PAM360 Remote Connect is a native desktop application that allows users to launch secure remote sessions to target systems using credentials managed in PAM360. By default, the Remote Connect application establishes a direct connection from the user’s machine to the target endpoint. While effective, this approach may not align with strict security policies that require network isolation between end-user devices and critical systems. To avoid direct communication between the PAM360 Remote Connect application and the target endpoints during remote sessions for enhanced security, configure the SSH proxy available in PAM360 for the PAM360 Remote Connect application. When configured, all remote connect requests are routed through a designated proxy resource managed within PAM360, ensuring better network control, reduced attack surface, and improved compliance with organizational security standards.
This document outlines the roles required, prerequisites, and SSH proxy configuration within the PAM360 web interface. Read further to know more about them in detail.
By default, users assigned to the Privilege Administrator, Cloud Administrator, or Administrator roles can configure the SSH Proxy for PAM360 Remote Connect. In addition to these predefined roles, users with a custom role that has the Configure SSH Proxy privilege enabled are also allowed to perform SSH Proxy configuration.
Below are the prerequisites for the SSH proxy to work seamlessly to attain a secured remote connection:
Best Practice
To bind the necessary ports to PAM360's IP address or FQDN instead of the default 'localhost', we recommend you to add the system property sshtunnel.tunnelapi.bindaddress=<PAM360 Installed Server's IP or FQDN> to the system_properties.conf file, which is located in the PAM360 installation directory's conf folder.
To configure the SSH proxy for PAM360 Remote Connect from the PAM360 web interface, follow these steps:

Additional Details
Users can set the PAM360 installed server/resource as the SSH proxy resource. However, the Windows Domain Server cannot be set as an SSH proxy.