Frequently Asked Questions - Customer Service Support
SiteManager Shows "Registered but Offline" After Firmware Update
Category: Troubleshooting › Remote Access & Connectivity Subcategory: Firmware & Updates Tags: firmware sitemanager offline registered connectivity 9.4.2 bulk-update Audience: OT Administrators, IT Teams, Machine Builders Last updated: July 2025
Overview
After applying a firmware update to one or more SiteManagers — either individually or via the bulk update feature in Secomea Prime — some units may display the status "Registered but Offline" in GateManager. This means the SiteManager has successfully registered with the GateManager server but cannot establish an active remote access tunnel.
This article walks you through the most common causes and the step-by-step resolution process.
💡 If you are running a time-sensitive remote session (e.g. a scheduled machine builder maintenance window), jump to Emergency Workaround first, then return to the full troubleshooting steps.
Symptoms
You may be experiencing this issue if:
- One or more SiteManagers show "Registered" status with a grey or red indicator in GateManager or Secomea Prime, rather than green/online
- The affected SiteManagers were online before the firmware update was applied
- Other SiteManagers on the same network segment remain online after the update
- Remote access sessions to OT endpoints behind the affected SiteManagers cannot be initiated
- Power cycling the unit(s) does not resolve the offline status
Most Common Causes
| Cause | Likelihood | Notes |
|---|---|---|
| Firmware update partially applied — unit rebooted mid-update | High | Common with bulk updates over congested networks |
| Network configuration mismatch post-reboot — DNS or DHCP lease not renewed correctly | High | SiteManager may obtain a new IP that is blocked at switch/VLAN level |
| Certificate refresh required — new firmware version triggers a re-authentication cycle | Medium | Usually self-resolves within 10–15 minutes; if not, manual action needed |
| Firewall rule conflict — outbound port blocked after infrastructure change coinciding with update window | Medium | Check with network team if any changes were made in the same window |
| Hardware fault triggered by update — rare, but firmware updates can surface pre-existing memory or storage issues | Low | Escalate to Secomea Support if all other steps fail |
Step-by-Step Resolution
Step 1 — Confirm the firmware update completed successfully
- Log in to Secomea Prime → navigate to Appliances
- Locate the affected SiteManager(s) and open each unit's detail view
- Under Firmware Version, confirm whether the update completed:
- If the version shows the new firmware (e.g. 9.4.2) → update completed, proceed to Step 2
- If the version still shows the previous firmware (e.g. 9.4.1) → the update did not apply. Re-trigger the update individually (not via bulk) and monitor the progress bar until complete before rebooting
- Check the Event Log for the affected unit — look for entries such as
Firmware update started,Firmware update failed, orDevice rebooting
Step 2 — Force a network lease renewal
SiteManagers obtain their IP address via DHCP by default. After a reboot triggered by a firmware update, the unit may not renew its lease correctly, particularly if the reboot was rapid or if DHCP lease time is long.
At the physical unit:
- Locate the SiteManager in the network cabinet
- Disconnect the LAN cable for 10 seconds, then reconnect
- Wait 60–90 seconds for the unit to re-register
- Check Secomea Prime — the status should update to Online within 2 minutes
If the unit is inaccessible physically, proceed to Step 3.
Step 3 — Check outbound connectivity from the SiteManager's network segment
Secomea SiteManagers connect outbound only — no inbound firewall ports are required. However, the following outbound connections must be permitted from the SiteManager's network segment:
| Destination | Port | Protocol | Purpose |
|---|---|---|---|
*.secomea.com |
443 | TCP/HTTPS | GateManager cloud communication |
*.secomea.com |
11444 | TCP | Tunnel establishment |
| DNS server | 53 | UDP/TCP | Domain resolution |
To verify:
- Check with your network team whether any firewall rules, ACLs, or VLAN policies were changed in the same maintenance window as the firmware update
-
If possible, run a connectivity test from a device on the same network segment:
javascript
curl -I https://gm-eu3.secomea.com
A response of
HTTP 200orHTTP 302confirms outbound HTTPS connectivity is working - If port 11444 is blocked, the SiteManager will appear "Registered" (HTTPS handshake succeeded) but "Offline" (tunnel cannot be established) — this is the most common cause of this exact status combination
Step 4 — Clear the GateManager device entry and re-register
If Steps 1–3 do not resolve the issue, the device entry in GateManager may need to be refreshed.
