thumb_up
thumb_down
link
Copy link
Copied
insert_emoticon
lmatfy
Copied

System requirements for the new sign-on method

Study the system requirements. The system requirements apply to both two-factor authentication and single sign-on unless specified otherwise.

Contents

Computer/workstation user

Component

Explanation

Control system

Browsers

  • Microsoft Edge
  • Microsoft Internet Explorer 11
  • Google Chrome
  • Safari (Apple Mac)
  • Mozilla Firefox

If you use Chrome, Safari or FireFox, you must configure the browser in such a way that this is automatically updated to the last version.

You must add the URLs below to the Trusted Sites in relation to Internet Explorer. If you do not, the 'The current website is trying to open a site in your Trusted sites list' message may be displayed. This is how you open the Trusted Sites.

  • https://*.afasonline.com
  • https://*.afas.online
  • https://*.afasinsite.nl

Also see:

Citrix Receiver

See also: Frequently asked questions about Citrix Receiver

TLS

  • TLS 1.2 must have been enabled. TLS (Transport Layer Security) is an encryption protocol for the authentication and security of data that are sent through the Internet.

    You can test whether your computer/workstation works for outgoing traffic to AFAS Online by opening the login.afasonline.com site. This site requires TLS1.2.

PCC

AFAS only recommends and supports LTSR (Long Term Service Release) version of Citrix Receiver. The LTSR version is a stable release of Citrix that has new versions less often. The best support can be given on this version. AFAS offers limited support on other versions, amongst others, because it may involve new products that have not been sufficiently tested.

You can use a newer version, for example, because of the support of High DPI or other services for which Citrix Receiver or the Workspace app is required. Citrix Workspace and Citrix Receiver version 4.10 and higher offer settings for the better handling of high DPI, 4k screens and scaling.

For more information about the release policy of Citrix and the made choice, see the Life Cycle Milestones for Citrix Receiver page. Since TLS 1.2 is required, Citrix Receiver versions that are lower than 4.2.100 for Windows and 12.0 for Mac will, in any case, not work.

The Citrix Windows Apps from the Microsoft Store are really not recommended by AFAS.

Network and data traffic

Component

Explanation

IP range

  • 185.46.182.0/24 (therefore 185.46.182.0 to 185.46.182.255)

Outgoing traffic

  • Outgoing traffic clients by means of port 443 (HTTPS). Usually, you do not have to open anything for this unless you work with a whitelist on the firewall or with a proxy.
  • We support TLS1.0, TLS1.1 and TLS1.2 where possible for outgoing traffic.
  • Outgoing traffic operates on the basis of whitelisting. AFAS Online will prepare as best as possible all outgoing communication from your environment. A personal communication profile will, in a very few cases, not work immediately. If this is the case, submit an incident to have the address released.

Incoming traffic

Certificates originate from QuoVadis/WiseKey.

See also:

  • Profit Connectors linked to the new sign-on method

Other

  • Users can sign on via AFAS Pocket with regard to two-factor authorisation (on supported iPhones or Android devices). The first step is to sign on using a username + password and the second step is to confirm via AFAS Pocket on the user's smartphone. If you only use AFAS Pocket for this authentication, you do not need to configure (the app connector of) Pocket.

    A user can link AFAS Pocket for two-factor authorisation to multiple AFAS Online accounts.

    Note:

    AFAS Pocket offers a lot more functionality and especially with regard to Employee Self Service. If you use this solution, you must, however, execute the configuration in Profit. In this situation, AFAS Pocket is linked to one specific environment for the full use of the Pocket functionality and to one or more AFAS Online accounts for two-factor authorisation.

  • Preventing the jacking of parts of your own InSite/OutSite on an external site (anti-click jacking) is on by default. If this needs to be disabled, please submit an incident ticket. You can, however, include a linked to an InSite/OutSite page on an external site.

    You can continue to show an external page on your own site with an integration page.

  • Changing the URLs of the test and accept sites into 12345.insitetest.afas.online and 12345.insiteaccept.afas.online. The URLs of the live InSite and OutSite are not changing.
  • If you carry out an analysis from AFAS Online, you cannot call web services through the analyses. This is, however, possible if you carry out an analysis through the command line of the PCC.

IP addresses, URLs and ciphers

This information is intended for organisations that use a whitelist on the firewall or a proxy.

Note:

In the weekend of August 7, 8 en 9, 2020 the IP-addresses of connectors (SOAP and REST) have changed. This change took place to improve the contunuity of the connector platform. This change also applies to the PCC.

