Available Documentation
System Documentation
System Documentation Admin Panel - management interface
User Access Gateway Portal for end users
API Documentation System integration API
Download PDF System Documentation PDF
Search in this documentation
Table of Contents
  • About Documentation
  • Layout Themes of the Admin Panel
  • Introduction
    • System Overview
      • Session Monitoring & Recording
      • Secret Management
      • Just-in-time (JIT) Access
      • Single Sign-on (SSO)
      • Agentless Convenient Access
      • Ai-powered Prevention
      • Productivity Analyzer
      • Rapid Deployment
      • Compliance Support
    • Available GUI Languages
    • Licensing
    • Supported Protocols
      • HTTP
      • Modbus
      • MS SQL (TDS)
      • MySQL
      • PostgreSQL
      • RDP
      • SSH
      • Telnet 3270
      • Telnet 5250
      • Telnet
      • VNC
      • X11
      • TCP
      • Secret Checkout
    • Deployment Scenarios
    • Connection Modes
    • User Authentication Methods and Modes
    • Security Measures
      • Data Encryption
      • Backups
      • Permissions
      • Sandboxing
      • Reliability
      • Cluster Configuration
    • Data Model
    • Dashboard
      • Widgets
      • Adding, Customizing and Removind Dashlets
      • Hard Drives Status Information
    • Footer Information
    • Third-Party Licenses
  • System Deployment
    • Requirements
    • Hardware Overview
    • System Initiation
      • Virtual Machine
    • Accessing Fudo Enterprise Portals
      • Admin Panel
      • User Access Gateway
      • Supported Web Browsers
  • Quick Start
    • SSH
      • Prerequisites
      • Configuration
      • Establishing Connection
      • Viewing User Session
    • SSH in Bastion Mode
      • Prerequisites
      • Configuration
      • Establishing Connection
      • Viewing User Session
    • SSH in Bastion Mode with Jump Host Option
      • Prerequisites
      • Configuration
      • Establishing a Connection
    • RDP
      • Prerequisites
      • Configuration
      • Establishing an RDP Connection with a Remote Host
      • Viewing User Session
    • RDP in Bastion Mode
      • Prerequisites
      • Configuration
      • Establishing an RDP Connection with a Remote Host
      • Viewing User Session
    • Telnet
      • Prerequisites
      • Configuration
      • Establishing a Telnet Connection with the Remote Host
      • Viewing User’s Session
    • Telnet 5250
      • Prerequisites
      • Configuration
      • Establishing a Telnet Connection with the Remote Host
      • Viewing User’s Session
    • PostgreSQL
      • Prerequisites
      • Architecture Overview
      • Configuration Steps
      • Establishing PostgreSQL Connection
    • MySQL
      • Prerequisites
      • Configuration
      • Establishing Connection with a MySQL Database
      • Viewing User Session
    • MS SQL
      • Prerequisites
      • Configuration
      • Establishing Connection with a MS SQL Database
      • Viewing User Session
    • HTTP
      • Prerequisites
      • Configuration
      • Connecting to Remote Resource
      • Viewing User Session
    • VNC
      • Prerequisites
      • Configuration
      • Establishing Connection
      • Viewing User Session
  • Sessions
    • Filtering Sessions
      • Defining Filters
      • Saving Custom Filters
      • Applying Custom Filters
      • Editing Custom Filters
      • Disabling Filters
      • Deleting Custom Filters
      • Full Text Search
    • Viewing Sessions
    • Pausing Connection
    • Terminating Connection
    • Joining Live Session
    • Sharing Sessions
    • Commenting Sessions
    • Sessions’ Retention Lockdown
    • Exporting Sessions
      • Export Session File Formats
    • Deleting Sessions
    • OCR Processing Sessions
    • Session Data Replication
    • Session Timestamping
    • Require Approval for Access
      • Approving Pending User Requests
      • Declining Pending Requests
    • AI Behavioral Analysis in Sessions
    • Ai Session Summary [BETA]
  • Access Requests
    • Awaiting Requests
    • Active Requests
    • Archived Requests
  • Reports
    • System Reports
    • User Reports: Periodic and On-Demand
    • List of Predefined Reports
    • Subscribing to a Periodic Report
    • Unsubscribing from a Recurring Report
    • Generating a Report on Demand
    • Viewing and Saving Reports
    • Deleting Reports
  • User Management
    • Users
      • Creating a User
      • Editing a User
      • Blocking a User
      • Unblocking a User
      • Deleting a User
      • Authentication Failures Counter
    • Groups (RBAC)
      • Access Resolution and Prioritization
      • Creating Group
      • Modifying Groups
      • Deleting Groups
    • Role-Based Access Control (RBAC)
      • Transition to RBAC After Upgrade
        • Understanding Privileges and Capabilities