⚠️ Warning: Deleting a device entry will remove its configuration from GateManager. Before proceeding, export the device configuration or note the endpoints/credentials configured. Contact Secomea Support if you are unsure.
- In GateManager, navigate to the affected SiteManager
- Select Actions → Delete device entry
- On the physical SiteManager unit, press and hold the Reset button for 3 seconds (short reset — this does NOT factory reset the unit; it forces a fresh GateManager registration)
- Wait 2–3 minutes for the unit to re-register
- Reconfigure any endpoints if required
Step 5 — Roll back the firmware (if issue persists)
If the affected units remain offline after Steps 1–4, rolling back to the previous firmware version is the fastest path to restoring remote access.
- In Secomea Prime → Appliances, select the affected SiteManager(s)
- Click Firmware → Install specific version
- Select the previous stable version (e.g. 9.4.1)
- Apply the update and monitor until complete
💡 Once units are back online, contact Secomea Support before re-applying 9.4.2 on the affected units. Our team can review the event logs to identify the root cause before the next update attempt.
Emergency Workaround
If you have a scheduled remote maintenance session that cannot be delayed (e.g. a machine builder visiting remotely):
- Contact Secomea Support immediately at +45 48 88 16 75 (premium/emergency line) — reference your account number and the scheduled session time
- As a temporary measure, ask your machine builder to connect via an alternative access method (e.g. direct VPN to your corporate network, if permitted by your IT policy) while the SiteManager issue is resolved
- If on-site access is required, Secomea Support can issue a temporary local access code to allow the machine builder's engineer to access the PLC directly without the SiteManager tunnel — ask the support agent for this option
How to Export GateManager Event Logs (for Support Escalation)
If you need to escalate to Secomea Support, exporting the event log speeds up diagnosis significantly.
- Log in to GateManager
- Select the affected SiteManager → Logs → Event Log
- Set the time range to cover the last 72–96 hours (to capture the pre- and post-update window)
- Click Export → CSV
- Attach the file to your support ticket
When to Contact Secomea Support
Escalate to support if:
- The unit remains "Registered but Offline" after completing all steps above
- More than 25% of SiteManagers in a bulk update are affected
- You suspect a hardware fault (unit is warm to touch, indicator LEDs behaving abnormally)
- You need assistance rolling back firmware on a large fleet
Article 2
Understanding SiteManager Status Indicators in Secomea Prime and GateManager
Category: Troubleshooting › Remote Access & Connectivity Subcategory: Status & Monitoring Tags: sitemanager status online offline registered gatemanager prime monitoring Audience: OT Administrators, IT Teams, Machine Builders, Support Agents Last updated: July 2025
Overview
Secomea Prime and GateManager display real-time status information for every SiteManager in your deployment. Understanding what each status means is essential for diagnosing connectivity issues quickly — especially in distributed environments with SiteManagers across multiple sites or facilities.
SiteManager Status Reference Table
| Status | Colour | What it means | Typical cause | Action required? |
|---|---|---|---|---|
| Online | 🟢 Green | SiteManager is connected to GateManager and remote access tunnels can be established | Normal operation | None |
| Registered but Offline | 🔵 Blue / ⚪ Grey | SiteManager has checked in with GateManager (registration layer) but the remote access tunnel is not active | Network issue, firmware update, port blocked, post-reboot delay | ✅ Yes — see Article 1 |
| Offline | 🔴 Red | SiteManager has not communicated with GateManager within the expected interval | Power loss, network outage, hardware failure, internet down at site | ✅ Yes — investigate site connectivity |
| Never Connected | ⚫ Black / No indicator | Device is registered in GateManager but has never successfully established a connection | New device not yet powered on, incorrect server address configured | ✅ Yes — complete initial configuration |
| Firmware Update in Progress | 🔄 Animated | Firmware is currently being applied | Triggered by admin via Prime or GateManager | ⏳ Wait — do not power cycle |
| Maintenance Mode | 🔧 Spanner icon | Administrator has placed the unit in maintenance mode | Deliberate configuration change | Depends on intent |
The Difference Between "Registered" and "Online"
This distinction is important and frequently misunderstood:
Registered means the SiteManager has successfully reached the GateManager server on port 443 (HTTPS) and confirmed its identity. This is the first layer of communication and requires only standard outbound HTTPS access.
