Network access
An embedded terminal for SSH targets, an OpenVPN or Fortinet tunnel for everything else. No VPN client on the user's machine, and the Broker oversees both routes.
SSH relay
The Broker opens the SSH connection, and an embedded terminal appears in the client tab. The password is resolved inside the Broker and stays there, with password and keyboard-interactive authentication alike. If the credential store does not answer in time, you get a readable error instead of a black screen.
Tunnel-connector
A tunnel into the target network opens over OpenVPN or Fortinet. It terminates in a connector running on your own Linux server, in a separate network namespace per customer. So no VPN client is installed on the user's machine, and the local LAN and every other customer's network stay untouched. The Tunnel module is charged separately.
Dead man's switch
An unattended tunnel stays up for at most fifteen minutes. If the Broker or the network link goes down for good, the tunnel closes itself, and the audit trail closes only the row it genuinely no longer sees as live.
Double hop
One click locks both the jump host and the target server for real, and both locks release together. The inner navigation is automatic up to opening the target and typing the credentials, and not beyond that.
SSO and autologin
On Windows sign-in targets the credential prompt opens pre-filled with your own Windows username, with focus on the password field. Web-based management targets open in an embedded view, and the client signs in on its own via Basic/Digest authentication or form-filling.
The tunnel binds to loopback only
A tunnelled listener never binds to 0.0.0.0 or a LAN address. No port opens on the network for another machine to reach; only processes on your own workstation can see it.