Skip to main content

Secure remote access

One access layer for private application protocols

Use browser routes for private web applications, Native SSH for standard SSH clients, and Pomerium clients for tunneled TCP or UDP services.

What this pattern controls

Web routes

Open HTTP applications in a standard browser.

SSH routes

Use a standard SSH client with Native SSH Access.

Non-HTTP routes

Use Pomerium clients for tunneled TCP and UDP services.

Protocol choice

Match the access path to the service

Pomerium supports several application protocols. Each protocol has a specific client and authorization boundary.

  • Use a standard browser for HTTP and HTTPS routes.
  • Use a standard SSH client for Native SSH Access.
  • Use Pomerium CLI or Desktop for tunneled TCP and UDP services.

Remote boundary

Give users the service instead of the network

A remote user receives access to a named route, not general reach into the private network.

  • Publish one route for each selected service.
  • Prevent users from bypassing Pomerium to reach the upstream directly.
  • Keep resource-level permissions in the upstream service.

Access paths

Use the documented path for each protocol

Web

Browser access for private web applications

Open a protected HTTP or HTTPS route in a standard browser. Pomerium checks policy for each protected HTTP request.

SSH

Native access for SSH servers

Connect with a standard SSH client after Pomerium and the upstream servers are configured for Native SSH Access.

TCP and UDP

Client-assisted access for non-HTTP services

Use Pomerium CLI or Desktop as the local access client for tunneled TCP and UDP services.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo