Skip to content
Networking & DNSIntermediate

How AppAnywhere Works: Installation, Static IP and Port 7722 Setup

Quick Answer AppAnywhere publishes applications running on a Windows host so authorized users can access them remotely. Installation involves preparing the h...

BI
Bison Technical Team Enterprise IT specialists
Updated 07 Oct 2026 9 min read 1 total views
Structured technical guidanceSafety notes included where requiredSources listed below

Quick Answer

AppAnywhere publishes applications running on a Windows host so authorized users can access them remotely. Installation involves preparing the host, installing the vendor-supported package, configuring users and applications, and testing local access before enabling access from outside the office.

For a deployment using public port 7722, give the server a fixed local IP address, obtain a reachable public IP at the server location, and forward external port 7722 to the server’s actual listening port. 7722 is a deployment choice, not a verified AppAnywhere default. The vendor’s legacy user guide identifies TCP 3389 as its default RDP port and documents a setting for changing it. A static public IP provides a consistent connection address; the guide also describes dynamic DNS as an alternative. :chatgpt-content-reference{index="0"}

Advertisement

How AppAnywhere Works

AppAnywhere uses Remote Desktop Protocol (RDP) technology to provide remote access to Windows applications and desktops. The application executes on the host; the remote user interacts with its session through a compatible client. Administrators can assign applications to users or groups. :chatgpt-content-reference{index="1"}

Component Purpose
AppAnywhere Basic Provides remote sessions and application publishing.
WEB Plugin Provides browser-based access. The published description refers to Java-based functionality, so confirm compatibility with your current browser and product build.
Universal Printer Converts remote print output into PDF-based data for delivery to the user’s workstation.

The WEB Plugin and Universal Printer have separate vendor descriptions. Confirm which components your purchased edition includes before deployment. :chatgpt-content-reference{index="2"}

Before You Begin

  • Obtain the current installer and installation instructions from the vendor or an authorized supplier.
  • Confirm support for the exact Windows edition and build you intend to use. The public pages contain legacy operating-system references and do not establish compatibility with every current Windows release.
  • Confirm AppAnywhere, Windows, and hosted-application licensing requirements for your intended use.
  • Ensure the application supports multiple simultaneous users and the proposed installation environment.
  • Arrange administrator access to the server and router, plus local console access if a network change disconnects your remote session.
  • Back up application data and record existing network, firewall, and router settings.
  • Plan server capacity around the application workload and expected concurrent users.

The vendor’s download page links to an administrator guide, but its operating-system references and screenshots are historical. Use the following workflow alongside instructions supplied for your installed release. :chatgpt-content-reference{index="3"}

Understand the Two IP Addresses

Address Where it is used Example or requirement
Fixed local IP Identifies the server inside the office network. For example, 192.168.1.50, if valid and unused on your network.
Public IP Identifies the Internet connection through which outside users connect. Obtain an address that permits inbound connections from your ISP.

Keep the server’s local address stable using a DHCP reservation or a correctly configured static address. DHCP reservation makes the router assign the same address to the server. A changing local address can break the forwarding rule. :chatgpt-content-reference{index="4"}

A static public IP is recommended for a consistent remote endpoint. A dynamic public IP can work with dynamic DNS, which updates a hostname when the public address changes. Neither arrangement removes the need for a working inbound network path. :chatgpt-content-reference{index="5"}

Check for CGNAT or Double NAT

Carrier-grade NAT (CGNAT) places an ISP-controlled address-translation layer upstream of your router. Ordinary forwarding on your router cannot create an inbound path through that layer. Ask the ISP whether your connection has a public IPv4 address and permits inbound connections.

If an ISP modem/router sits ahead of your own router, double NAT may require forwarding at both devices or an ISP-supported bridge configuration. Resolve this before troubleshooting AppAnywhere itself. :chatgpt-content-reference{index="6"}

Step 1: Prepare the Server Network

  1. Record the server’s current IP address, subnet mask, gateway, and DNS settings.
  2. Reserve its address in DHCP, or assign an unused static address compatible with the existing subnet.
  3. When assigning an address manually, coordinate with the DHCP configuration to prevent duplicate addresses.
  4. Confirm that the server can reach required application resources and that another office computer can reach the server.
Warning: Changing a server’s IP address can disconnect active sessions and affect applications that reference its old address. Make the change during a maintenance window with local recovery access available.

Step 2: Install and Configure AppAnywhere

  1. Sign in with an administrator account and run the vendor-approved installer.
  2. Review the license agreement and follow the installation prompts for your release.
  3. Restart when required.
  4. Open the installed administration tool and check the license status.
  5. Create or select authorized user accounts and assign the required applications.
  6. Configure the supported connection client for the host address and listening port.

The legacy guide describes installation followed by a restart, an administration tool, license checks, application assignment, and connection-client generators. Exact labels and available options may differ in your release. :chatgpt-content-reference{index="7"}

Use individual accounts with strong passwords and only the permissions each user needs. Test application launch, file access, and saving under a normal user account before allowing external connections.

Step 3: Decide How Port 7722 Will Be Used

The router’s external port and the server’s internal port can differ. Choose the mapping that matches the actual listener:

Configuration Router mapping Windows Firewall destination port
Server configured to listen on TCP 7722 External TCP 7722 to 192.168.1.50 TCP 7722 7722
Server confirmed to listen on TCP 3389 External TCP 7722 to 192.168.1.50 TCP 3389 3389

Replace 192.168.1.50 with your server address. Port translation does not change the server listener. Confirm that your router supports separate external and internal ports. :chatgpt-content-reference{index="8"}

If you change the server listener, use the supported product configuration and update client settings. Do not assume that configuring the router automatically changes AppAnywhere.

Verify the Listener

On the Windows server, open Windows PowerShell as administrator and run this read-only check for a server expected to listen on TCP 7722:

Get-NetTCPConnection -State Listen -LocalPort 7722

For the second mapping, substitute 3389. A matching entry confirms a TCP listener, but not that it belongs to the correct application. Check the owning process and local address. A listener limited to 127.0.0.1 cannot accept connections from other computers. If no matching entry exists, check the configured port and service status before changing the router. :chatgpt-content-reference{index="9"}

Step 4: Configure Windows Firewall

Warning: An inbound firewall rule permits access to a listening service. Restrict access to authorized source addresses where practical. Keep the firewall enabled and avoid broad port ranges.

These steps require administrator rights on the Windows host:

  1. Open Windows Defender Firewall with Advanced Security.
  2. Select Inbound Rules, then New Rule.
  3. Select Custom. Restrict the rule to the verified application or service where supported.
  4. Select TCP and set the local port to the server’s actual listener: 7722 or 3389 in the examples above.
  5. Under Scope, specify authorized remote addresses where practical, including your local test client.
  6. Select Allow the connection and apply the rule to the appropriate active network profile.
  7. Name the rule clearly and save it.

Use the internal listening port for this rule, even when the router exposes a different external port. Managed firewall policies may require changes by your domain administrator. :chatgpt-content-reference{index="10"}

Step 5: Test Access Inside the Office

From another Windows computer on the local network, run the following in Windows PowerShell. Administrator rights are normally unnecessary:

Test-NetConnection -ComputerName 192.168.1.50 -Port 7722

Use port 3389 instead if that is the internal listener. TcpTestSucceeded : True means the TCP connection succeeded. It does not verify authentication or application operation. Next, connect using the supported client and test the published application. :chatgpt-content-reference{index="11"}

Do not proceed to Internet testing until local access works.

Step 6: Configure Router Port Forwarding

Warning: Direct forwarding exposes the remote-access service to incoming Internet traffic. Prefer access through a maintained VPN or supported secure gateway where practical. Using port 7722 alone does not provide encryption or prevent unauthorized login attempts.
  1. Sign in to the router’s administration interface.
  2. Open Port Forwarding, Virtual Servers, or the equivalent NAT settings.
  3. Create a TCP rule with external port 7722.
  4. Set the destination to the server’s fixed local address.
  5. Set the internal port to the verified server listener.
  6. Apply available source restrictions, enable the rule, and save.

Menu names vary by router. Do not add UDP or other ports unless your installed product’s requirements call for them. :chatgpt-content-reference{index="12"}

Step 7: Verify External Access

Use a computer on a separate Internet connection, such as a mobile hotspot. In Windows PowerShell, replace the placeholder below with your actual public IP or hostname:

Test-NetConnection -ComputerName "YOUR_PUBLIC_IP_OR_HOSTNAME" -Port 7722

If the TCP test succeeds, configure the supported client with the same public address and external port 7722. Sign in as a normal user, launch the assigned application, and verify saving and printing. A successful TCP test alone does not prove the complete service works. :chatgpt-content-reference{index="13"}

Browser Access and Universal Printing

Browser Access

The WEB Plugin documentation describes HTTP/HTTPS access and Java-based sessions. Confirm the supported browser, client technology, certificate requirements, and web listener for your installed version. Do not assume that an RDP listener on port 7722 accepts browser traffic. Use the vendor-specified HTTPS endpoint for web access. :chatgpt-content-reference{index="14"}

Universal Printing

The vendor describes Universal Printer options for PDF preview, the workstation’s default printer, and selection of a local printer. First verify that the workstation can print locally. Then test a one-page document from the remote session. The PDF-preview option requires a local PDF reader according to the vendor documentation. :chatgpt-content-reference{index="15"}

Troubleshooting

Symptom Check next
No local TCP connection Verify the service listener, server address, internal port, and Windows Firewall rule.
Local access works; external access fails Check the forwarding destination, public IP, upstream NAT, ISP restrictions, and source filters.
External access works, but testing the public address inside the office fails The router may not support NAT loopback. Verify from a separate Internet connection.
Connection stops working after a network change Check whether the server’s local address or the Internet connection’s public address changed.
TCP test succeeds; login fails Check the receiving service, account permissions, credentials, and product logs.
Login succeeds; application fails Test the application under that user account and inspect its permissions, dependencies, and data access.
Remote printing fails Test local printing, then verify the installed printing component and selected output mode.

For network failures, isolate local connectivity from Internet forwarding before changing application settings. Router troubleshooting guidance identifies private WAN addresses, firewall blocking, and loopback limitations as relevant checks. :chatgpt-content-reference{index="16"}

Rollback and Recovery

  1. Disable the new router forwarding rule to stop direct external access.
  2. Disable only the Windows Firewall rule created for this deployment.
  3. If you changed the listener, restore its previous value through the supported configuration and update clients.
  4. If necessary, restore the recorded network settings from the local console.
  5. Retest local application access before reintroducing external access.

Keep application data backups separate from configuration backups. Record the working port mapping and authorized access method once testing is complete.

Sources

YOUR FEEDBACK

Was this guide useful?

Your answer helps us keep BISONKB accurate and practical.

THE BISON BRIEF

Practical IT knowledge, once a week.

New troubleshooting guides, scripts and infrastructure notes. No noise.

By subscribing, you agree to our privacy policy. Unsubscribe at any time.