        • Predefined Roles as a Starting Point
      • Creating Role
      • Assigning Roles to Users
      • Modifying Roles
      • Deleting Roles
      • Typical Role Scenarios and Required Privileges
        • Tab-Level Access Control Matrix
        • Dashboard Widgets Visibility
        • Sessions Tab Permissions
        • Downloads Tab Permissions
        • Safes Management
        • Discovery Tab Permissions
        • Access Request Permissions
        • Fudo Officer
        • Reports Tab Permissions
        • Sudo Policy Permissions
  • Session Management
    • Servers
      • Creating a Server
        • Creating an HTTP Server
        • Creating a Modbus Server
        • Creating a MS SQL Server
        • Creating a MySQL Server
        • Creating a PostgreSQL Server
        • Creating an RDP Server
        • Creating an SSH Server
        • Creating a Telnet Server
        • Creating a Telnet 3270 Server
        • Creating a Telnet 5250 Server
        • Creating a VNC Server
        • Creating a TCP Server
      • Port Ranges in Server Configuration
        • Configuring a Port Range
        • Server Configuration Prioritization in Case of Conflict
      • Use SSH Tunnel - SSH Reverse Tunnel Server Configuration
      • Importing a Server List from CSV File
      • Editing a Server
      • Blocking a Server
      • Unblocking a Server
      • Deleting a Server
    • Pools
      • Creating a Pool
      • Deleting a Pool
    • Accounts
      • Creating an Account
        • Creating an Anonymous Account
        • Creating a Forward Account
        • Creating a Regular Account
      • Editing an Account
      • Blocking an Account
      • Unblocking an Account
      • Deleting an Account
      • Managing Security Alerts
        • Triggering Secret Change
        • Ignoring Security Alert
    • Listeners
      • Creating a Listener
        • Setting up the SSH Listener
        • Setting up the RDP Listener
        • Setting up the VNC Listener
        • Setting up the HTTP Listener
        • Setting up the Modbus Listener
        • Setting up the MySQL Listener
        • Setting up the PostgreSQL Listener
        • Setting up the TCP Listener
        • Setting up the MS SQL Listener
        • Setting up the Telnet Listener
        • Setting up the Telnet 3270 Listener
        • Setting up the Telnet 5250 Listener
      • Editing a Listener
      • Blocking a Listener
      • Unblocking a Listener
      • Deleting a Listener
    • Safes
      • Creating a Safe
      • Editing a Safe
      • Blocking a Safe
      • Unblocking a Safe
      • Deleting a Safe
    • Discovery
      • Creating a Rule
        • Creating a Rule for Accounts
        • Creating a Rule for Servers
      • Managing Rules
      • Creating a Scanner
        • Creating a Scanner for Domain Controller Accounts
        • Creating a Scanner for Domain Controller Servers
        • Creating a Scanner for Local Accounts
      • Managing Scanners
      • Managing Discovered Accounts
      • Managing Discovered Servers
    • Remote Applications
      • Adding Remote Application
      • Adding Arguments
      • Connecting to Remote Application via Access Gateway
      • Granular Access to Remote Applications
      • Deleting Remote Application
    • Policies
      • Regular Expression-Based Policy
      • Ai Module-Based Policy
      • Ai Module-Based Policy Examples
      • AI Session Summary Policy
        • Policy Configuration
        • How It Works
      • Sudo Command Control Policy
        • How Sudo Command Control Works
        • Setting up Fudo for Sudo Control
        • Sudo Policy Configuration
        • Sudo Plugin Installation
    • Downloads
      • Sessions
      • Files
    • Productivity
      • Overview
      • Sessions Analysis
      • Activity Comparison
  • Password Vault
    • Overview
      • Architecture Overview – Security Model
      • Password Vault Structure
      • Event Logging and Audit Trail
    • Collections
      • Creating Collections
      • Nesting Collections
      • Accessing Collection Editing
        • Edit Collection Panel
      • Assigning Users and Groups to Collections
      • Managing Collection Object Rights
        • Assigning Object Rights to Users
        • Assigning Object Rights to Roles
      • Collection Notifications
      • Deleting Collections
    • Secrets
      • Creating Secrets
      • Importing Secrets
      • Accessing Secret Editing
        • Edit Secret Panel
      • Moving Secrets Between Collections
      • Deleting Secrets
      • Assigning Password Vault Secrets to Accounts
    • Secret Access Monitoring
      • Event Types and Status Indicators
      • Filtering and Reviewing Events
    • Fudo Password Vault Browser Extension
      • Installation
      • Opening the Extension
      • Signing In
      • Extension Menu and Settings
      • Signing Out
