tencent cloud

Cloud Service Secure Access Scenarios

Download
Focus Mode
Font Size
Last updated: 2026-09-08 20:44:41
AI-Translated & Reviewed

Why Are SaaS-Based Secure Access Services Needed After Cloud Migration?

Cost optimization: Replacing traditional private deployment reduces IDC data center maintenance costs.
Agile adaptation: Dynamically scale cloud resources to meet elastic business demands.
Unified management: Centrally manage security policies across multi-cloud and hybrid cloud environments to reduce Ops complexity.

How to Achieve Unified Connectivity When Business Resources Are Distributed Across Multiple Networks, Regions, or Data Centers?

You can configure multiple connection groups to divide business resources from different networks (such as public cloud, private cloud, and local IDC) into corresponding groups. Add connections to each group and deploy connection connectors to target machines to achieve secure cross-network and cross-region connectivity.

Where Should Connectors Be Deployed? Is Multi-IDC Sharing Supported?

Deployment requirements: Deploy on a server that can access both private network business resources and the iOA cloud gateway.
If multiple IDC networks are interconnected, you only need to deploy a connector in any one IDC to proxy cross-data-center access to services in other IDCs.

How to Connect SaaS Applications with IP Allowlists to the iOA Gateway?

1. Add the connector egress public IP address to the SaaS application IP allowlist.
2. Deploy the connector on a machine that can access the SaaS application and the iOA cloud gateway.
3. Add the SaaS application address to the iOA resource and bind it to the corresponding connector.

How to Add a Quick Access Entry for Enterprise Business Resources to the Client Homepage?

1. Click Personalized Settings. On this page, add the site domain or IP address corresponding to the business resource.
2. Currently, only tunnel app URLs can be delivered to the client homepage.
3. Users can only view business resource sites that they have been explicitly authorized to access. Unauthorized site resources (such as those with unassigned or expired permissions) will not be displayed on the client homepage, achieving the principle of least privilege access control.

How to Configure Intelligent Switching Between Private Network Direct Connection and Public Network Proxy?

1. Private network direct connection conditions: The terminal IP address belongs to the enterprise private network IP range configured in Enterprise Private Network Management, and "Enable private network direct connection" is selected in Trusted Access Management > Resource Configurations.
2. Public network proxy trigger: Terminals with non-private IP addresses automatically access through the iOA gateway.

What Is the Purpose of the Direct Connection Allowlist?

IP addresses in the allowlist (business addresses) are accessed through direct connection regardless of whether the terminal is on a private or public network. This applies to high-security services that do not require proxying, such as core databases.

Why Are Most Services Normal, but Most iOA Resource Connectivity Checks Show "Not Detected"?

All-port tunnel resources significantly increase the pressure on the connector for business connectivity detection. If your business does not require all-port tunneling, configure only the necessary ports. This operation only affects the display of business connectivity status and does not impact actual business access.



Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback