Installation Guides
Tenant Connector
term abbreviation multi tenant connector mtc this document outlines the steps for deploying kron pam tenant connector (mtc) functionality the tenant connector provides secure remote data center connections to tenants who want to use kron pam’s features, such as preventing password theft and eliminating unsupervised access they need a secure connection between their remote data centers and the central kron pam server depending on the tenant connector (mtc) option, the respective licenses should be active on the kron pam server connector open vpn (for openvpn), connector builtin vpn (for both outbound and inbound built in vpn) there are three options for tenant connector (mtc) deployment if the customer has an openvpn license and configuration, and if the customer wants to use them for the tenant connector deployment, the outbound openvpn option should be selected on the tenant connector page of kron pam web gui if the customer selects this option, the customer should have an openvpn username, password, and configuration file tenants who do not have an openvpn license and want to use kron pam’s secure connection can use the built in vpn option (either outbound or inbound) provided by kron pam the outbound built in vpn option handled by kron pam enables a secure connection between the kron pam server and the tenant connector the outbound connection refers to the path that begins from kron pam and ends at the tenant connector the ports that are used in outbound built in vpn for the initial installation file transfer operation, the specific tcp port (e g , 22) that is selected by the customer should be opened one time at the connector node after the installation, this tcp port might be closed the whole communication between the connector device and kron pam passes through a specific udp port (e g , 10000) and utilizes the external ip address that is specified on the tenant connector page of the kron pam web gui for jwt token based authentication 443 tcp port should be opened at the kron pam’s node for device mapping between the kron pam server and the tenant connector, the predefined udp ports (starting with 40000) are used each device assigned to the tenant connector on the device page of kron pam web gui has an internal udp port that the connector routes with iptables toward the real connection port that is, when a request to access port 40000 comes to the connector from the kron pam server, the connector forwards the request to the ip address and the real connection port (e g , 22 or 3389) of the device by doing port forwarding thanks to iptables the inbound built in vpn option is an alternative solution to the outbound built in vpn option handled by kron pam, which enables a secure connection between the kron pam server and the tenant connector the inbound connection refers to the path that begins from the tenant connector and ends at the kron pam the ports that are used in inbound built in vpn the same ports are used as in the outbound built in vpn, except for the file transfer tcp port (e g , 22) in the case of the inbound option selected, the file transfer tcp port shouldn’t be opened since there is no initial installation file transfer operation in the inbound connection