> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Installing and Registering the Gateway

> Install the Docusnap Enterprise Gateway on a Windows host, sign in and bind it to your subscription – the prerequisite for every scan.

The **Docusnap Enterprise Gateway** consists of two parts: a Windows service that
runs your jobs, and a window through which you set that service up. One setup
installs both in a single pass.

<Note>
  After registration, configuration, log and diagnostics are also available in the
  browser under *Scan › Gateways*. Both interfaces work on the same configuration,
  see [Managing Gateways](/docs/en/scan/gateway).
</Note>

## Getting and running the installer

The setup `DocusnapEnterpriseGatewaySetup.exe` is 64-bit and installs the service
and the window together, machine-wide and with an elevation prompt. You find it
under *Scan › Gateways* through the *Download Gateway* button.

In the setup you decide on the Npcap driver: it is preselected and required for
network scans, but you can deselect it. Missing prerequisites (.NET Framework 4.8,
the Visual C++ redistributables) are installed by the setup along the way.

Afterwards the service *Docusnap Enterprise Gateway* starts automatically with
Windows, and two shortcuts of the same name – in the Start menu and on the desktop
– open the window. The gateway is not yet bound to a subscription.

## Signing in and registering

Before registration, only the *Registration* tab can be used in the window; the
other four tabs are greyed out and are enabled by the registration.

<Steps>
  <Step title="Sign in">
    The gateway opens the sign-in page in your default browser. If the browser
    does not respond within 60 seconds, the sign-in counts as failed.

    | Message | Means |
    | - | - |
    | "Login failed due to timeout." | the 60 seconds have passed without a result |
    | The gateway reports missing rights to the subscriptions of the gateway | your account has no access to a subscription |
  </Step>

  <Step title="Choose subscription and assignment">
    In the *Registration* tab you set *Subscription:*, *Organization:*, *Site:*
    and *Platform:*. The *Display Name:* is required and prefilled with the fully
    qualified computer name.

    <Warning>
      **The *Subscription:* cannot be changed after registration.** Changing it
      requires deregistering and registering again – which deletes all credentials
      stored on the gateway, see
      [Storing Credentials Locally](/docs/en/scan/tutorial-credentials).
    </Warning>
  </Step>

  <Step title="Enter IP ranges">
    Through *IP Range* you define the network ranges this gateway serves – *Start
    IP*, *End IP* and a *Description*. Only IPv4 addresses are accepted.
  </Step>

  <Step title="Register">
    *Register* signs the gateway in to Docusnap365. On success the service
    restarts and the other four tabs become available.
  </Step>
</Steps>

<Tip>
  If there is exactly one subscription and exactly one organization at the first
  sign-in, the gateway registers itself – the tab is skipped, and the *Display Name:*
  stays the computer name.
</Tip>

<Note>
  The *Identifier:*, under which the gateway is listed in Docusnap365, is composed
  of the computer name, the domain name and a machine-specific key from the Windows
  registry. **A cloned system yields the same identifier as its original** as long as
  that key was copied along – relevant for golden images and virtual-machine
  templates.
</Note>

After registration the gateway appears in the browser overview, see
[Managing Gateways](/docs/en/scan/gateway#reading-the-overview).

<Warning>
  **Deregistering deletes all credentials stored on the gateway** – the local files
  and the associated keys in Docusnap365. Jobs are kept. The gateway asks for
  confirmation first.
</Warning>

If only the sign-off from Docusnap365 fails during deregistration, the gateway
deletes its local configuration anyway. It is then deregistered locally but
possibly not in Docusnap365, see
[Deregistering or deleting the gateway](/docs/en/scan/gateway#deregistering-or-deleting-the-gateway).
If the gateway reports that the sign-in to Docusnap365 has expired, sign in again
and repeat the operation.

You save changes to organization, site, platform and the IP ranges through *Save*.
The operation requires a running service with an internet connection and can take
up to half a minute, because the gateway waits until the service has applied the
new configuration.

## Registration status and service

The *General* tab shows three tiles:

| Tile | Shows |
| - | - |
| *Docusnap 365* | *Registered* or *Not Registered* |
| *Service* | *Started*, *Stopped* or *Not Configured*, with the buttons *Start* and *Stop* |
| *Log on as* | the Windows account the service runs under |

<Note>
  *Registered* only means that a connection string is stored – not whether the
  connection is currently up. Whether the gateway is actually reachable is shown
  reliably by the overview in
  [Managing Gateways](/docs/en/scan/gateway#reading-the-overview) in the browser.
</Note>

Through *Log on as* you set the account the service runs under – name and password,
or *Use system account* for `LocalSystem`. Saving stops the service, changes the
account and starts it again; a running job execution is aborted.

The gateway reports separately whether the account was saved and whether the
service started afterwards. "Service account saved, service logon failed (error
1069\): wrong password or missing 'Log on as a service' right." means the account
is set but the service is not running. Check the password and the account's
Windows user right "Log on as a service".

<Warning>
  This account needs full access to the *Storage Directory:* that you set in the
  *Settings* tab – otherwise the scan scripts cannot be updated, see
  [Setting the Storage Directory](/docs/en/scan/gateway-storage-directory). Which rights
  the account needs on the **target systems**, which ports must be open and which
  firewall rules are required, check against your environment.
</Warning>

## Unattended registration

For a rollout to many machines, registration can be started without the
interface: calling it with the switch `-r` and the path to a JSON file supplies
subscription, organization, IP ranges, display name and an access token. The
gateway registers and then exits.

<Warning>
  **No window and no message** appears – not even when the registration fails.
  In that case, check the log.
</Warning>

## Related

Once registered and connected, you continue working with the gateway in the
browser – see [Managing Gateways](/docs/en/scan/gateway). Credentials that must never
leave this network you create in the *Credentials* tab, see
[Storing Credentials Locally](/docs/en/scan/tutorial-credentials). For the first scan
job see [Creating a Scan Job](/docs/en/scan/create-inventory).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.