mirror of
https://github.com/fosrl/docs-v2.git
synced 2026-10-01 10:19:23 +02:00
58 lines
3.1 KiB
Plaintext
58 lines
3.1 KiB
Plaintext
---
|
|
title: "Understanding Clients"
|
|
description: "Create a client to connect to your Pangolin network from a remote computer"
|
|
---
|
|
A client is a way to access resources on sites remotely and privately via a virtual private network. Clients are used with private resources to faciliate zero-trust network access.
|
|
|
|
By default a client does not have access to any hosts on the local network of the site. Admins must explicitly define resources on the site and give specific users and roles access to the resources.
|
|
|
|
Users must log in and connect from a Pangolin client available on [Windows, Mac, Linux, iOS/iPadOS, and Android](/manage/clients/platforms). They sign in with their user credentials through a web login flow. Machines (automated systems and servers) connect with [machine client credentials](/manage/clients/credentials): an ID, secret, and endpoint.
|
|
|
|
## Client Types
|
|
|
|
There are two types of clients: user devices and machines.
|
|
|
|
<CardGroup cols={2}>
|
|
<Card title="User Devices">
|
|
- Associated with a user in your Pangolin organization
|
|
- Logs in with user credentials through a web login flow (password, 2FA, or an identity provider)
|
|
- Available for download on Mac, Windows, and Linux
|
|
</Card>
|
|
|
|
<Card title="Machines">
|
|
- Represent a server or automated system instead of a user
|
|
- Connect with machine client credentials (ID and secret)
|
|
- Available in CLI form with Pangolin CLI
|
|
</Card>
|
|
</CardGroup>
|
|
|
|
### User Devices
|
|
|
|
A user may download a client for their specific system. Before they can connect, they select a Pangolin server and log in with their user credentials through the web login flow. Users can log in as a Pangolin user or with your attached external identity provider.
|
|
|
|
Examples include:
|
|
|
|
- **SSH**: Admins and developers can connect with their client to specific hosts for SSH.
|
|
- **RDP**: Users can connect to a remote host using familiar remote desktop software.
|
|
|
|
Then, just like in the Pangolin dashboard, a user selects the organization to connect to. Once connected, all resources made available to the user in that organization become available via the tunnel.
|
|
|
|
### Machines
|
|
|
|
Machine clients are for servers and automated systems that are not associated with a specific user.
|
|
|
|
Examples include:
|
|
|
|
- **CICD**: Access remote resources like a database in an automated deployment pipeline.
|
|
- **Servers**: Provide a VPS with access to a resource running in a different network.
|
|
|
|
Though you may connect a server via a user account using a CLI client, we recommend you specifically use a machine client.
|
|
|
|
Machine clients authenticate with [machine client credentials](/manage/clients/credentials): an ID and secret. These are passed as arguments to the Pangolin CLI. They can be revoked and rotated. User devices never use these credentials.
|
|
|
|
## Client Modalities
|
|
|
|
Clients connect to sites using NAT hole punching or relaying. A client first attempts a direct peer-to-peer tunnel, then falls back to relaying through your Pangolin server if hole punching fails.
|
|
|
|
See [NAT Traversal](/manage/clients/nat-traversal) for how each modality works, how to check whether a site is relayed, and tips for improving hole punching reliability.
|