tencent cloud

Bastion Host

Product Introduction
Overview
Strengths
Scenarios
Differences between SaaS BH Standard Edition and Pro Edition
Purchase Guide
Billing Overview
Purchase Method
Upgrade Subscription Plan
Upgrade Bandwidth
Upgrade Extension Pack
Renewal
Payment Overdue
Refund
Getting Started
First Login of Admin
Admin Manual
First Login of Ops Engineer
Ops Engineer Manual
Operation Guide
Admin Guide
Operations Guide
Practical Tutorial
Blocking High-risk Commands
File Transfer Control
Tracing Security Incidents
Cross-VPC Asset Management
Access Bastion Host O&M Page Via Intranet Domain
Troubleshooting
Windows Resource Login Connection Timeout
Windows Resource Login Prompting Wait Active
Linux Resource Login via Mac Prompting No Matching Host Key Type Found
Windows Resource is Inaccessible for Mac Users
iTerm Client Displaying Unrecognizable Characters to Mac Users During Ops
Unable to Invoke Local XShell or SecureCRT
Ops Members Cannot Receive SMS Verification Code
Ops Members Cannot Load the Account When Logging in to Resources
Linux Resource Login Prompting Host Unreachable
Linux Resource Login Failure Prompting Password Error
FAQs
Usage
Consultation
BH Policy
Privacy Policy
Data Processing And Security Agreement
DocumentationBastion HostTroubleshootingWindows Resource Login Connection Timeout

Windows Resource Login Connection Timeout

PDF
Focus Mode
Font Size
Last updated: 2025-08-19 14:28:35

Phenomenon Description

Accessing Windows resources fails with a prompt stating that the remote computer cannot be connected to, as shown below:

image






Possible Causes

The BH's connection to the CVM Network or port of the resource is unreachable, causing the BH unable to proxy access to the resource.

Solutions

1. If the BH and the resource are not in the same VPC, access is not possible. In this case, purchase multiple services or connect the VPC networks.
2. If the resource has security group restrictions, the BH cannot access the target resource. You need to adjust the security group settings to allow the BH to access the resource's remote protocol port.

Directions

Not in the Same VPC

1. Log in to the BH console.
2. In the left sidebar, choose Activate Service.
3. On the Activate Service page, click Purchase to purchase multiple services.


Note
You can also use a VPC to connect VPC networks. For more details, see connecting other VPCs.

Security Group Restrictions

1. Log in to the BH console.
2. In the left sidebar, choose Activate Service.
3. On the Activate Service page, view the private and public IP addresses of the BH that cannot access the target resource. Record the private IP address to add it to the inbound rules in Step 6.



4. Log in to the CVM console and click Instances under the Instances & Images menu.
5. On the Instance page, click ID/name > Security Group of the CVM instance that requires a security group binding to access the security group details page for that instance.



6. 
On the Security Group page, click Edit Rule to access the Inbound rules page for the security group in the VPC.


7. On the Inbound rules page, add or modify inbound rules to allow the private IP address of the BH to access the remote desktop port of the resource.
Note
Source: Allow access to specific IPs based on actual requirements.
Port protocol: Enter the remote desktop port.
Add: Click Add rule, configure the relevant parameters, and click Finish.



Edit: Click Edit rule, modify the source IP and protocol port, and click Save.


8. On the host page of BH, click Editing, check the resource port configuration to ensure it is set to the remote desktop port. If it is incorrect, modify it based on the actual situation.




Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback