Operation and maintenance security center (fortress machine)
Play video
A unified, efficient and secure O&M channel on the cloud is used to centrally manage asset permissions, monitor operation behavior throughout the process, restore O&M scenarios in real time, and ensure that cloud O&M identities can be identified, permissions can be controlled, risks can be blocked, operations can be audited, and help ensure compliance.

Free trial activity

[Cloud native O&M] free experience Cloud native operation and maintenance experience under SAAS architecture, lightweight deployment and opening, convenient operation and maintenance of multi VPC scenarios, and automatic synchronization of cloud ECS
Light weight deployment
Cross VPC Intranet Operation and Maintenance
Automatic recognition of ECS on cloud
Related recommendations
[Enterprise Dual Engine Version] 7-day free trial Provide enterprise level operation and maintenance security control capability, comprehensive asset operation and maintenance scenarios, fine-grained operation and maintenance security control capability, and enterprise level multi scenario compatible access
RDS, self built database operation and maintenance control
Mixed O&M Scenario Unified O&M
Dual engine architecture, high SLA guarantee
Related recommendations

Product specification

Flexible selection of multiple combinations of version, assets, bandwidth and storage
edition
Basic Edition
Package
50 Assets
Purchase duration
January
Enquiry in progress
edition
Enterprise dual engine version
Package
50 Assets
Purchase duration
January
Enquiry in progress
edition
Lightweight version
Number of assets
five
Purchase duration
1 month
Enquiry in progress
edition
Developer Edition
Number of assets
five
Purchase duration
3 months
Enquiry in progress

Product advantages

Use profession for safety, use safety for products, and use products for services
More comprehensive operation and maintenance capability
Unified operation and maintenance of multi cloud and offline server mixed scenarios
Windows/Linux/database one-stop management and control
Global deployment
Support global regional deployment, operation and maintenance
Full support for operation and maintenance of English version and international mobile phone number
More secure and reliable
Cloud architecture and dual engine deployment are more secure
Asset security risk monitoring, which can be perceived by association
More convenient and easy to use
One click product activation and one click asset/user synchronization
Upgrade as you drive, 7 * 24 expert service

Product Functions

Professional operation and maintenance security monitoring capability Establish a unified security operation and maintenance channel, and solve the problems of "numerous assets difficult to manage", "unclear operation and maintenance responsibilities and permissions", and "difficult to trace operation and maintenance events" through fine-grained control of operation and maintenance permissions, real-time blocking of risk commands, password insensitive hosting, and operation behavior recording and broadcasting audit.
Unified operation and maintenance control Provide a unified access to asset operation and maintenance, realize the control and audit of all operation and maintenance behaviors, and achieve one-stop security control over the operation and maintenance behaviors of LINUX/WINDOWS and database assets in the cross account, heterogeneous cloud, and offline IDC hybrid scenarios.
Identity double factor authentication In terms of the prevention of counterfeit user login, it has a dual factor authentication function, which can be used to conduct identity authentication again through dynamic password or SMS authentication, so as to prevent illegal users from stealing account passwords and carrying out counterfeit login and illegal access to assets.
Privilege fine-grained partition In terms of permission specification, users can be grouped and decentralized in a fine-grained way, such as limiting file upload, download, creation, etc., to achieve the most flexible configuration control on the basis of minimizing permissions.
Automatic blocking of high-risk behaviors In terms of malicious access behavior, sensitive high-risk commands, such as deleting data (rm rf/*), formatting and other highly sensitive operations, can be automatically blocked in real time to prevent major accidental deletion events.
Server password rotation In terms of account and password security, the LINUX server password settings can be automatically changed on a regular basis to prevent password disclosure and other risks from increasing security protection.
Traceability audit visualization In terms of audit traceability, visual audit records are used to truly restore the whole behavior scene through visual recording and broadcasting, so as to conduct efficient forensic tracking of security events.

Version scenario recommendation

Small cloud user scenarios
Medium and large mixed user scenarios
Developer/lightweight application scenarios
SAAS lightweight version provides deeper cloud native integration capability, lighter deployment mode and easier cloud native experience
Product advantages
Lightweight deployment
One click opening, multi VPC on cloud, multi regional intranet connection
Deep integration of cloud assets
Automatic synchronization of cloud assets and automatic identification of system accounts
Privileged account management
Divide account permission categories to achieve one click authorization by category
Light specification cost
Smaller resource specification constraints, which can support 5-20 asset scenarios
Enterprise Dual Engine Application Scenario
Enterprise dual engine version, suitable for diversified demand scenarios of enterprises, provides richer functional experience, more stable dual engine architecture, and more smooth operation and maintenance experience
Architecture advantages
Dual engine support
Higher service stability guarantee, dual engine architecture, dual active operation, SLA up to 99.95%.
Enterprise level configuration
Provide more sufficient bandwidth and storage space, improve the performance experience for enterprise capacity asset operation and maintenance, and prevent the performance bottleneck caused by excessive business volume
Functional advantages
Database operation and maintenance control
In addition to linux/windows asset operation and maintenance control, unified database operation and maintenance control can be carried out at the same time
Unified operation and maintenance of mixed scenarios
Unified O&M management and control of complex and diverse offline IDC, heterogeneous cloud, cross account and other asset hybrid scenarios
Web page operation and maintenance
Provide a more convenient operation and maintenance mode, which can be operated and maintained directly by using web terminal without the client
Server password rotation
Provide server automatic password changing capability to strengthen server password security protection

