> For the complete documentation index, see [llms.txt](https://docs.adaptiva.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.adaptiva.com/patch/air-gap/use-airgap.md).

# Use Air Gap

Security and best practices for Air Gap for OneSite Patch

## Designate Security Roles

When setting up the Air Gap server, you should set up an Air Gap Admin and Air Gap Operator on both servers:

* Super Admin Role: admin permissions for any Adaptiva product.
* Air Gap Admin Role: only admin permissions for the Air Gap add-on.
* Air Gap Operator Role: can export/import patches, but can’t change settings.

1. Click the **gear icon > Settings > Security > Roles**.
2. Click **Air Gap Roles**.
3. For each role, select it, and then in the **Details** view, use the **Role Membership** section to designate either an individual or an AD Group.
4. Be sure to click **Save** once you have added an individual or group to a role.
5. Repeat this process for the other Air Gap role.

   ![Air Gap Roles](https://2503798551-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F7VJNM00p5XQ4pMWqCu8y%2Fuploads%2Fgit-blob-5746a3adbbfe62d5437fe525a41d830ce1972fd6%2Fair-gap-roles.png?alt=media)

## Best Practices and Import History

The Overview screen has some useful information in addition to being the place where you create requests and upload payloads. Here you'll find a **Zone Status** and **Zone Overview** section.

### Sync Cadence

You should regularly sync your Air Gap servers to receive metadata feed updates, patches, and installers. The regularity of this activity depends largely on your patch strategies. If you have aggressive patch strategies for weekly updates, you will need to request a patch sync before the execution of the weekly patch strategy.

### Import History

The **Patch Sync Response Import History** section shows a history of imports.

### Keep Paired Servers in Sync

If you upgrade your online OneSite Patch server, you must also upgrade your paired Air Gap server(s). If the paired servers have different versions of the OneSite Platform installed, patch sync requests will fail.

{% hint style="warning" %}
Server versions must be an exact match, down to the final revision number. For example, 10.2.973.**9** and 10.2.973.**6** do not match.
{% endhint %}

### Security Scans

All Patch response files can be scanned using standard corporate practices and remediation techniques.

## Related Topics

* [Overview: Air Gap](/patch/air-gap/airgap-overview.md)
* [Install Air Gap](/patch/air-gap/install-airgap.md)
