New in RMOS v4.0:
Additional Options for Secure Remote Access to Devices

 

v4.0 adds two new ways to securely connect to remote devices: SOCKS proxy and port forwarding

How SOCKS proxy works in an MSP environmentIn large networks with separate security zones or multiple customers like in an MSP deployment, access can be limited by Uplogix to specific devices, ensuring a secure connection and enforcement of IT policy. RMOS 4.0 includes two new options for secure access to managed devices: SOCKS proxy and port forwarding.

Socks Proxy
A socks proxy allows access from the NOC to Uplogix appliances in different security zones on a distributed network. The “dial out” capability of the Uplogix appliance to connect to the Uplogix Control Center in the NOC is a long established feature of the ARM platform. Now the Control Center can respond through a socks proxy to ensure return communication to a secure zone of a network to devices managed by the Uplogix appliance.

An example use case for the socks proxy feature would be in an MSP deployment where networks for multiple customers are separated from each other, but managed from a single NOC. A problem with a device at one customer is detected by the local Uplogix appliance and an alert is sent to the NOC. An administrator can then connect to the device on the customer network through a SOCKS proxy. From the Uplogix Control Center in the NOC, administrators can connect to devices behind firewalls at different customer sites from one workstation while maintaining security between customers.

Learn more about Uplogix support for MSPs.

Port Forwarding
To manage devices without a console port or without a routable IP address from an Uplogix appliance, users can use a port on the appliance to define a management IP address for the device, or in the case of a direct Ethernet connection to the device, a dedicated IP address. Using an Uplogix applet or any SSH client, users can connect from their workstation through a secure tunnel to the device. The standard Uplogix security and features are applied, including granular authorization, authentication and logging.