Multiple jump hosts for redundancy?

Multiple jump hosts for redundancy?

avatar

Hi, we are interested in using the jump feature, which we have tested successfully with a single jump host.

Our concern is that this concentrates all admin connectivity via a single point of failure - the jump host. In an emergency situation this could be extremely problematic.

Is it possible to create a pool of jump hosts, so that if one is unavailable, another in the pool will be automatically chosen?

Thanks

All Comments (5)

avatar

Hello,

Thank you for reaching out to us regarding this,

Unfortunately, from my understanding, this would not be possible at this time,

Currently, you would need to edit the Jump Host in the entry Properties manually, I'm wondering if having the option to select which Jump Host to use before launching the entry would would work in your case?

Let me know,

Best regards,

Samuel Dery

avatar

Thanks Samuel

It would be preferable not to have an extra click to select a jump host if the default host is available.

If the default jump host were not available, providing a selector to choose an alternate would work.


It has occurred to me that another reason for pooling jump hosts would be for load balancing - I realise this is not currently possible, but would be a great feature to have available.


Regards

avatar

Hi,

Load balancing with high availability is already supported with Devolutions Server + Devolutions Gateway using Devolutions Gateway Farms. From the point of view of Remote Desktop Manager, there is no manual operation, as Devolutions Server will automatically redirect connections through one of the Gateway Farm members that is in a healthy state. You can also put farm members into a "drain mode" such that they stop receiving new connections to let existing connections finish gracefully for a period of time, after which you can take it offline for maintenance with no service disruption.

Can you describe what kind of connections you are using with the jump host? The proper solution would be to migrate to Devolutions Gateway, which is where all the effort is being put for these kinds of use cases.

Best regards,

Marc-André Moreau

avatar

Thanks for the insight Marc-André

Our use case is primarily for internal network segmentation, so that management interface access is restricted to a small set of machines - we already have a SASE solution in place for remote connectivity, along with a remote desktop/gateway type solution for staff access, so the Devolutions Gateway would be a large overlap in functionality and not really fit our environment.

In terms of connections - we are using the typical administrator types - web consoles, SSH/telnet, RDP

Regards

avatar

Hi,

> Our use case is primarily for internal network segmentation, so that management interface access is restricted to a small set of machine

That's exactly what we've designed Devolutions Gateway for, in addition to remote access from the Internet. You can even combine it with a traditional VPN if you want two layers of network security, but it's built to be secure with just one layer.

> we already have a SASE solution in place for remote connectivity, along with a remote desktop/gateway type solution for staff access, so the Devolutions Gateway would be a large overlap in functionality and not really fit our environment.

What are you using the jump host for then? You don't need to replace everything if it works well, but for the part which is currently solved by the jump host, if you want high availability, the best option we can recommend is Devolutions Gateway.

> In terms of connections - we are using the typical administrator types - web consoles, SSH/telnet, RDP

Those are all supported connection types with Devolutions Gateway, and we even have web clients available in Devolutions Server for RDP, SSH, Telnet. We're working on additional web-based administration consoles to add to this list for future releases.

Best regards,

Marc-André Moreau