Would it be possible to separate the port used for Management UI and the port used for Agent to reach the Hub?
Currently it doesn’t seems to be possible, maybe in a future release?
It would easily increase the security for MSP.
(I’m well aware of the recommendation of whitelisting customer IPs, but preventing the access to the UI at all is better).
If not, maybe with a URL match on a reverse proxy?
Yes it can be done but if the API is accessible then it’s equally as usable for any automated hacking tool (in fact, more so), they will just look at the OpenAPI definition is publishes.
We don’t currently feel it’s appropriate to have the hub/api be accessible on the public internet without restrictions because the hub itself can be quite a powerful tool depending on what it has been configured to do. We may be able to address this in the future.
You’ve got a point.
Still, we see that as a way to reduce the attack surface (protecting against any security flaws in the UI for example), and making it less visible for regular user.
Yes, please create a support ticket by emailing support at certifytheweb.com and we will look at that for you. This community forum is not the main support channel for licensed customers.