
Windows Server
Run Pomerium Core on an adjacent supported host to protect applications and services on Windows Server.
Overview
Windows Server is Microsoft's enterprise server platform. It runs applications, web services, file services, directory services, and other workloads in data centers, clouds, and hybrid environments.
Private Windows Server applications can receive identity-aware access through an adjacent supported Pomerium gateway without broad network exposure.
Windows Server supplies the protected service, client, or surrounding network. Pomerium runs on a supported adjacent platform and supplies the identity-aware access point.
Prerequisites
- A supported Pomerium host, container platform, or Kubernetes cluster that can accept the user-facing route and reach the private service in the adjacent environment.
- DNS, TLS, identity-provider configuration, and route policy for the selected application.
How it works
Place Pomerium Core on a supported host, container platform, or Kubernetes cluster next to the environment. The Pomerium deployment must accept the user-facing route and reach the private service.
Pomerium does not publish a Windows Server binary. Run Pomerium Core on an adjacent supported host, container platform, or Kubernetes cluster that can accept the user-facing route and reach the Windows Server service.
Test reachability from the Pomerium host to the private upstream. Then confirm that a direct public route cannot bypass Pomerium.
Example
An internal IIS application runs on Windows Server. Pomerium runs on a Linux gateway in the same network and forwards an approved HTTP request to IIS.
Considerations
- RDP and other TCP or UDP services need their own Pomerium non-HTTP routes and a client on the user device.
