Using DB & Server Access Control Client

Prev Next

Available in VPC

The client is an agent program installed on the user's PC to connect to the server or DB via the DB & Server Access Control service. When a connection is made through the client, it is relayed to the target resource via a proxy server, and connection history, as well as executed commands and queries, are recorded in the Cloud Log Analytics service.

Note

The client installation file can be downloaded from the NAVER Cloud Platform console and supports Windows and macOS. For more on how to download it, see Proxy Server.

Client interface

The following is a basic description of the Client interface after logging in:

dsac-client_01_en

Component Description
① Select language Choose between Korean, English, and Japanese as the language to use on the client interface.
② [Sync access control policies] Update the list by retrieving the latest access permission information from the proxy server. Since it does not update in real time, synchronization is required to reflect the latest status if permissions change.
③ Access granted list List of targets granted access to the logged-in sub-account.
  • [DB] tab list: List of DB targets with access permissions. Includes target name, resource type, private domain (IP address), and access port information.
  • [Server] tab list: List of server targets with access permissions. Includes target name, private domain (IP address), and access port information.
④ Log out Log out of the client.

Log in from an internet environment

In an environment with internet access, connect to the proxy server via an SSL VPN and log in with your NAVER Cloud Platform sub-account. To log in:

  1. Run the client.
  2. On the Connection environment settings screen, select Internet.
  3. Click [Log in].
  4. When the sub-account login screen popup appears, log in by entering your sub-account ID and password.
  5. Once you have successfully logged in, the list of DB and server targets that have been granted access will display.
Note
  • You cannot log into the client with your main account. Be sure to log in using a sub-account.
  • If access permissions for DB & Server Access Control Target are not set for the sub-account, the Target list will not be displayed after logging in. Check the user-defined policies for the relevant sub-user in Sub Account.

Log in from a closed network environment

In a closed network environment where internet access is blocked, connect to the proxy server via an IPSec VPN and log in using your sub-account's Access Key, Secret Key, and OTP. To log in:

  1. Run the client.
  2. On the Connection environment settings screen, select [Closed network].
  3. Enter the IP address of the closed network proxy server you want to access and click [OK].
  4. On the login screen, enter the following items:
    • Access Key ID: The access key of the sub-account you want to log in with.
    • Secret Key: The secret key of the sub-account you want to log in with.
    • OTP Serial Number: The OTP serial number registered to the sub-user.
  5. Click [Log in].
  6. Once you have successfully logged in, the list of DB and server targets that have been granted access will display.
Note
  • You can check your Access Key ID and Secret Key on the NAVER Cloud Platform console by navigating to My Page > Account management > Authentication key management, or in the sub-account details section of the Sub Account service.
  • The OTP serial number is the serial number issued when registering an OTP to a sub-account. An OTP must be registered on the sub-account in advance.

Log out

To log out of the client:

  1. Run the client.
  2. Click [Log out].
  3. When the popup appears, click [Yes].
    • Once you have been logged out, the login screen will display.

Sync policies

If sub-account permissions change, you can synchronize to reflect the latest access permission information in the client. The client's target list displays information from the time of login and is not updated in real time. To sync policies:

  1. Log into the client.
  2. Click [Sync access control policies].
    • The DB and server target lists are updated by retrieving the latest access permission information from the proxy server.