Online (active tunnel) means the SiteManager has also established the secure remote access tunnel on port 11444 (TCP). This second layer is what allows remote sessions to OT endpoints behind the SiteManager.
A device can be Registered but Offline if HTTPS traffic is permitted but port 11444 is blocked — for example, by a firewall rule or network policy that changed without the OT team's knowledge.
Diagnostic shortcut: If all affected units are "Registered but Offline" after a specific network event (firmware update, VLAN change, firewall rule update), port 11444 is the first thing to check.
Checking Status in Secomea Prime
- Log in to Secomea Prime
- Navigate to Appliances in the left-hand menu
- The Status column shows the current state of each SiteManager with colour coding as above
- Click any unit to open the detail view — this shows:
- Last seen timestamp
- Current firmware version
- Connected endpoints
- Recent event log entries
- Use Filters to isolate offline or problematic units across large deployments
Setting Up Status Alerts
You can configure Secomea Prime to notify you automatically when a SiteManager goes offline:
- Navigate to Settings → Notifications
- Select SiteManager Offline Alert
- Choose your notification method: email, webhook, or third-party integration
- Set a grace period (e.g. 5 minutes) to avoid alerts for brief connectivity blips
- Assign the alert to specific SiteManagers or to all units in your account
💡 For premium customers with on-call escalation, Secomea supports webhook-based alerting that can connect to tools such as OpsGenie or AlertOps for immediate on-call notification.
Article 3
GateManager License Cap Reached — What It Means and How to Resolve It
Category: Account & Subscriptions › License Management Subcategory: License Limits & Upgrades Tags: license cap sitemanager gatemanager subscription upgrade partner rollout registration-blocked Audience: Account Administrators, Partner Account Managers, IT Managers Last updated: July 2025
Overview
If you see the error message "Maximum active SiteManagers reached for this subscription" when attempting to register a new SiteManager in GateManager or Secomea Prime, your account has reached the SiteManager limit included in your current subscription tier.
This article explains what this means, how to verify your current license status, and how to resolve the issue — including requesting a temporary extension when a site rollout cannot be delayed.
Understanding SiteManager License Limits
Every Secomea subscription includes a defined number of active SiteManagers — the hardware or virtual gateway units deployed at your sites. When this limit is reached, new SiteManagers cannot register until either:
- An existing SiteManager is deactivated, or
- Your subscription is upgraded to a higher limit
Your subscription limit is visible at any time inside Secomea Prime → Settings → Subscription Overview.
Step 1 — Check Your Current License Status
- Log in to Secomea Prime
- Click your profile icon (top right) → Settings → Subscription Overview
- You will see:
- Active SiteManagers: the number currently consuming your license
- Subscription limit: the maximum included in your plan
- Active EndPoints: connected OT devices
- Concurrent licenses: simultaneous remote access sessions permitted
💡 If the numbers do not match what you expect — for example, if you purchased a license upgrade but your limit has not changed — your upgrade may not have been applied to your Prime account. See Step 3 below.
Step 2 — Free Up License Capacity (If Applicable)
If you have SiteManagers that are decommissioned, replaced, or no longer in use, removing them from GateManager will free up license slots immediately.
- In GateManager, locate the SiteManager to be removed
- Confirm it is genuinely inactive (status: Offline for an extended period with no planned use)
- Select the unit → Actions → Delete device entry
- The license slot is released immediately and the next SiteManager registration will succeed
⚠️ Deleting a device entry is permanent — the unit's configuration, endpoint list, and access logs will be removed from GateManager. Export any audit logs you need to retain before proceeding.
Step 3 — Verify Whether a Recent Upgrade Was Applied {#step-3}
If you or your partner recently purchased a subscription upgrade (for example, from 22 to 30 SiteManagers) and your limit still reflects the old number, the upgrade may not have been provisioned to your GateManager/Prime account.
To verify:
- Check your order confirmation or distributor invoice for the upgrade PO reference number
- Log in to Secomea Prime → Settings → Subscription Overview — confirm whether the limit reflects the upgraded number
- If the limit has not changed:
- Contact Secomea Support with your PO reference number and order date
- Support will verify the order against the distributor portal and manually apply the license upgrade to your account
- This is typically resolved within 4 business hours during CET business hours
💡 Partners submitting on behalf of customers: If you processed an upgrade via the distributor portal on behalf of an end customer, include both the partner ID and the end customer's GateManager ID (e.g. GM-NO-0038) in your support ticket. This allows the support team to locate the order and apply the upgrade to the correct account without delay.