Application scenarios

Financial industry
Internet industry
Financial industry
Due to important business and sensitive data, the financial industry needs to strengthen security monitoring on the behavior of direct operation and maintenance server assets to prevent data leakage caused by unauthorized access during operation and maintenance, as well as business system paralysis caused by high-risk command operations.
Able to solve
Ultra vires protection
Privilege fine-grained division effectively prevents sensitive data leakage events caused by ultra vires
High risk blocking
High risk commands are blocked in real time to ensure business system security during operation and maintenance
Efficient event restore
Visual recording and broadcasting can fully audit the operation behavior, which is conducive to efficient traceability of security incidents
Recommended combination
Internet industry
With the rapid development of the Internet, huge server resources, diversified employees and accounts will lead to chaotic access, difficult account management, and complex permissions.
Able to solve
Unified operation and maintenance entrance
Unified closure of multi account operation and maintenance, one-stop access to huge back-end server resources
Credential privacy hosting
Unified trusteeship of credentials and password free login to avoid risks such as easily forgotten passwords of multi resource accounts and easy disclosure of password information when multiple people know
Fine grained permission division
Fine grained permission management capability, realizing the most flexible permission control on the basis of minimizing permissions, and realizing the standardized management of complex permissions
Recommended combination

Product Dynamics

2017-05-04 New products
Yundun Fortress Machine Commercialized Release
View details
2017-05-04 New products
Yundun Fortress Machine Release
View details
2017-07-19 Function optimization
The bastion machine supports the access management of intranet and internet IP
View details
2017-08-24 Function optimization
Release of fortress machine V2.0.0 and V2.0.2
View details
2017-09-14 New functions/specifications
One button upgrade of fortress machine
View details
New functions/specifications on December 25, 2017
Fortress machine V2.1.5 release
View details
2018-01-18 New functions/specifications
Bastion machine supports package upgrade function
View details
2018-03-29 New Region/New Availability Zone
Fort Machine China Station Overseas Region Release
View details
2018-04-19 New functions/specifications
Access action trail;
View details
2018-05-09 New functions/specifications
Log export; Access to the Sky Tower;
View details
2018-05-10 New Region/New Availability Zone
Newly released North China 2-government cloud region
View details
2018-09-17 New functions/specifications
Alibaba Cloud O&M Management and Audit Product - Fortress Machine V3 Release
View details
2018-11-01 Fix the problem
V3.0.6 feature improvements
View details
2019-01-22 Function optimization
Fortress machine supports real-time synchronization of ECS assets
View details
2019-07-31 New functions/specifications
Fortress machine supports the role of operation and maintenance auditor
View details
2020-05-20 New Features/Specifications
Release of fortress machine operation and maintenance control strategy
View details
2020-09-14 New Features/Specifications
Release of highly available version of bastion machine
View details
2021-03-22 New Features/Specifications
Fortress machine opens the first batch of console API interfaces
View details
2021-10-10 New Features/Specifications
Fortress machine supports unified management of operation and maintenance in multi cloud environment
View details
2022-04-06 New Features/Specifications
Fortress machine supports third-party asset management
View details
2022-08-23 New Features/Specifications
Fortress machine supports database operation and maintenance
View details
2022-09-05 New Features/Specifications
Fortress machine supports web operation and maintenance portal operation and maintenance
View details
2022-12-12 New Features/Specifications
The lightweight version goes online
View details
2022-12-22 Function optimization
Support the operation and maintenance of AWS and Tencent cloud assets
View details
2022-12-22 Function optimization
Support operation and maintenance of Oracle database
View details
2023-01-03 New region/new zone
International Station Hangzhou Region opened service
View details
2023-02-21 New Features/Specifications
Fortress machine connectivity problem diagnosis tool
View details
2023-05-25 New Features/Specifications
Fortress computer developer version goes online
View details
2023-07-19 New region/new zone
Developer version&lightweight version opened in Chengdu region
View details
2023-09-06 New Features/Specifications
Enterprise dual engine version supports operation and maintenance PolarDB
View details
2023-10-31 New Features/Specifications
The lightweight version supports CS private network operation and maintenance
View details
2023-12-06 New functions/specifications
Basic version&enterprise dual engine version control strategy supports control to asset account dimension
View details
2023-12-06 New functions/specifications
Basic version and enterprise dual engine version support automatic locking of users who have not logged in for a long time
View details
View all logs
Quick Start Operations
This video introduces basic entry operations, including adding hosts, authorized hosts, etc
Watch now
Basic Operation and Maintenance
This video helps you quickly understand how to use the bastion machine for O&M access
Watch now
Control policy configuration
This video helps you quickly understand how to configure control strategies to control operation and maintenance behaviors
Watch now
Mixed O&M configuration
This video helps you quickly understand how to configure mixed O&M scenarios through the network domain proxy mode
Watch now

Documentation and Tools