      • Browsing Collections and Secrets
      • Autofilling Credentials on Websites
      • Access Requests, Exclusive Checkout, and Revoked Access
    • Compromised Passwords
      • How It Works
      • Accessing Compromised Passwords Settings
      • Uploading a Compromised Password List
      • File Format Requirements
        • Plaintext Password Files
        • SHA-1 Hash Files
      • Scan Results
      • Managing Uploaded Files
    • Secret Changers
      • Secret Changer Policy
        • Defining a Secret Changer Policy
        • Editing a Secret Changer Policy
        • Deleting a Secret Changer Policy
      • Custom Secret Changers
        • Defining a Custom Secret Changer
        • Editing a Custom Secret Changer
        • Deleting a Custom Secret Changer
      • Importing and Exporting Secret Changers
        • Exporting a Secret Changer
        • Importing a Secret Changer
      • Connection Modes
        • SSH
        • LDAP
        • Telnet
        • WinRM
      • Setting up Secret Changing on a Unix System
  • Settings
    • System
      • Date and Time
      • Certificates
      • SSH Access
      • Configuration Encryption
      • SNMP
        • Configuring SNMP
        • Configuring SNMPv3 TRAP
        • SNMP MIBs
        • Getting SNMP readings using snmpwalk
        • Fudo Enterprise Specific SNMP Extensions
      • Trusted Timestamping
      • Secret Changers - Active Cluster Node
        • Cluster Secret Changers
      • Sensitive Features
      • Configuring an HTTP Proxy
      • System Update
        • Updating System
        • Restoring Previous System Version
        • Deleting Upgrade Snapshot
      • Hotfix
      • License
      • Diagnostics
      • Exporting/Importing System Configuration
        • Exporting System Configuration
        • Importing System Configuration
    • Network Settings
      • Reverse Proxy
        • Prerequisites
        • Configuration Steps
        • User Access Gateway Connections
        • Enabling and Disabling Reverse Proxy
        • Reverse Proxy Status Indicators
        • SSH Tunnel Operation
        • Workflow Recommendation
        • Internal Routing Behavior
        • Security Considerations
        • Troubleshooting
      • Network Interfaces Configuration
        • Managing Physical Interfaces
        • Defining IP Address Using System Console
        • Setting up Virtual Networks (VLAN)
        • Setting up Link Aggregation (LACP)
      • Labeled IP Addresses
      • Routing Configuration
      • DNS Configuration
      • ARP Table Configuration
    • Notifications
      • Configuring the SMTP Server
    • Artificial Intelligence (AI)
      • AI Behavioral Analysis
        • Configuring Models Trainers
        • Behavioral Analysis Models
      • AI Session Summary [BETA]
    • Authentication
      • External Authentication Server Definition
        • Active Directory
        • LDAP
        • Cerb
        • Radius
        • Assigning an External Authentication Method to a User
        • Second Authentication Factor
      • OpenID Connect Authentication Definition
      • Global Authentication Settings
        • Default Domain
        • Deny New Connections
        • Password Complexity
        • OATH Authentication Definition
        • SMS Authentication Definition
        • DUO Authentication Definition
        • Single Sign On
        • Kerberos Authentication Settings
        • FIDO2 Authentication Settings
    • External Passwords Repositories
      • CyberArk Credential Provider
      • Thycotic Secret Server
      • Local Administrator Password Solutions (LAPS)
      • Fudo Password Vault
      • Azure Key Vault
    • External Storage
      • Configuring External Storage
    • Resources
      • RDP/SSH/VNC Login Screen Configuration
      • User Portal Configuration
        • Login Screen Configuration
        • Predefined Keyboard Layout
    • Backup and Retention
      • Session Data Backup
      • Data Retention
    • Cluster Configuration
      • Session Data Replication and Behavior in the Event of a Node Failure
      • Cluster Initialization
      • Adding Cluster Nodes
        • Cluster Initialization and Adding Nodes
        • Setting Relationships Between Nodes
        • Linking Nodes with the Initial Node
        • Cluster Initialization Completion Verification
      • Cluster Expansion with New Nodes
      • Editing Cluster Nodes
      • Removing Cluster Nodes
        • Removing a Node from the Cluster
        • Rejoining a Removed Node
      • Redundancy Groups
      • Checking Session Replication Status
    • Users Synchronization - User Directory
      • Configuring Users Synchronization Service
      • Disabling Data Synchronization for User
      • Kerberos Support for Active Directory
    • SCIM 2.0 Provisioning
      • Managing Access to the SCIM Configuration
      • Configuring SCIM Provisioning
