Many clients do not want their accounting workstations to access the internet. Furthermore, the Spire installer should set up any Windows Firewall rules required for proper operation. However, if there is a firewall blocking general Internet access for the Spire server, that firewall needs to be configured so the Spire server can download updates and licensing information properly. Note that Spire desktop/client workstations do not require access to the Internet (they just need to access the Spire server).
Configuring Windows Firewall for Spire server on Internet-limited networks
Note that these steps may vary depending on the server's Windows version.
- Start the Windows "Control Panel" app.
- If the "View by" is set to "Category", click the "System and Security" link.
- Click the "Windows Defender Firewall" link.
- Click on "Advanced Settings" on the left.
- Select "Outbound Rules" and then click the menu item "Action → New Rule".
- Select the "Custom" option and click "Next":
- Select "This program path" and click "Browse" to browse to folder "C:\Program Files (x86)\Spire\Server", then select and open "spiretray.exe":
- Click the "Services → Customize" button, select "Apply to this service", find "Spire API Server" and select it, then click OK:
Click "Next" to advance the setup.
- Set the "Protocol type" to "TCP" and the "Remote port" to "Specific Ports" and 443, then click "Next":
- If you were using a firewall that allows specifying the remote address, you could enter central.spiresytems.com in order to further segregate the rule, but Windows Firewall only allows IP addresses so just click "Next" when you get to the IP-address setup. The settings should be defaulted to "Any IP address" for both local and remote sections.
- Select "Allow the connection" and click "Next".
- It's recommended to select the "Domain" and "Private" network types, so only allow "Public" if you absolutely have to (given the network requires it):
- Click "Next" and give your rule a name, then click "Finish":