This article applies to an upcoming version of PRTG
From NATS to QUIC
We are changing the multi-platform-probe-to-core communication from NATS to the internet communication protocol known as QUIC. QUIC is a transport layer network protocol defined in RFC 9000 as a modern internet communication protocol.
Important: We plan to introduce QUIC alongside NATS connections to prevent downtime in monitoring and give you time to migrate your multi-platform probes to the new protocol. We recommend that you migrate your remote probes as soon as possible as we plan to completely discontinue NATS connections one stable version after the introduction of QUIC. You will receive ToDo tickets within PRTG to this point.
Why switch to QUIC
QUIC includes TLS 1.3 encryption and Ed25519-based authentication, so the connection between the multi-platform probe and the PRTG core server is secure without a separate messaging server component. QUIC also handles unstable or roaming connections better than NATS, for example for probes on ships or satellites, and reduces connection latency.
If QUIC is not available on your network, the multi-platform probe can fall back to a direct TCP connection with TLS 1.3 encryption instead.
What changes
You no longer need to manage a NATS server connection and configure certificates across multiple systems.
Port changes
- PRTG uses port 23563/UDP for QUIC connections.
- PRTG uses port 23563/TCP for the fallback connection if QUIC is not available.
- PRTG automatically removes the firewall rules for port 23561, which the NATS connection used.
Configuration changes
You will need to reconfigure existing multi-platform probes to use QUIC (or TCP). You can do this as soon as the multi-platform probe 4.0 package is available.
How to migrate an existing multi-platform probe
Follow the steps below to migrate from the NATS protocol to QUIC. For more information on specific commands to use to install or configure the multi-platform probe, see the Multi-Platform Probe for PRTG manual.
- Download and install multi-platform probe 4.0 on your remote probe system.
- Update your existing probes to the new version.
- After the update finishes, run the Configuration Wizard on the remote probe system.
- In the configuration wizard, select whether the remote probe should use a QUIC or a TCP connection.
- To use the self-signed server certificate provided by Paessler, select Fetch it from the PRTG server and verify the thumbprint. Otherwise, use a certificate from the system store or a specified path.
- The wizard creates a new probe access token for the connection. In PRTG, navigate to Setup | System Administration | Probes and paste the access token to the setting Access Tokens under Multi-platform probes.
Note: You do not need to approve a migrated probe again. The PRTG core server already recognizes the probe from the existing connection.
Special cases
If you use a NATS server to isolate external-facing services on the network, we recommend that you set up a firewall to achieve the same results. In case this is not sufficient for you, please contact the Paessler support team. In cases where you cannot use QUIC, PRTG supports a direct TCP/TLS connection as a fallback.
More
- Paessler Blog