Skip to main content
Version: 2026.09

Configurator

The Configurator is where you set up the server-side settings: database connection, web certificate, Windows services and logging. It opens automatically at the end of the installation. To open it later, run C:\Program Files\Nascella\VpnReporter\Configurator\Nascella.Vpn.Configurator.exe as administrator.

Opening the Configurator​

The Configurator opens a console window and starts a web interface on port 9999 that is reachable only from the server itself. The interface opens in your browser automatically; if Windows asks which app to use, choose your browser.

If the browser does not open, copy the address shown in the console window (http://127.0.0.1:9999/start/...) and paste it into a browser on the server. The address is valid until the Configurator is closed.

Configurator console window and browser selection

1. First-time setup​

On the first start, the Configurator detects the missing security keys and network settings and opens the first-time setup screen. Enter the Company name and click Next. The token identity (Issuer/Audience) is generated from this name.

First-time setup: company name

Security keys and certificates are generated, ports are assigned and the settings are saved. Click Finish.

ComponentDefault address
APIhttps://127.0.0.1:35001 (only from inside the server)
Web consolehttps://*:35444

First-time setup completed

2. Database​

After the first-time setup, the Database Settings screen opens.

Interface language

Change the Configurator's language with the Language button at the bottom left.

  1. Select the Provider: MSSQL, MySQL, PostgreSQL or SQLite.
  2. Enter the server, port, database name, user name and password.
  3. Click Test Connection. Settings can only be saved after a successful test.
  4. If the server is reachable but the database does not exist yet, you are asked whether to create it. Click Yes.

Database Settings: create the database?

  1. The database is created and the connection is tested again. When you see Connection successful, click Save.

Database created, connection successful

  1. The settings are written to the appsettings.json files in the Configurator, Api and Web folders, and you are asked whether to restart the services.
    • Yes: the services restart and VPN Reporter is ready to use with the default settings.
    • No: choose this if you want to replace the web certificate, then continue with Network and TLS.

Settings saved, restart the services?

3. Network and TLS​

The installation creates a self-signed certificate for the web console, so browsers show a warning. We recommend replacing the web server certificate with your own. The API certificate does not need to be changed.

Sections of the Network & TLS screen:

SectionDescription
API ServerPort (default 35001) and certificate. The API address is fixed: it is reachable only from inside the server (127.0.0.1).
Web ServerIP address (* = all addresses), port (default 35444) and certificate. The certificate name (CN), file, expiry date and days left are shown.
CORS - Allowed OriginsAddresses used to reach the web console; one per line (commas also work). Updated automatically when the web port changes.
WorkerAPIIgnore SSL certificate errors: applies to the collector's connection to the API. Enabled by default because the API uses a self-signed certificate; turn it off if you installed a trusted (corporate) certificate for the API.

To replace the web certificate:

  1. In the Web Server section, click Change… next to the certificate line.

  2. In the window that opens, choose Import my own PFX file, select the PFX file and enter its password. The certificate name (CN) and expiry date are shown; if they are correct, click OK. The other options are Keep current certificate and Generate new self-signed certificate.

    Web certificate: importing your own PFX file

  3. In CORS - Allowed Origins, enter the secure address you will use to reach the web console, for example https://vpn.nascella.com:35444. The name must match the name in the certificate.

  4. Click Save.

Network & TLS: new web certificate, days left and CORS address

After saving you are asked whether to restart the services; click Yes. The services are stopped and started in turn.

Services restarted

Keep an eye on the certificate expiry

The days left are shown on this screen and in the Certificates section of the Dashboard. Import the new certificate the same way before the current one expires.

4. Dashboard and services​

The Configurator's Dashboard shows the service status (Start / Stop / Restart), the API and web addresses and the CORS addresses. Click a CORS address to open the web console.

Before going live

Click Configure Delayed Auto-Start. The setup creates the services with manual start; this button makes them start automatically (delayed) when Windows starts and sets 3 restart attempts, 60 seconds apart, if a service fails.

Dashboard: service status and delayed auto-start

The lower part of the page shows the configuration file locations (every save updates all three files) and the expiry dates of the API and web certificates.

Dashboard: file locations and certificates

Other settings​

These screens are not needed for the first setup.

Logging​

SettingDescription
Log languageLanguage of the log files. Independent of the interface language; files are written in a single language.
Log time zoneTime zone of the timestamps in the logs.
Log folderA relative path is resolved against the application folder.
Minimum levelRecords below this level are not written (default Information).
RetentionMain and error logs 31 days, stack-trace log 14 days (defaults). A new file starts every day; above 50 MB an extra part is added for the same day.

Logging: general settings

Logging: advanced settings

Traffic log​

Folder where the traffic logs pulled from the firewall are stored. A relative path is resolved against the application folder; the folder is created if missing.

Traffic log folder

Admin recovery​

Reopens the admin account when nobody can sign in: forgotten password, lost two-factor device, locked or deactivated account. The change is written straight to the database.

Cannot be undone

It only affects the user named admin; no other account is touched. All open sessions of the admin account are signed out.

  1. Select the operations to apply:
    • Reset the password: the password returns to the product default and must be changed at the first sign-in.
    • Remove two-factor authentication: when the authenticator device is lost.
    • Unlock the sign-in lock: clears the lock-out and the failed sign-in counter.
    • Re-enable the account: brings back an admin account that was deactivated or deleted.
  2. Click Generate Code and send us the six-digit code.
  3. Paste the time-limited encrypted token we send back and click Apply Recovery.

The code survives a restart, so you can close the Configurator while waiting for our answer. Each code is single-use.

Administrator Account Recovery

GeoIP scan​

Fills in location details (ISP, region, city, coordinates) for public IP addresses saved before GeoIP was configured. The scan uses your GeoIP provider's quota and only touches records where these fields are empty. Nascella approval is required: click Generate Code, send us the code, paste the time-limited token we send back and start the scan. Each token allows one scan.

GeoIP Scan

Duration repair​

Previews and repairs invalid (abnormally large) connection durations; the values before and after the repair are written to an audit file. An administrator token is required: review the records, generate a code and send it to our support team, paste the token you receive and run the repair. Use it only when our support team asks you to.

Repair VPN connection durations

Quit​

When you are done, click Quit at the bottom left and confirm with Yes. Unsaved changes are lost.

Close the Configurator?

The Configurator closes and the browser tab closes on its own after a few seconds.

Configurator closed

Next step: First sign-in to the web console.