RDM: SSH VPN Missing Options

avatar

RDM 2022.3.21.0

Hi All

It seems that there are missing SSH VPN Options when trying to use SSH VPN directly in a Entry when not using existent SSH Object.

Example using existing SSH Object:
Type SSH (Existing)
Tab Settings (SSH):
forum image

Example trying to setup SSH VPN on a Web Object:
Type SSH (Configure)
Tab Settings (SSH):
forum image

There is no option "Use over secure gateway" which is important when using Dynamic Mode on Outgoing Tunnel Settings.

Another Question:
Is there maybe an Option to only use "Gateway" (Connect through SSH gateway (jump host)) without SSH VPN?
forum image

Best Regards,
Andreas

All Comments (4)

avatar

Hello Andreas,

Have you gotten to this article yet ? https://blog.devolutions.net/2020/02/how-to-configure-a-secure-gateway-in-remote-desktop-manager/

I'm not sure exactly how the Secure Gateway feature works in the backend, but it's likely that the Ports array is managed by the object itself, therefore not supported at an entry custom VPN tab...
It's possible that through its complexity comes a little rigidity

Would it make sense?
I hope this helps.

Best regards,

Alex Belisle

avatar

Hi Alex

Thanks for the Article.

We are using allready SSH Tunnels which functions as Gateway. But every Tunnel itself has also a central Gateway configured, to connect always from the same source IP Address to the Destination because of IP Restrictions.
In some Cases its not needed to open the SSH before, but coming along with the central Source IP to have Access to the Destination.
Thats why im looking for a Central Gateway functionality like a Proxy, but without a central additional SSH Gateway available on every Vault.
In most Cases theyre just Web Sessions (like Firewalls etc).
So do i understand it correctly, for this case i need to create an additonal SSH Tunnel on all 280 Vaults with the same config?

Best Regards,
Andreas

avatar

Hello,

Sorry for the delay, I'm still analyzing your request...
We do have a feature request to make some entries system wide, like SSH Tunnel, to allow notably the utilization of the Secure Gateway Feature.

This forum may end up in a call with you to see if we can do something in the interim.
In the short term, we might resort to create the entry in your 280 vaults, but I can most likely provide a script to create them in an automated fashion, but I'm aware it's not ideal.

Thoughts?

Alex Belisle

avatar

Hello,

I could no replicate the setup internally.

Would you mind sending an email to service@devolutions.net so we can plan a call for me to take a closer look?
We'll post the solution afterward.

Thanks for your cooperation.

Best regards,

Alex Belisle