If you use white listing on specific IP-addresses, it is important to chech of the new IP-asdresses are allowed. For this, contact your system administrator. If you don't use white listing, or if you've whitelisted our IP-range (185.46.182.0/24), than this change will have NOimpact.

Please view the new IP-addresses in the tables below. For production and test, the current IP-address will be changed to a range. This means the IP-address may change to another IP-adres in the same range.

PCC

Applications

Explanation

Host name

Public IP

Ports

TLS version

TLS Ciphers [1]

Certificate

InSite, PCC

PCC Notification hub. This must be available to all users who use the PCC.

pc**.notificationhub.afas.online

185.46.182.28

443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

Connector, PCC

SOAP API for production environments. This must be available for all connections/connectors and PCC users.

[participant].soap.afas.online

185.46.182.140 thru 185.46.182.179.

443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

Connector, PCC

SOAP API for test environments. This must be available for all connections/connectors and PCC users who link up to test environments.

[participant].soaptest.afas.online

185.46.182.180 thru 185.46.182.199.

443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

Connector, PCC

SOAP API for accept environments. This must be available for all connections/connectors and PCC users who link up to accept environments.

[participant].soapaccept.afas.online

185.46.182.45

443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

Connector, PCC

REST API for production environments. This must be available for all connections/connectors and PCC users.

[participant].rest.afas.online

185.46.182.140 thru 185.46.182.179.

443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

Connector, PCC

REST API for test environments. This must be available for all connections/connectors and PCC users who link up to test environments.

[participant].resttest.afas.online

185.46.182.180 thru 185.46.182.199.

443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

Connector, PCC

REST API for accept environments. This must be available for all connections/connectors and PCC users who link up to accept environments.

[participant].restaccept.afas.online

185.46.182.44

443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

InSite

InSite. Must be available to all InSite users.

[participant].afasinsite.nl

185.46.182.60

80 (redirect), 443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

InSite

InSite test sites. Must be available to all InSite users who must be able to sign on to InSite sites of test environments.

[participant].insitetest.afas.online

185.46.182.90

80 (redirect), 443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

InSite

InSite accept sites. Must be available to all InSite users who must be able to sign on to InSite sites of accept environments.

[participant].insiteaccept.afas.online

185.46.182.95

80 (redirect), 443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

Sing-on portal (InSite + Profit)

Applications

Explanation

Host name

Public IP

Ports

TLS version

TLS Ciphers [1]

Certificate

InSite, Profit

Multifactor authentication. Your device will make a connection with this address from AFAS Pocket to approve/reject the authentication.

auth.afasonline.com

185.46.182.10

443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

InSite, Profit

Login Portal. All users sign on here through the browser.

login.afasonline.com

185.46.182.11

80 (redirect), 443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

InSite, Profit

Secure Token Service. This must be available to all users. If using federation (SSO), this address must also be accessible for the federation server (for example, ADFS) on site. Outgoing oAuth/OpenID Connect connections may not occur from this IP address.

sts.afasonline.com

185.46.182.12

443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

InSite, Profit

Identity Provider. This must be available to all users to ensure they can sign on to the portal.

idp.afasonline.com

185.46.182.13

443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

Profit Windows

Citrix Netscaler. The Citrix Client makes a connection using this address (portal.afasonline.com - CNAME: portal.gslb.afasonline.com). Must be available for Profit Windows users.

portal.afasonline.com

185.46.182.121

443

1.2

[0xC0,0x27],[0xC0,0x28],[0xC0,0x30],[0xC0,0x2F]

QuoVadis RSA

Profit Windows

Citrix Netscaler. The Citrix Client makes a connection using this address (portal.afasonline.com - CNAME: portal.gslb.afasonline.com). Must be available for Profit Windows users.

portal.afasonline.com

185.46.182.122

443

1.2

[0xC0,0x27],[0xC0,0x28],[0xC0,0x30],[0xC0,0x2F]

QuoVadis RSA

Bank link

Bank Integration Portal. Required to change banking links. Redirect from the bank website.

bis.afas.online

185.46.182.37

443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

Additional for InSite

Applications

Explanation

Host name

Public IP

Ports

TLS version

TLS Ciphers [1]

Certificate

InSite

InSite. Must be available to all InSite users.

[participant].afasinsite.nl

185.46.182.60

80 (redirect), 443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

InSite

InSite test sites. Must be available to all InSite users who must be able to sign on to InSite sites of test environments.

[participant].insitetest.afas.online

185.46.182.90

80 (redirect), 443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

InSite

InSite accept sites. Must be available to all InSite users who must be able to sign on to InSite sites of accept environments.

