Advanced Server Access architecture

Advanced Server Access is a combination of the Advanced Server Access platform, clients, server agents, and gateways. Users connect to servers using the Advanced Server Access client. Servers can be placed behind gateways for compliance reasons (see Session capture) and to control pathing.

Advanced Server Access eliminates the need to maintain server credentials through the following flow when an Advanced Server Access client attempts to connect to a server:

  1. Client authenticates against Okta

  2. Advanced Server Access provides an ephemeral certificate to the client

  3. (Optional) Client uses the certificate to authenticate against a bastion or gateway

  4. Client connects to the target server

Diagram that provides an overview of the Advanced Server Access architecture and how it works with Okta

Direct Connections

In simpler configurations, the Advanced Server Access client creates SSH or RDP connections directly to servers running the Advanced Server Access server agent. The following diagram illustrates a simplified topology:

Diagram showing ports used by Advanced Server Access

Gateway Connections

In more complex configurations, connections are first sent to an Advanced Server Access gateway before being forwarded to servers running the Advanced Server Access server agent. The following diagram illustrates a simplified topology:

Diagram showing ports used by Advanced Server Access to connect to servers through gateways