Solution is acting as a gateway for remote administration tasks. Available on HTTPS only. Allow RDP, VNC and SSH from it to our applicative end servers. Access is restrained to Admin with 2FA.
Pros
All port closed except 443
Attackable scope is limited
Administration tasks are under one entry point
Need
Privileged users accesses should only be made through a secure portal no matter is the end-devices.
Some remote network are totally isolated from internal ressources. No VPN, low filter, minimal infrastructure. We needed automatic check going securely through Public internet.
With Hybrid workspace we needed to have a reliable solution to know who is available, online and reachable. The solution shouldn’t be intrusive or used as a presence control system. Self-hosting without any outside connectivity was mandatory.