This section describes the infrastructure, sizing, and connectivity requirements for deploying and operating Sectona PAM-Cloud. The required resources and prerequisites vary based on factors such as the licensed user count, deployment size, number of managed assets, and expected number of concurrent privileged sessions.
Before deployment, ensure that the required customer-side infrastructure, network connectivity, and supporting services are available and properly configured. Customer-side PAM components must be able to establish secure outbound communication with the Sectona PAM-Cloud environment to enable platform connectivity and privileged access operations.
The following sections describe the infrastructure sizing, network requirements, connectivity prerequisites, and other dependencies required for a successful Sectona PAM-Cloud deployment.
Network Prerequisites
This section defines the network connectivity, routing, traffic flow, and security requirements for deploying and operating Sectona PAM-Cloud. It describes the network prerequisites required to establish secure communication between the Customer Infrastructure and the Sectona PAM-Cloud environment.
The connectivity architecture is designed to use secure outbound communication from the customer environment, minimizing the requirement for inbound network access and reducing the customer infrastructure's exposure to external networks.
The following requirements cover the necessary network routes, firewall rules, ports, protocols, DNS resolution, and connectivity controls required for successful communication between customer-side PAM components and Sectona PAM-Cloud services.
|
Source / Component |
Destination |
Protocol / Port |
Description |
|---|---|---|---|
|
RNA Proxy Connector |
https://<customer>.sectona.cloud |
HTTPS / 443 |
Towards Cloud-PAM |
|
|
https://<customer>.rna.sectona.cloud |
HTTPS / 5344 |
Towards Cloud-RNA Proxy Server |
|
|
Jump Shell |
SSH / 22 |
|
|
|
Jump Host |
RDP / 3389, TCP /4389 |
|
|
Jump Host |
https://<customer>.sectona.cloud |
HTTPS / 443 |
Towards Cloud-PAM |
|
|
https://<customer>.rna.sectona.cloud |
HTTPS / 5433 |
Towards Cloud-RNA Proxy Server |
|
RNA Proxy Connector, Jump Host, Jump Shell |
Customer Infrastructure |
RDP / 3389 |
Remote Desktop Protocol (RDP) based target assets. |
|
|
|
SSH / 22 |
Secure Shell (SSH) based target assets. |
|
|
|
HTTPS / 433 |
HTTPS based target assets. |
|
|
|
TCP / 3306 |
MySQL based target assets. |
|
|
|
TCP / 1433 |
Microsoft SQL based target assets. |
|
|
|
TCP / 21 |
FTP based target assets. |
|
|
|
TCP / 389, 636 |
Active Directory |
|
|
|
TCP / 514 |
SIEM Server |
|
|
|
WMI Ports |
Windows based target assets. |
|
|
|
TCP / 50002 |
IBM DB2 based target assets. |
|
|
|
TCP / 3306 |
MariaDB based target assets. |
|
|
|
TCP / 1521 |
Oracle based target assets. |
|
|
|
TCP / 5432 |
PostgreSQL based target assets. |
|
|
|
TCP / 449, 8476 |
AS/400 based target assets. |
|
|
|
HTTPS / 443 |
Cloud Infrastructure |
|
End User |
https://<customer>.sectona.cloud |
HTTPS / 443 |
Towards Cloud-PAM |
|
|
https://<customer>.rna.sectona.cloud |
HTTPS / 5344 |
Towards Cloud-RNA Proxy Server |
Target-system ports are dependent on the protocols and technologies supported by the managed assets. Additional ports may be required based on the target platform, discovery method, authentication mechanism, session protocol, or PAM functionality being configured.
RNA Proxy Connector
The RNA Proxy Connector is a customer-side component that works in conjunction with the RNA Proxy Server to establish secure communication between Sectona PAM-Cloud and managed assets within the customer infrastructure. It is deployed within a protected network zone where direct inbound connections from the PAM-Cloud environment or end users are restricted or not permitted.
The RNA Proxy Connector initiates a secure outbound connection to the RNA Proxy Server, providing the communication channel required to facilitate privileged session traffic between the PAM-Cloud environment and customer-managed assets. The RNA Proxy Connector functions as a controlled communication boundary between PAM-Cloud and the customer infrastructure. It enables session traffic to be securely routed to managed assets without requiring direct inbound connectivity to protected systems.
This architecture helps maintain network segmentation, minimize the exposed attack surface, and prevent direct external access to protected customer assets. It also provides a controlled and monitored connectivity path for delivering secure and auditable privileged access across on-premises and customer-managed cloud environments.
RNA Proxy Connector Software Prerequisites
|
Prerequisite |
Specification |
|---|---|
|
Operating System |
Microsoft Windows Server 2022 or Windows Server 2025 |
|
Runtime Dependencies |
Microsoft .NET Framework 4.8 and Microsoft Visual C++ Redistributable 2015–2022 |
RNA Proxy Connector Hardware Specification (Without Direct Proxy)
|
Prerequisite |
50 concurrent sessions |
100 concurrent sessions |
200 concurrent sessions |
400 concurrent sessions |
|---|---|---|---|---|
|
CPU |
4 cores |
8 cores |
12 cores |
16 cores |
|
Memory |
4 GB |
8 GB |
12 GB |
16 GB |
|
Disk |
C: Drive 70 GB D: Drive 50 GB |
C: Drive 70 GB D: Drive 50 GB |
C: Drive 70 GB D: Drive 50 GB |
C: Drive 70 GB D: Drive 50 GB |
RNA Proxy Connector Hardware Specification (With Direct Proxy)
|
Prerequisite |
50 concurrent sessions |
100 concurrent sessions |
200 concurrent sessions |
400 concurrent sessions |
|---|---|---|---|---|
|
CPU |
8 cores |
16 cores |
32 cores |
64 cores |
|
Memory |
16 GB |
32 GB |
64 GB |
128 GB |
|
Disk |
C: Drive 70 GB D: Drive 50 GB |
C: Drive 70 GB D: Drive 50 GB |
C: Drive 70 GB D: Drive 50 GB |
C: Drive 70 GB D: Drive 50 GB |
The above specifications are recommended baseline requirements and should be evaluated against the expected workload, session types, managed assets, and deployment configuration.
Jump Host
A Jump Host is a hardened intermediary server that provides a controlled access path between privileged users and systems hosted within a restricted customer network. It acts as an access gateway for administrative connections to protected target systems that should not be directly accessible from external or untrusted networks.
In a Sectona PAM-Cloud deployment, the Jump Host is deployed within a controlled network segment and is used to broker privileged connections to customer-managed target systems. Depending on the target system and configured access method, privileged connections can be established using protocols such as RDP or SSH. Access is governed by the applicable PAM authentication, authorization, and security policies.
The Jump Host helps enforce network segmentation by preventing direct access to protected target systems. Privileged users access the target systems through the designated Jump Host, allowing connections to be controlled and monitored according to configured PAM policies. The Jump Host therefore serves as a controlled security boundary for privileged connectivity, helping reduce direct exposure of sensitive systems while providing a monitored and auditable access path.
Jump Host Software Specification
The following hardware specifications are recommended based on the expected number of concurrent privileged sessions through the Jump Host.
|
Prerequisite |
Specification |
|---|---|
|
Operating System |
Microsoft Windows Server 2022 or Windows Server 2025 |
|
Runtime Dependencies |
Microsoft .NET Framework 4.8 and Microsoft Visual C++ Redistributable 2015-2022 |
Jump Host Hardware Specification
The following hardware specifications are recommended based on the expected number of concurrent privileged sessions through the Jump Host.
|
Prerequisite |
20 concurrent sessions |
40 concurrent sessions |
60 concurrent sessions |
|---|---|---|---|
|
CPU |
8 cores |
16 cores |
24 cores |
|
Memory |
12 GB |
24 GB |
32 GB |
|
Disk |
C: Drive 70 GB D: Drive 50 GB |
C: Drive 70 GB D: Drive 50 GB |
C: Drive 70 GB D: Drive 50 GB |
Configuration and License Requirements
-
Network Level Authentication (NLA): Disable NLA on the Jump Host when Allow Using RDP Client is enabled for any access type.
-
Concurrent Session Capacity: The maximum number of concurrent Jump Host sessions is subject to the applicable Remote Desktop Services Client Access License (RDS CAL) licensing plan.
-
Sizing Consideration: The hardware specifications should be evaluated against the expected concurrent session load and the types of privileged connections being established through the Jump Host.
Jump Shell
A Jump Shell is a hardened intermediary gateway that provides controlled command-line access between privileged users and systems hosted within private or restricted environments. It enables secure access to Unix/Linux-based target systems and containerized or cloud-native environments using command-line tools and protocols such as SSH and kubectl.
The Jump Shell is deployed within a controlled network segment and provides an intermediary access path to protected target environments. Privileged access is governed by the applicable PAM authentication, authorization, and access policies, helping prevent direct user access to sensitive systems.
Jump Shell Software Specification
The following software prerequisites must be met on the server hosting the Jump Shell before installation and configuration.
|
Prerequisite |
Specification |
|---|---|
|
Operating System |
Linux kernel version 5.0 or later operating system |
|
Runtime Dependencies |
Curl latest version, Bash shell |
Jump Shell Hardware Specification
The following hardware specifications are recommended based on the expected number of concurrent privileged sessions through the Jump Shell.
|
Prerequisite |
50 concurrent sessions |
100 concurrent sessions |
200 concurrent sessions |
400 concurrent sessions |
|---|---|---|---|---|
|
CPU |
6 cores |
12 cores |
16 cores |
24 cores |
|
Memory |
8 GB |
16 GB |
24 GB |
32 GB |
|
Disk |
100 GB |
100 GB |
100 GB |
100 GB |
The above specifications represent the recommended baseline configuration and should be evaluated against the expected concurrent session volume, target-system types, command-line workloads, and deployment requirements.