be used to achieve a different proxy for HTTP Monitors and Browser Monitors.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Log in to the Dynatrace Synthetic service as a domain user&lt;/H3&gt;
&lt;P&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt;this is usually needed for applications using Kerberos authentication. Before making this change, it would be good to try using the &lt;A href="https://docs.dynatrace.com/docs/observe/digital-experience/synthetic-monitoring/general-information/synthetic-authentication#http-bm" target="_self"&gt;Kerberos authetication&lt;/A&gt; option.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For applications that need to be opened in a Browser started by a domain user, you can update the user that the Dynatrace Synthetic service logs on as.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;IMPORTANT:&lt;/STRONG&gt; Dynatrace does not support this and must be re-configured every time the ActiveGate is updated. We recommend disabling auto-update for these ActiveGates, and a maintenance window to cover the update period, and re-configuring the log-on user.&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;On the Synthetic ActiveGate, in Services, right-click on Dynatrace Synthetic service&amp;gt; select properties&amp;gt; select Login On tab. &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Change &amp;nbsp;'Local Service' to a domain user, enter the password, and Save. &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Restart the Service.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;To revert to using the Local Service user&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;On the Synthetic ActiveGate, in Services, right-click on Dynatrace Synthetic service&amp;gt; select properties&amp;gt; select Login On tab. &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Change the domain user to 'Local Service' with no password and Save. &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Restart the Service.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;If this doesn't resolve the issue, open a support ticket.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 id="toc-hId-1971787789"&gt;What's Next&lt;/H2&gt;
&lt;P&gt;If none of the previous steps resolved the issue, open a chat or support ticket and provide&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;a description of the problem&lt;/LI&gt;
&lt;LI&gt;a link to the affected monitor&lt;/LI&gt;
&lt;LI&gt;the troubleshooting steps you have already completed and the outcome of each step&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Related reading&lt;/H3&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":open_book:"&gt;📖&lt;/span&gt;&amp;nbsp;&amp;nbsp;&lt;A class="" href="https://community.dynatrace.com/t5/Troubleshooting/Synthetic-Troubleshooting-Map/ta-p/250426" target="_blank" rel="noopener"&gt;Synthetic Troubleshooting Map&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":open_book:"&gt;📖&lt;/span&gt;&amp;nbsp; &lt;A href="https://docs.dynatrace.com/docs/observe/digital-experience/synthetic-monitoring/private-synthetic-locations/setting-up-proxy-for-private-synthetic" target="_self"&gt;Set up a proxy for private synthetic monitoring&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":open_book:"&gt;📖&lt;/span&gt;&amp;nbsp; &lt;A href="https://docs.dynatrace.com/docs/observe/digital-experience/web-applications/initial-setup/firewall-constraints-for-rum" target="_self"&gt;Firewall constraints for RUM&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Aug 2026 16:11:51 GMT</pubDate>
    <dc:creator>HannahM</dc:creator>
    <dc:date>2026-08-19T16:11:51Z</dc:date>
    <item>
      <title>Firewall Constraints and allowlisting for Synthetic Monitoring</title>
      <link>https://community.dynatrace.com/t5/Troubleshooting/Firewall-Constraints-and-allowlisting-for-Synthetic-Monitoring/ta-p/213876</link>
      <description>&lt;P&gt;&lt;LI-TOC indent="15" liststyle="disc" maxheadinglevel="2"&gt;&lt;/LI-TOC&gt;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;*&lt;EM&gt;Use a table of contents for longer articles.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Summary&lt;/H2&gt;
&lt;P&gt;&lt;EM&gt;*This is a mandatory section.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Short description of which part of the Dynatrace platform the article refers to and what kind of problem it will help resolve/ task it will describe.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Problem&lt;/H2&gt;
&lt;P&gt;&lt;EM&gt;*This is a mandatory section.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Provide a precise description of the problem/ task to be described. Use anonymized screenshots, and include text for&amp;nbsp;important messages, errors, or information that will help the customer find this article when searching.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Troubleshooting steps&lt;/H2&gt;
&lt;P&gt;&lt;EM&gt;*This section can be omitted as necessary.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Explain what troubleshooting steps should be taken to ensure the problem matches this article.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Resolution&lt;/H2&gt;
&lt;P&gt;&lt;EM&gt;*This section can be omitted for articles that guide customers on ticket creation.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Explain the solution or all possible solutions resulting from the troubleshooting steps.&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;What's next&lt;/H2&gt;
&lt;P&gt;&lt;EM&gt;*This is a mandatory section. Customers need a way to respond or follow up if they have questions.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Explain what to do if the article did not help.&amp;nbsp;&lt;/EM&gt;&lt;EM&gt;Note that there are multiple options available, including:&lt;/EM&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;EM&gt;&lt;STRONG&gt;Opening a support ticket&lt;/STRONG&gt; - be as specific as possible about the information the customer should include in the ticket.&amp;nbsp;&lt;/EM&gt; If this article did not help, please open a support ticket, mention that this article was used and provide the following in the ticket:
&lt;UL&gt;
&lt;LI&gt;link to XYZ&lt;/LI&gt;
&lt;LI&gt;screenshot of XYZ&lt;/LI&gt;
&lt;LI&gt;information about XYZ&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;&lt;STRONG&gt;Suggesting Product Idea&lt;/STRONG&gt; - encourage the customer to suggest/ vote for a Product Idea explaining their business use case.&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;&lt;STRONG&gt;Explain this will change in the future&lt;/STRONG&gt; - explain that this behaviour will change in a future release. (No product idea / support ticket needed)&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;&lt;STRONG&gt;Alternatives -&lt;/STRONG&gt;&amp;nbsp;any other actions or links to other articles that could move the customer forward.&lt;/EM&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;*If it exists, link this article to the relevant troubleshooting map using the following guideline&lt;/EM&gt;&lt;/P&gt;
&lt;H3&gt;More articles can be found on the &lt;A href="https://community.dynatrace.com/t5/Troubleshooting/" target="_self"&gt;XXX Troubleshooting Map&lt;/A&gt;&lt;/H3&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 19 Aug 2026 16:11:51 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Troubleshooting/Firewall-Constraints-and-allowlisting-for-Synthetic-Monitoring/ta-p/213876</guid>
      <dc:creator>HannahM</dc:creator>
      <dc:date>2026-08-19T16:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Constraints and whitelisting for Synthetic Monitoring</title>
      <link>https://community.dynatrace.com/t5/Troubleshooting/Firewall-Constraints-and-allowlisting-for-Synthetic-Monitoring/tac-p/214503#M248</link>
      <description>&lt;P&gt;great write up, thank you for sharing this!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 18:49:22 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Troubleshooting/Firewall-Constraints-and-allowlisting-for-Synthetic-Monitoring/tac-p/214503#M248</guid>
      <dc:creator>ChadTurner</dc:creator>
      <dc:date>2023-06-08T18:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Constraints and whitelisting for Synthetic Monitoring</title>
      <link>https://community.dynatrace.com/t5/Troubleshooting/Firewall-Constraints-and-allowlisting-for-Synthetic-Monitoring/tac-p/214511#M253</link>
      <description>&lt;P&gt;Terrific Guide!!!! Thks for sharing this.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 19:51:40 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Troubleshooting/Firewall-Constraints-and-allowlisting-for-Synthetic-Monitoring/tac-p/214511#M253</guid>
      <dc:creator>DanielS</dc:creator>
      <dc:date>2023-06-08T19:51:40Z</dc:date>
    </item>
  </channel>
</rss>

