Firewall Configuration Guide for Cove’s Move to Mutual TLS
A Disclaimer Before You Begin
This guide is provided for reference to help you get started and is not official documentation from your firewall vendor. Menu names, steps, and settings may vary by firmware version or configuration. Always consult your firewall vendor’s documentation or support team for guidance specific to your environment before making changes.
Stopping the Man in the Middle
Man-in-the-middle (MITM) attacks let an attacker sit between two systems, intercept their traffic, and read or alter it without either side noticing. On an unprotected connection, that means backup traffic — including credentials and business data — could be exposed in transit.
That’s why we’re upgrading the connection between Backup Manager and the N-able cloud from one-way TLS to mutual TLS (mTLS), which adds client-side certificate authentication on top of encryption. Both sides now verify each other’s identity before any data moves, closing the gap MITM attacks rely on and keeping backup traffic genuinely end to end (E2E) encrypted with no proxy able to decrypt and re-encrypt it in the middle.
Preparing for the Move to mTLS
Backup Manager will be moving to mTLS which will validate the full TLS certificate chain on its connections. There is no client-side setting to disable this check, so any firewall or proxy that re-signs TLS (SSL/TLS inspection, DPI-SSL, HTTPS content inspection) will break backups unless the relevant Cove domains are explicitly excluded from that inspection.
Therefore, Cove must be excluded from TLS inspection before November 2nd, 2026. To help you get started, we’ve put together this configuration guide for the most commonly used firewalls.
For every firewall below, the fix is the same in principle: add cloudbackup.management and *.cloudbackup.management to that firewall’s TLS/SSL inspection exclusion or allow list, using domain or SNI matching rather than IP matching.
Quick Reference
Domains to exclude on every firewall that supports domain/SNI-based TLS exceptions:
- cloudbackup.management
- *.cloudbackup.management (covers all storage nodes automatically, e.g. < home-node >.cloudbackup.management and < home-node >-webrcg.cloudbackup.management)
Where to find a device’s home node: The home node name (e.g., us-atl-08-02) is visible in the device’s Backup Manager URL, or on the device’s overview page in the Cove Management Console.
For more information, you can refer to our knowledge base.
1. Cisco® Meraki™ MX
Meraki’s HTTPS Inspection feature (MX OS 26.2+, Advanced Security or SD-WAN+ license) can decrypt and inspect HTTPS traffic, then re-encrypt it. It supports an L7 allow list matching destination hostname with wildcards.
Official documentation:
2. Fortinet® FortiGate®
FortiGate’s SSL/SSH Inspection profile supports exempting destinations by wildcard FQDN, matched against the TLS SNI field — this works independently of DNS resolution.
Official documentation:
- SSL/TLS deep inspection (overview, exemptions)
- Technical Tip: Exempting applications/domains/websites from Deep SSL Inspection
Note: SSL exemption only applies when the policy’s Inspection Method is Full SSL Inspection (deep inspection). If the policy uses certificate inspection only, no exemption is needed.
3. SonicWall® (SonicOS® / DPI-SSL)
SonicWall’s DPI-SSL Client (and Server, if applicable) SSL inspection supports domain-based exclusions via Common Name Exclusions, or via FQDN Address Objects added to the Exclude list.
Official documentation:
WatchGuard® Firebox®
The Firebox’s HTTPS-Proxy action supports Domain Name Rules, which take precedence over the predefined Content Inspection Exceptions list.
Official documentation:
5. Sophos® Firewall (XGS Series)
Sophos Firewall matches TLS exclusions by SNI, which is most efficiently done through a URL group rather than an FQDN host object (FQDN hosts require DNS lookups and are less efficient).
Official documentation:
6. Palo Alto Networks® (PAN-OS®)
PAN-OS matches its SSL Decryption Exclusion list against both the TLS SNI in the Client Hello and the CN/SAN in the server certificate, so the exclusion does not depend on DNS resolution or a fixed IP, and wildcards are supported.
Official documentation:
- Exclude a Server from Decryption for Technical Reasons
- Palo Alto Networks Predefined Decryption Exclusions (overview)
Next Steps
Mutual TLS gives Cove backup traffic stronger protection against interception. To keep backups running without disruption, make sure the exclusion is in place before the deadline. Use the steps above to help configure your specific firewall and reach out to your firewall vendor if you need help beyond what’s covered here. If you run into issues on the Cove side, our support team is ready to help.
© N‑able Solutions ULC e N‑able Technologies Ltd. Todos os direitos reservados.
Este documento é fornecido apenas para fins informativos e não deve servir de base para aconselhamento jurídico. A N‑able não oferece nenhuma garantia, expressa ou implícita, nem assume qualquer responsabilidade legal ou responsabilidade pela precisão, integralidade ou utilidade de qualquer informação nele contido.
As marcas N-ABLE, N-CENTRAL e outras marcas registradas e logotipos N‑able são de propriedade exclusiva da N‑able Solutions ULC e da N‑able Technologies Ltd e podem ser marcas legais comuns, registradas ou de registro pendente com o Escritório de Marcas e Patentes dos EUA e com outros países. Todas as outras marcas comerciais mencionadas neste documento são usadas apenas para fins de identificação e são marcas comerciais (e poderão ser marcas registradas) de suas respectivas empresas.