      • Configuring the Identity Provider
      • Rotating the API Key
      • Disabling SCIM Provisioning
      • SCIM-Managed Account Behavior
      • Attribute Mapping
      • Restrictions On Scim-Managed Objects
      • Blocking Model
      • Authentication with OIDC
      • Auditing
    • Certificate-based Authentication Scheme
    • Login Timeout
    • System Version Restore
    • System Reboot
    • Changing Encryption Passphrase
    • Integration with CERB Server
    • System Maintenance
      • Backing up Encryption Keys
      • Monitoring System Condition
      • Health Check
        • API Health Check
      • Callhome
        • Data Collected by Callhome Service
        • The Benefits of Using Callhome
        • Enable/Disable Callhome
      • Hard Drive Replacement
      • Resetting Configuration to Default Settings
  • Events Log
    • Filtering Logs by Date and Time
    • External Syslog Servers
    • Exporting Events Log
  • Account Activity in the User Access Gateway (UAG)
  • Reference Information
    • RDP Connections Broker
    • Log Messages
  • Fudo Officer 2.3
    • Configuration
    • Managing Profiles
      • Add New Profile
      • Switch Profiles
      • Edit Profile
      • Delete Profile
    • Managing Session Requests
      • Awaiting Requests
      • Active Requests
      • Revoking Request
      • Archived Requests
    • Notifications
      • Configuring Application Notifications
    • Settings
      • Biometric Authentication
      • Change PIN Code
      • Two-Factor YubiKey Authentication
      • Language
  • Fudo ShareAccess
    • Data Model
    • Pairing Fudo Enterprise with Fudo Shareaccess
      • Troubleshooting the connection
    • License
      • Trial License Activation
      • Requesting a License
      • Uploading License File
    • Manage Fudo ShareAccess Members
      • Inviting Members
      • Verifying Members Status
      • Creating an Account Without an Invitation
      • Revoking Members Status
      • Deleting Members
    • Manage Access to Resources
  • Client Applications
    • PuTTY
    • Microsoft Remote Desktop
    • TightVNC Viewer
    • SQL Server Management Studio
  • Troubleshooting
    • Booting Up
    • Connecting to Servers
    • Logging to Administration Panel
    • Session Playback
    • Cluster Configuration
    • Trusted Timestamping
    • Sudo Plugin Issues
    • Support Mode
  • Use Cases
    • Two-Factor OATH Authentication with Google Authenticator
      • Protocols Supporting OATH Authentication Method
      • Configuring the OATH Authentication Method
      • TOTP Code Reuse for Parallel Access
        • Use Cases
        • Default Behavior
        • Behavior When Enabled
    • OpenID Connect Authentication Definition with Microsoft Entra (Azure)
    • Remote Desktop Services Configuration on Windows Server for Fudo Enterprise
      • Setup Remote Desktop Services (RDS) on Windows
      • Setup Fudo Enterprise - Bastion Scenario (Recommended)
      • Setup Fudo Enterprise - Proxy Scenario
    • Custom RDP Hostname in the Session Title
      • DNS Configuration in Windows DNS Manager
      • Fudo Enterprise Configuration
      • Start RDP Connection
      • Result
    • Managing RDP Server Certificates in Windows Server
      • Locating the Server Certificate in Windows Server
      • Providing the CA Certificate
    • Configuring the Single Sign On (SSO)
      • SSO Configuration on Windows Server 2019
      • Setup Fudo Enterprise
      • Setup and Check User Workstation - Windows2010 Client
    • Handling Local Account Password Changes Using a Domain Account with WinRM Secret Changer
      • Hostname and DNS Server Configuration
      • Adding a KDC Server
      • Server Configuration
      • Adding a Secret Change Policy
      • Administrator Account
      • Account for Which the Password Will Be Changed
    • Configuring SSH Key Rotation for an Account
      • Creating a Secret Change Policy
      • Creating an SSH Key Secret Changer
      • Storing the SSH Key in the Password Vault
      • Assigning the Changer to the Secret
      • Pointing the Account at the Secret
    • Configuring Kerberos Constrained Delegation for MSSQL(TDS) Server
      • Kerberos Authentication Configuration on Windows Server
      • Setup Fudo Enterprise
      • Establish a Connection
    • Establishing Connections to Servers via SSH Tunnel in Fudo Enterprise
      • General Requirements
        • Establishing an SSH Connection
        • Establishing an HTTP Connection
        • Connecting to an Oracle Database
        • Connection to a Server with Reverse Tunnel via Tunnel-type Listener
  • Frequently Asked Questions
  • Glossary
Fudo Enterprise 6.1
  • Start »
  • Use Cases »
  • Remote Desktop Services Configuration on Windows Server for Fudo Enterprise »
  • Setup Fudo Enterprise - Bastion Scenario (Recommended)
  • 🇵🇱 PL