[participant].insiteaccept.afas.online

185.46.182.95

80 (redirect), 443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

InSite

Profit BI Dashboards. This must be available to every InSite user who wants to view Dashboards.

pc**.bi.afas.online

185.46.182.35

443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

InSite

Analytics for AFAS InSite. This must be available to every InSite user for diagnostic purposes.

statistics.afas.online

185.46.182.26

443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

Connectors

Applications

Explanation

Host name

Public IP

Ports

TLS version

TLS Ciphers [1]

Certificate

Connector, PCC

SOAP API for production environments. This must be available for all connections/connectors and PCC users.

[participant].soap.afas.online

185.46.182.140 thru 185.46.182.179.

443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

Connector, PCC

SOAP API for test environments. This must be available for all connections/connectors and PCC users who link up to test environments.

[participant].soaptest.afas.online

185.46.182.180 thru 185.46.182.199.

443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

Connector, PCC

SOAP API for accept environments. This must be available for all connections/connectors and PCC users who link up to accept environments.

[participant].soapaccept.afas.online

185.46.182.45

443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

Connector, PCC

REST API for production environments. This must be available for all connections/connectors and PCC users.

[participant].rest.afas.online

185.46.182.140 thru 185.46.182.179.

443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

Connector, PCC

REST API for test environments. This must be available for all connections/connectors and PCC users who link up to test environments.

[participant].resttest.afas.online

185.46.182.180 thru 185.46.182.199.

443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

Connector, PCC

REST API for accept environments. This must be available for all connections/connectors and PCC users who link up to accept environments.

[participant].restaccept.afas.online

185.46.182.44

443

1.2

[0xC0,0x2B],[0xC0,0x2C]

QuoVadis ECC

Email

Applications

Explanation

Host name

Public IP

Ports

TLS version

TLS Ciphers [1]

Certificate

Variable

Default outgoing AFAS Online IP address. Any communication profiles and/or connections to your personal email servers come from this address.

proxy.afas.online

185.46.182.1

Variable

1.0, 1.1, 1.2

Variable

N/A

Variable

Email MTA. Used to send outgoing email when the AFAS.ONLINE email server is used. SPF: afas.online

mail.afas.online

185.46.182.200

25

1.0, 1.1, 1.2

Variable

N/A

Variable

Email MTA. Used to send outgoing email when the AFAS.ONLINE email server is used. SPF: afas.online

mta1.afas.online

185.46.182.201

25

1.0, 1.1, 1.2

Variable

N/A

Variable

Email MTA. Used to send outgoing email when the AFAS.ONLINE email server is used. SPF: afas.online

mta2.afas.online

185.46.182.202

25

1.0, 1.1, 1.2

Variable

N/A

Variable

Email MTA. Used to send outgoing email when the AFAS.ONLINE email server is used. SPF: afas.online

mta3.afas.online

185.46.182.203

25

1.0, 1.1, 1.2

Variable

N/A

Variable

Email MTA. Used to send outgoing email when the AFAS.ONLINE email server is used. SPF: afas.online

mta4.afas.online

185.46.182.204

25

1.0, 1.1, 1.2

Variable

N/A

Variable

Email MTA. Used to send outgoing email when the AFAS.ONLINE email server is used. SPF: afas.online

mta5.afas.online

185.46.182.205

25

1.0, 1.1, 1.2

Variable

N/A

Variable

Email MTA. Used to send outgoing email when the AFAS.ONLINE email server is used. SPF: afas.online

mta6.afas.online

185.46.182.206

25

1.0, 1.1, 1.2

Variable

N/A

Variable

Email MTA. Used to send outgoing email when the AFAS.ONLINE email server is used. SPF: afas.online

mta7.afas.online

185.46.182.207

25

1.0, 1.1, 1.2

Variable

N/A

Variable

Email MTA. Used to send outgoing email when the AFAS.ONLINE email server is used. SPF: afas.online

mta8.afas.online

185.46.182.208

25

1.0, 1.1, 1.2

Variable

N/A

Variable

Email MTA. Used to send outgoing email when the AFAS.ONLINE email server is used. SPF: afas.online

mta9.afas.online

185.46.182.209

25

1.0, 1.1, 1.2

Variable

N/A

Directly to

  1. Configuration with regard to the new sign-on
  2. System requirements
  3. Before, during and after the change to two-factor authentication
  4. Before, during and after the change to single sign-on
  5. Citrix Receiver Frequently Asked Questions

Process

Signing on

Work area

app