Step 4 — Request a Temporary License Extension
If you have confirmed that an upgrade was ordered but not yet applied, and you have a site installation scheduled within the next 48–72 hours that cannot be delayed, you can request a temporary license extension.
What this means:
- Secomea Support can provisionally raise your SiteManager limit to cover the planned installations
- The temporary extension is valid for 5 business days
- The permanent upgrade is applied in parallel once the order is confirmed
- There is no additional charge for the temporary extension period
How to request it:
Submit a support ticket (or call during business hours) with the following information:
| Field | What to include |
|---|---|
| Subject | "Temporary license extension request — [Company name]" |
| Account / GateManager ID | Your GateManager account identifier |
| Current limit | e.g. "Currently capped at 22 SiteManagers" |
| Units needed immediately | e.g. "Need 4 additional slots for Tromsø and Bergen installations" |
| Installation dates | Specific dates and sites |
| Order reference | PO number and order date for the upgrade you purchased |
| Partner ID (if applicable) | Your Secomea partner ID |
Step 5 — Upgrade Your Subscription Permanently
If you need to increase your SiteManager limit on an ongoing basis:
Direct customers:
- Log in to Secomea Prime → Settings → Subscription Overview → Upgrade plan
- Select the new SiteManager count tier
- Follow the checkout process — the new limit is applied immediately upon payment confirmation
Customers purchasing via a partner or distributor:
- Contact your Secomea partner or distributor to process the upgrade order
- Provide them with your GateManager account ID to ensure the upgrade is applied to the correct account
- Ask them to send you the PO confirmation for your records — this is important if a provisioning delay occurs (see Step 3)
💡 Planning ahead: If you are mid-rollout across multiple sites, consider upgrading to a limit 20–25% above your current planned deployment to avoid hitting the cap as sites come online in parallel.
Giving End Customers Visibility Into Their License Status
If you are a partner managing a Secomea account on behalf of an end customer, your end customer can be given read-only access to their own Subscription Overview inside Secomea Prime without requiring full administrative access.
To set this up:
- In Secomea Prime → Account Management, invite the end customer's IT contact as a User with the role Account Viewer
- This role allows them to see subscription status, active SiteManagers, and usage — but not to make configuration changes
- They will receive an email invitation and can log in with their own credentials
This reduces the need for end customers to contact the partner every time they want to check their license headroom.
Article 4
How Partners Can Submit Support Tickets on Behalf of End Customers
Category: Partners & Distributors › Partner Support Workflow Subcategory: Ticket Submission & Communication Tags: partner distributor ticket behalf end-customer CC communication portal workflow Audience: Secomea Partner Account Managers, Distributor Support Teams Last updated: July 2025
Overview
As a Secomea partner or distributor, you often act as the first point of contact for your end customers' support needs. This article explains the correct process for submitting support tickets on behalf of end customers, how to ensure your end customer is included on all communications, and how to escalate directly to Secomea Support when needed.
When to Submit a Ticket on Behalf of an End Customer
Submit a ticket on behalf of your end customer when:
- The end customer does not have a direct Secomea support relationship or login
- The issue requires Secomea's involvement but the customer cannot contact Secomea directly (e.g. language barrier, time zone, or contractual model)
- You are managing the customer's Secomea account under a managed services agreement
- The issue involves a licensing or billing discrepancy that was originated through your distributor order
Article 4
Secomea Network and Firewall Requirements for SiteManager Connectivity
Category: Installation & Configuration › Network Requirements Subcategory: Firewall & Security Tags: firewall network port 11444 443 outbound connectivity IT sitemanager requirements Audience: IT Administrators, Network Engineers, OT Teams Last updated: July 2025
Overview
Secomea SiteManagers use an outbound-only connection model — meaning no inbound ports need to be opened on your firewall for remote access to work. This is a core security principle of the Secomea architecture and one of the key reasons it is straightforward to deploy in industrial environments without modifying inbound firewall rules.
However, specific outbound connections must be permitted from the SiteManager's network segment to the Secomea cloud infrastructure. This article provides everything your IT or network team needs to configure firewall rules correctly.