Setup Fudo Enterprise - Bastion Scenario (Recommended)¶

The Bastion scenario is the recommended setup for the RDS feature, as it requires minimal manual configuration on Fudo. In this scenario, you need to:

  • create users via the RDS functionality to correspond with Active Directory users,

  • add all servers included in the RDS Collection,

  • configure an account for server authentication,

  • set up a single listener in bastion mode paired with this account.

Note

This use case describes how to configure Fudo Enterprise using the Active Directory external authentication method. Please keep in mind that you can customize user authentication using any other method supported by Fudo Enterprise to align with your specific requirements, the methods typically used in your environment, and your work scenarios.

Configure external authentication method:

  1. Login into your Fudo Enterprise Admin Panel.

  1. Select Settings > Authentication.

  2. In the External authentication tab click Add external authentication.

  1. Enter unique name (e.g., ActiveDirectory01).

  2. Set the Bind address to Any.

  1. In the General section select Active Directory.

  1. In the Host field provide the Domain Controller IP address (e.g., 10.0.136.1).

  2. Leave default port number: 389.

  3. Provide the name of the domain which will be used for authenticating users in Active Directory (e.g., mk.local).

  4. In the Credentials fields provide the privileged account’s login credentials used to access the Domain Controller.

  1. Click Save.

Create User in Fudo:

  1. Select User Management > Users and then click Add user.

  1. Enter the user name that matches the chosen user account in Active Directory (e.g., ‘user1’).

  2. In the Settings tab, under the Safes section, select portal.

  1. Click Save.

  1. Go to the Authentication section and from the Add authentication method drop down list select External authentication.

  1. Chose created in previous steps Active Directory method and click Save.

  1. If necessary, please fill in the remaining parameters as needed for your specific configuration. For more details, please refer to the Creating a User section.

  1. Click Save and close.

Configure Server with the role of Connection Broker:

  1. Select Session Management > Servers and then click + Add server.

  1. Enter server’s unique name (e.g., Broker).

  2. In the Permissions section, add users allowed to manage this object.

  3. In the Settings section on the list of available protocols select RDP.

  1. Select the TLS enabled and the NLA enabled options.

  1. In the Destination section select IPv4 and enter IP address of the server selected during RDS setup for the RD Broker role (in our example, RDB server with IP 10.0.136.2).

  1. Click Save and close.

Configure Servers with the role of Session Hosts:

  1. Select Session Management > Servers and then click + Add server.

  1. Enter server’s unique name (e.g., HOST1).

  2. In the Permissions section, add users allowed to manage this object.

  3. In the Settings section on the list of available protocols select RDP.

  1. Select the TLS enabled and the NLA enabled options.

  1. In the Destination section select IPv4 and enter server’s IP address (in our example, 10.0.136.4).

  1. Click Save and close.

  1. Repeat all the above steps to create second server with name HOST2 and IP address 10.0.136.5.

Configure Pool:

  1. Select Management > Pools and then click + Add pool

  1. Enter pool’s unique name (e.g., RDS-pool).

  2. In the SETTINGS tab select servers to be added to the pool including the broker (e.g., HOST1, HOST2, BROKER).

  3. In the PERMISSIONS section, add users allowed to manage this object (e.g., user1).

../../_images/rds_fudo_pool.png
  1. Click Save and close

Configure Account:

  1. Select Management > Accounts and then click Add account.

  1. Define object’s name (e.g., user1).

  1. In the Type section select FORWARD.

  2. In the Target section click Pool, and from the drop down list select Pool created in previous step (e.g., RDS-pool) to assign created account to this server pool.

