- No inbound firewall rule is required for the internal web app.
- The connector reaches only the internal apps you publish through BusinessProxy.
- External users see the public app address, not internal DNS names or private IP addresses.
- If the connector or app path is unavailable, access closes instead of falling back to a wider network route.
Connector Guided onboarding
Connect internal web apps without opening inbound ports
Run a small outbound connector near the internal web app. It connects to BusinessProxy over TLS and relays approved app sessions back to the app, so external users never receive a route into your private network.
App Gateway is enabled with guided onboarding. We review the target app, connector reachability, public app address behavior, diagnostics and revoke flow before turning on regular access.
Value
Why security teams use an outbound connector
Access model
Connector path in plain terms
The connector runs where it can reach the internal app and opens an outbound connection to BusinessProxy. A user starts from the portal, receives an approved app session and opens the public app address. BusinessProxy checks the session and relays only that app traffic through the connector.
Administration
What administrators control
- Which workspace connector is assigned to each published app.
- Which users or groups can launch each app session.
- How long app sessions live and when active sessions are revoked.
- Whether the app path is ready before regular access is enabled.
Connector family
Webhook Connector receives machine events into private services
The main connector opens controlled browser sessions to internal web apps. Webhook Connector is separate: it receives public service events, checks the receiving address and secret, then forwards each accepted event to one fixed private upstream through an outbound connection.
Docs
Operational setup belongs in the docs
Account-specific packages, installation commands, health checks, diagnostics and credential maintenance are administrator tasks covered in the connector documentation. The connector keeps internal apps reachable through BusinessProxy without opening inbound firewall ports.