How the Secomea Connection Works
scss
SiteManager (OT network)
│
│ Outbound TCP 443 (HTTPS) — Registration & control
│ Outbound TCP 11444 — Secure remote access tunnel
▼
Secomea GateManager (Cloud)
│
▼
Remote user (Secomea Prime)
- The SiteManager initiates an outbound HTTPS connection (port 443) to register with GateManager and confirm its identity
- The SiteManager then establishes an outbound encrypted tunnel (port 11444) which is used for all remote access sessions
- Remote users connect to Secomea Prime (cloud) — they never connect directly to your network; all traffic flows through the GateManager as an intermediary
💡 This is why "Registered but Offline" is such a specific symptom — the device has successfully established the HTTPS connection (port 443 is open) but cannot establish the tunnel (port 11444 is blocked or filtered).
Required Outbound Firewall Rules
The following outbound rules must be permitted from the SiteManager's network segment (e.g. OT VLAN, machine network):
| Destination | Port | Protocol | Direction | Purpose |
|---|---|---|---|---|
*.secomea.com |
443 | TCP | Outbound | GateManager registration, control channel, Prime web access |
*.secomea.com |
11444 | TCP | Outbound | Secure remote access tunnel (critical) |
| DNS server (internal or external) | 53 | UDP + TCP | Outbound | Domain name resolution for *.secomea.com
|
| NTP server | 123 | UDP | Outbound | Time synchronisation (required for certificate validation) |
⚠️ Port 11444 is the most commonly missed rule. If you are seeing "Registered but Offline" status, verify this port is permitted before investigating hardware or firmware issues.
No inbound rules are required. Do not open any inbound ports for Secomea functionality.
GateManager Server Addresses by Region
If your firewall policy requires explicit IP or hostname allowlisting rather than wildcard *.secomea.com, use the following:
| Region | GateManager Hostname | Use when |
|---|---|---|
| EU (Primary) | gm-eu3.secomea.com |
Default for European deployments |
| EU (Secondary) | gm-eu4.secomea.com |
Failover / alternative EU server |
| US | gm-us1.secomea.com |
North American deployments |
| APAC | gm-ap1.secomea.com |
Asia-Pacific deployments |
💡 Your specific GateManager hostname is visible in Secomea Prime → Settings → Account → GateManager server. Always check here first rather than assuming the region.
Verifying Connectivity from the SiteManager's Network Segment
To confirm that the required ports are open from the SiteManager's network segment, run the following tests from any device on the same VLAN or subnet as the SiteManager:
Test HTTPS connectivity (port 443):
bash
curl -I https://gm-eu3.secomea.com # Expected: HTTP/1.1 200 OK or HTTP/1.1 302 Found
Test tunnel port (port 11444):
bash
# Windows (PowerShell) Test-NetConnection -ComputerName gm-eu3.secomea.com -Port 11444 # Linux / macOS nc -zv gm-eu3.secomea.com 11444 # Expected: Connection to gm-eu3.secomea.com port 11444 [tcp] succeeded
Test DNS resolution:
bash
nslookup gm-eu3.secomea.com # Expected: Returns a valid IP address
If any of these tests fail, share the results with your network team and reference this article to confirm the required rules.
Common Scenarios Where Connectivity Breaks
| Scenario | What changes | What gets blocked | Resolution |
|---|---|---|---|
| Firewall rule update during maintenance window | New ACL rule inadvertently blocks outbound non-standard ports | Port 11444 | Add explicit permit rule for TCP 11444 outbound to *.secomea.com
|
| VLAN segmentation project | SiteManager moved to a more restricted OT VLAN | Both 443 and 11444 to external destinations | Add outbound permit rules to new VLAN's ACL |
| Firmware update reboot | SiteManager obtains new DHCP IP after reboot | May fall outside existing IP-based ACL | Update ACL to use subnet range, not individual IP |
| Proxy server enforcement | IT enforces all HTTP/HTTPS through a proxy | Port 11444 (non-standard, bypasses proxy) | Add proxy exception for *.secomea.com or permit direct routing for port 11444 |
| DNS change | Internal DNS server changed, old entries cached |
*.secomea.com resolution fails silently |
Flush DNS cache on SiteManager; verify DNS server is reachable on UDP/TCP 53 |
Sharing This Article With Your IT or Network Team
If you need to share firewall requirements with your IT or network team who may not be familiar with Secomea, you can share a direct link to this article or download the Secomea Network Requirements Summary PDF from our documentation library:
📄 Download: Secomea Firewall & Network Requirements (PDF)
This document is formatted for IT/security teams and includes a one-page summary suitable for firewall change request forms.