How do I install a private Security Gateway?

Consider the following requirements before starting Security Gateway installation.

Before you begin

Security Gateway requirements:

  • A machine dedicated to Security Gateway with:
    • 1 GB free disk space
    • 2 GB RAM (4 GB recommended)
    • 1 dual core processor
  • Communications between Dynatrace SaaS installations and monitored environments are sent via HTTPS on port 443. URLs for monitored environments use the form <YourEnvironmentID>
  • Communications between Security Gateway installations and Dynatrace Server are sent via HTTPS on port 8443.
  • Data sent from OneAgent is received via HTTPS on port 9999.

If you're installing OneAgent on a system that runs on VMware, install Security Gateway in a network segment that can easily reach your VMware solution.

On which platforms can Security Gateway be installed?

Note: The Linux operating system has a limit on the number of open files that a process can handle. It's recommended that you set the permitted number of open files to at least 500000 for the root user to ensure proper operation. The current limit can be checked via the ulimit -H -n command. Note that this limit is set on a per-user basis, so if you run Security Gateway with a different user than root, you need to update the relative configuration file accordingly.

Download and run the installer

To install Security Gateway

Select Deploy Dynatrace from the navigation menu.

Click the Start installation button.

Click the Install Dynatrace Security Gateway link.

How you download your installer depends on your setup and needs. You can choose to download an installer directly to the server where you plan to install Security Gateway or you can download an installer to a different machine and then transfer the installer to the server.

On the Download Dynatrace Security Gateway page, click Linux. Downloading the installer for Linux is fairly easy—just copy the wget command line from the Use this command on the target host text box (see below) and paste it into your terminal window. Make sure to copy the command directly from the first text box because it contains your environment ID. Wait for the download to complete. Then verify the signature by copying the command from the Verify signature text box and pasting the command into your terminal window. To start installation, copy the command line from the And run the installer with root rights text box and paste the command into your terminal window.
Make sure your system is up to date, especially SSL and related certificate libraries. If you plan to download Security Gateway directly to the server, note that outdated libraries (for example, CA certificates) or missing OpenSSL will prevent the installer from downloading (we use encrypted connections, so OpenSSL is required to enable wget to access the server).
You can also download the installer by clicking the Download Security Gateway installer link at the bottom of the page and saving the installer script to any location on your system, thereby bypassing the wget command altogether.

You can install Security Gateway on a Linux or Windows machine. Security Gateway needs to send monitoring data to Dynatrace. This is why Security Gateway requires Internet access. Security Gateway listens (i.e., accepts incoming connections) on port 9999 and talks to Dynatrace Server (i.e., makes outgoing connections) on port 443. Ensure that your firewall settings allow communication through these ports.

Linux: Copy the command from the Use this command on the target host text box and paste the command into your terminal. Note that you’ll need root privileges for this. You can use su or sudo to run the installation script. You need to make the script executable before you can run it. To do this, type one of the following commands (where "0" is used in place of the actual version number) in the directory where you downloaded the installation script.

You can add additional parameters to the installation command, to customize your installation. If you want, for example, to install a private Security Gateway as a non-root user, you can use the USER=<user name> parameter as indicated below.

Dynatrace-Security-Gateway-Linux-<version>.sh [USER=<user name>]

The specified user name should already exist in the system (i.e., the Security Gateway installer won't create it). There are no special requirements as to the type of user or group that the user must belong to.

Security Gateway can use an HTTP proxy server address. On Windows, you can enter this address in one of the installer steps. On Linux, you need to use an additional command line parameter, i.e. the PROXY parameter, whose value is the proxy address and port, for example PROXY="".

If you use a proxy that performs SSL termination, add a proxy certificate to the trusted keystore (trusted.jks).
In a standard installation, the keystore file (trusted.jks) is located in the following folders:

  • For Linux: /var/lib/dynatrace/gateway/ssl/customkeys/
  • For Windows: JAVA_HOME\JRE\lib\security\cacert

Execute the following command in either Linux or Windows (depending on your installation):
keytool -importcert -file /path/to/your/SSLcert.cer -keystore trusted.jks

Once Security Gateway connects to Dynatrace Server, installation is complete. That’s all there is to it! As soon as Security Gateway connects to Dynatrace Server, OneAgent is informed and re-configured to send monitoring data through Security Gateway. To check on the status of the installation, click the Show deployment status button and select the Dynatrace Security Gateways tab.

How to start/stop Security Gateway using the command line

You can use the following commands to start/stop Security Gateway.

service dynatracegateway start|stop|forcestop, where dynatracegateway is the init.d script for OneAgent. The difference between stop and forcestop is that the stop command instructs the process to start its shutdown routine, while forcestop forces the process shutdown.

How to update Security Gateway

To update Security Gateway, download the new version and reinstall it. You don´t need to uninstall your current Security Gateway version. Just install the new version over the old one.