Joining a Gateway to the Manager
Joining uses two text blocks that travel in opposite directions.
Naming: this article uses the v5.5.4 product names - Gateway (formerly CSG) and Manager (formerly XCM). Appliances on older versions, and their documentation, use the old names for the same things.
Contents
- On the Gateway - Copy the Trust Text
- On the Manager - Add the Gateway and paste the Trust Text
- On the Manager - Confirm the Gateway shows Pending
- On the Manager - Open the pending Gateway and copy the Join Text
- On the Gateway - Open Fabric → Membership
- On the Gateway - Paste the Join Text, then check the FIRST and LAST lines
- On the Gateway - Enter the Manager address
- On the Gateway - Submit, then confirm the Gateway turns Connected
How it fits together. The Gateway sends Trust Text to the Manager; the Manager then sends Join Text back to the Gateway.
Both blocks contain the word
FABRIC. The words that actually tell them apart are TRUST INFO and CONNECTION INFO.
ℹ The example blocks below are fictitious
They are here only to show you the shape - a first line, a base64 body, and a last line. Always copy the real text from your own appliance's web interface. Your blocks will look completely different from these, and different again every time you view them. That is expected and does not mean anything is wrong.
The steps
1. On the Gateway - Copy the Trust Text
Go to Settings → Fabric → Membership. The Gateway's own Trust Text is shown there with a copy button beside it.
✓ Always use the copy button, never select by hand
This applies at every copy step in this article. The button takes the entire block including both dashed wrapper lines; a hand-drag almost always clips the first or last line, and a block missing either one is rejected.
| Trust Text - Gateway to Manager |
|---|
--- FABRIC CLIENT TRUST INFO --- |
These must match exactly: --- FABRIC CLIENT TRUST INFO --- and --- END FABRIC CLIENT TRUST INFO ---
Example only - copy yours from the Gateway's web interface. Do not use the text above.
Before pasting, check what you have: it must start and end with a dashed line. The base64 in the middle on its own is not enough.
2. On the Manager - Add the Gateway and paste the Trust Text
Go to Fabric → Add Gateway. Enter a Name, paste the Trust Text into the Trust Text field, and submit. The name is yours to choose and is how this Gateway will appear in the Manager from now on.
3. On the Manager - Confirm the Gateway shows Pending
The Gateway should now appear in the Fabric list with a status of Pending.
Pending is correct here, not a failure. It means the Manager has accepted the Gateway and is waiting for the Gateway to finish the join from its own side - which is what the remaining steps do.
4. On the Manager - Open the pending Gateway and copy the Join Text
Use Chrome for both tabs if you can - see the browser warning under “If it fails” below. Open the Gateway entry you just created. Its detail page has a Join Text panel with its own copy button - use it, exactly as in step 1. This is the copy that fails most often, and hand-selecting it is the most common reason why.
| Join Text - Manager to Gateway |
|---|
--- FABRIC CLIENT CONNECTION INFO --- |
These must match exactly: --- FABRIC CLIENT CONNECTION INFO --- and --- END FABRIC CLIENT CONNECTION INFO ---
Example only - copy yours from the Manager's web interface. Do not use the text above.
5. On the Gateway - Open Fabric → Membership
Switch to your Gateway browser tab and go to Settings → Fabric → Membership.
6. On the Gateway - Paste the Join Text, then check the FIRST and LAST lines
Paste into the Join Text field, then read both ends back before doing anything else. Checking only the top is not enough - if something truncated the paste, the first line is perfect and the closing line is simply gone, which fails in exactly the same way.
⚠ Scroll to the bottom of the box
The field is taller than it looks and the last line is often out of view. It must read
--- END FABRIC CLIENT CONNECTION INFO ---. If the text just stops mid-way through the base64, the paste was cut short - re-copy with the button and try a different browser.
OK - Correct - continue
--- FABRIC CLIENT CONNECTION INFO ---
NO - Wrong block - back to step 4
--- FABRIC CLIENT TRUST INFO ---
A second quick check: Join Text is noticeably longer than Trust Text - roughly 4 to 5 body lines versus about 3. A short block in this field is almost certainly the wrong one.
7. On the Gateway - Enter the Manager address
Enter the hostname or IP address of the Manager. It must be an address the Gateway itself can reach - not necessarily the one you use from your own desk. It cannot be a loopback address, and it cannot be the Gateway's own address.
8. On the Gateway - Submit, then confirm the Gateway turns Connected
Submit the form, then return to the Manager's Fabric list. The Gateway should move from Pending to Connected. If it stays Pending for more than a minute or two, the text was accepted and the problem is now the network path - see the last section.
If it fails, read the error first
⛔ If the paste keeps being rejected, change browser
Microsoft Edge to Microsoft Edge copy/paste has been seen to fail where the same steps in Google Chrome succeeded immediately - same operator, same appliances, same text. Something between the copy and the paste alters the block, and none of it is visible on screen.
In order of preference:
- Use an up-to-date Google Chrome, with as few browser extensions as possible.
- Do both halves from the same machine and the same browser session, rather than moving the text between desktops.
Enterprise DLP policies and browser extensions pushed by Group Policy can both rewrite clipboard contents, so this may be specific to a particular machine or profile rather than true of that browser everywhere.
The wording tells you which half is wrong, which saves a lot of time.
Invalid structure / invalid format
- What it means: The wrapper lines are wrong, or the wrong block was pasted
- What to do: Stop looking at the base64. Re-copy using the button in step 4 and re-check the first line
Transcription error / invalid content
- What it means: The wrapper was right, the body got altered
- What to do: Re-copy the whole block cleanly. Do not retype any of it
Nothing happens, or the Gateway stays Pending
- What it means: The text was accepted - this is now a network problem
- What to do: See the final section
If the Gateway stays Pending after a successful submit
At that point the text is fine and the two appliances simply cannot talk. The Fabric runs WireGuard over UDP port 39251, from the Gateway to the Manager. Confirm that port is open outbound, and that no firewall between the two is dropping it.
Checklist
- ☐ Trust Text copied from the Gateway and pasted into the Manager
- ☐ Gateway shows Pending on the Manager
- ☐ Join Text copied using the Manager's copy button, not the Gateway's
- ☐ The block in the Gateway's Join Text field begins with
--- FABRIC CLIENT CONNECTION INFO --- - ☐ Manager address entered, and reachable from the Gateway
- ☐ Gateway shows Connected on the Manager