Skip to main content

Overview

The N-Central integration enables ThreatAware to collect remote monitoring and management data from your N-Central instance, providing visibility into managed devices and their configuration status.
Connection Method: Direct API Setup Time: 20 minutes Access Required: N-Central Administrator account Network Requirements: Port forwarding and IP whitelisting required

Data collected

The N-Central integration provides:
  • Managed device information
  • Device configuration details
  • System health metrics
  • Remote management status

Use cases

Device Management

Track managed devices across your N-Central infrastructure

Configuration Visibility

Monitor device configurations and compliance status

Health Monitoring

View system health and availability across managed endpoints

Centralized Intelligence

Correlate N-Central data with other security systems

Setup instructions

1

Create Dedicated User Account in N-Central

  • Log in to the N-Central console with administrative credentials
  • Create a new user account specifically for ThreatAware integration
  • Assign the appropriate permissions for API access and device monitoring
  • Note the username and password for this account
2

Configure Firewall Port Forwarding

  • Access your firewall configuration
  • Set up a port forward to the N-Central server
  • Configure the port to match your N-Central API port (typically 8040)
  • Restrict access to the current ThreatAware allowlist IP addresses, available in-product under Settings → Integrations → AWS Account / IP Whitelist Info
Only the specified ThreatAware IPs will be allowed to connect to your N-Central instance through this port forward, ensuring security.
3

Identify N-Central Public IP and Forwarded Port

  • Determine the public IP address of your N-Central server
  • Confirm the forwarded port configured in the firewall
  • Test connectivity to ensure the port is accessible from outside your network
You can test port accessibility using online tools or by accessing the URL from an external network: https://<public-ip>:<forwarded-port>
4

Configure in ThreatAware

Complete the integration setup in ThreatAware:
  • Open ThreatAware and navigate to Settings > Integrations
  • Search for and select N-Central
  • Enter the required information:
    • Public IP Address: The public IP address of your N-Central server
    • Forwarded Port: The port configured in your firewall
    • Username: The dedicated user account created in N-Central
    • Password: The password for the dedicated user account
  • Click Connect to establish the integration
5

Verify Connection

After connecting, verify the integration is working:
  • Check that the Integration Status shows as Active
  • Wait up to 5 minutes for the initial data sync
  • Verify managed device data appears in ThreatAware

Required credentials

Field Name: N-Central Server Public IP Type: String Description: The public IP address of your N-Central serverThis is the external IP address accessible from the internet. Ensure your firewall port forward is configured to this address.Example: 203.0.113.42
Field Name: Forwarded Port Type: String/Integer Description: The port configured in your firewall for N-Central accessTypically this is port 8040 or another port configured during your port forward setup.Example: 8040
Field Name: N-Central Username Type: String Description: Username for the dedicated N-Central user accountUse the account created specifically for ThreatAware integration.
Field Name: N-Central Password Type: Password (encrypted) Description: Password for the N-Central user account
Store this credential securely in your organisation’s password manager.

Verification and testing

After setup, verify the integration is working correctly:
  1. Check Integration Status
    • Navigate to Settings > Integrations in ThreatAware
    • Confirm the N-Central integration shows Active status
    • Check the last sync timestamp
  2. Verify Data Collection
    • Wait up to 5 minutes for initial data collection
    • Check that managed devices appear in ThreatAware
    • Verify device details match your N-Central console
  3. Test Connectivity
    • Create a test device query in ThreatAware
    • Verify the results include devices from N-Central
    • Confirm data accuracy against your N-Central console

Troubleshooting

Symptoms: Integration fails to connectSolutions:
  • Verify the Public IP Address and Forwarded Port are correct
  • Test the connection manually by accessing the URL in a browser: https://<public-ip>:<port>
  • Confirm port forwarding rules are correctly applied in your firewall
  • Verify the N-Central server is running and accessible
  • Check that your firewall allows the connection through the specified port
Symptoms: Integration times out or fails to authenticateSolutions:
  • Verify IP whitelisting is correctly configured for the current ThreatAware allowlist IPs (see Settings → Integrations → AWS Account / IP Whitelist Info)
  • Confirm the firewall rules allow inbound connections from these IPs
  • Check that no other firewall rules are blocking the connection
  • Review firewall logs for blocked connection attempts
Symptoms: Connection fails after entering credentialsSolutions:
  • Verify the Username and Password are correct
  • Ensure the N-Central user account has not expired
  • Confirm the user account has the necessary permissions in N-Central
  • Check that no extra spaces were added when copying credentials
  • Verify the account is not locked due to failed login attempts
Symptoms: Integration shows active but no data appearsSolutions:
  • Wait up to 5 minutes for the initial data sync
  • Verify the N-Central user account has permissions to view devices
  • Confirm managed devices exist in your N-Central console
  • Check the N-Central server logs for API access errors
  • Verify the integration user can authenticate to N-Central directly

Network security considerations

IP Whitelisting Best Practice
  • Only allow ThreatAware’s specified IP addresses to access your N-Central instance
  • Review the firewall rules regularly to ensure restrictions are still in place
  • Document the port forwarding configuration for future reference
  • Monitor N-Central access logs to verify only ThreatAware is connecting
Important Security Notes
  • Do not expose your N-Central instance to the internet without proper firewall restrictions
  • Always use the specified IP whitelisting to restrict access
  • Regularly audit N-Central user accounts and revoke unused credentials
  • Ensure all traffic to N-Central is encrypted using HTTPS

Additional resources

N-Central Documentation

Official N-Central documentation and support resources

Firewall Configuration Help

Contact your network administrator for firewall port forwarding assistance