  3. Select Forward domain option to have the domain name included in the string identifying the user.

  4. In the Credentials section provide domain’s name (e.g., ml.local).

  5. Click Save.

Configure Listener

  1. Select Management > Listeners and then click Add listener.

  1. Enter listener’s unique name (e.g.,``rdp-broker-bastion``).

  2. Go to PERMISSIONS tab and add users allowed to manage this listener (e.g., user1).

  1. Go to SETTINGS tab and press the RDP button in the Protocol field.

  2. Select the TLS enabled option to enable encryption.

  3. Check the NLA enabled option for additional security.

  4. In the Connection mode section, select bastion.

  1. Set the local address to 10.0.58.238 or Any, and port 3389.

  1. In the CA certificate field, click Generate certificate to generate TLS certificate by choosing key algorithm and providing Common Name (server name where the certificate is installed), or click Upload to upload server certificate file with private key pasted at the end of the file.

  2. Click Save and close.

Configure Safe:

  1. Select Management > Safes and then click Add safe.

  2. Enter safe’s unique name (e.g.,``rdp-safe``).

  3. Click Save to save the object and proceed with further configuration.

  4. Go to the Users tab to assign users allowed to access accounts assigned to this safe.

    • Click Manage users.

    • Mark the checkbox in front of the users’ names to enable their server access through the monitored safe (e.g., user1).

    • Click Save to close the modal window.

  5. Select Accounts tab to add accounts accessible through this safe.

    • Click Manage accounts.

    • Mark the checkbox in front of the accounts’ names to add it (e.g., user1).

    • Click Save to close the modal window.

    • Select added account and click Manage listeners to assign listener (e.g.,``rdp-broker-bastion``).

    • Click Save to close the modal window.

  6. Click Save and close to save the safe configuration.

Establish a connection through the User Access Gateway:

Warning

When establishing connections using the Remote Desktop Services, please use the Native client option. Web client feature is not functional for this type of scenario.

  1. Log in to the Fudo Enterprise Access Gateway using user1 as the username and password corresponding to the one configured in the Active Directory.

Note

You can find the User Access Gateway address in the Settings > Network configuration menu tab.

../../_images/rds_fudo_ip.png
  1. Hover the cursor over the user1 account name, select Native client and click the Connect button to download the .rdp configuration file.

  1. Open the downloaded file to establish a connection.

  2. Enter the password for the user1 account to log in to the server.

Redirect the connection through Fudo using RDP native client:

  1. In order to redirect the connection through Fudo Enterprise, we need to use the Fudo Access Gateway address in the RDP client configuration.

  2. Choose your favorite remote desktop client, such as Microsoft Remote Desktop, and follow its workflow to add a new PC for connection.

  3. Following the example of Microsoft Remote Desktop, click the plus icon in the upper part of the window and select Add PC.

../../_images/rds_mrd_add_pc.png
  1. In the PC Name field, enter the address of the Fudo Enterprise Access Gateway followed by the port number and click Add.

../../_images/rds_mrd_config.png

Note

You can find the User Access Gateway address in the Settings > Network configuration menu tab.

../../_images/rds_fudo_ip.png
  1. Connect to the added PC by providing the bastion login string in Username field and password in the Password field.

Note

  • Please use the following pattern for the bastion login string: user name # account login on the target server # target server address (e.g., user1#user1#10.0.136.4).

You may specify the IP address of any server within the RDS collection as the target server address in the login string, and the broker will handle the connection redirection in accordance with RDS rules.

  • You can skip the account login if it’s the same as the user name, e.g, user1##10.0.136.4

../../_images/rds_mrd_bastion_string.png
  1. Remote Desktop client will establish connection with one of the servers from the RDS collection.

View the established session in the Fudo Enterprise Admin Panel:

  1. Login into your Fudo Enterprise Admin Panel.

  1. Select Sessions.

  2. Find desired session and click i.

../../_images/rds_fudo_sessionview_1.png

../../_images/rds_fudo_sessionview_2.png

Related topics:

  • Setup Fudo Enterprise - Bastion Scenario (Recommended)

  • RDP in Bastion Mode

  • Authentication

  • Network Interfaces Configuration

Next Previous

© Copyright 2026, Fudo Security Inc.