This docker BASTION is based on projet: https://guacamole.apache.org/, Authelia, nginx, https://github.com/siomiz/chrome.
In your rsyslog config (on your docker host):
In your interne DNS serveur add bastion server resolution:
First, get repository: git clone https://github.com/lprat/docker-guacamole And go to directory "cert" - make CA (see cert/Readme.md) - Make nginx.key, nginx.pem and dhparams.pem (see Readme.md) or import cert from your PKI - Create user certificat with script if you need for certificat client authentification (see cert/Readme.md) - if you use cert auth, un comment line in nginx_guac.conf:
#if ($ssl_client_verify != SUCCESS) {
# return 403;
#}
In "nginx_guac.conf":
You can config authentification guacamole in "docker-compose_guacamole.yml", by default TOTP is enable.
Use environment variable to config auth (openid, cas, header, ldap, radius, duo), example:
LDAP_HOSTNAME=xxx.fr
LDAP_USER_BASE_DN=
LDAP_PORT=636
Ref: https://github.com/apache/guacamole-client/blob/master/guacamole-docker/bin/start.sh
docker-compose -f docker-compose_guacamole.yml up -d
Connect to guacamole : https://bastion.your_domaine.fr/ ( username is guacadmin with password guacadmin ) and create new admin and remove guacadmin account.
Chrome is docker runned by docker-compose.
Create new connexion to chrome (host: chrome / port: 5900 / protocol: VNC).
When you add new RDP/VNC/SSH acces and it's work fine, you must apply local firewall rule (iptables/netfilter or windows firewall) on RDP/VNC/SSH to accept only "bastion (guacamole)" address IP.
First run command on host to apply good autorization on directory "guac-record":
chown -R 1000.1000 guac-record
For record session use directory: "/record" in guacamole config.
To decode video and text use command docker:
docker exec guacd /usr/local/guacamole/bin/guaclog -f /record/file-to-extract
#read with text editor /record/file-to-extract.txt
docker exec guacd /usr/local/guacamole/bin/guacenc -f /record/file-to-extract
#read with vlc /record/file-to-extract.m4v
In your rsyslog config (on your docker host):
In your interne DNS serveur add bastion server resolution:
First, get repository: git clone https://github.com/lprat/docker-guacamole And go to directory "cert" - In directory "cert" - make CA (see Readme.md) - Make nginx.key and nginx.pem (see Readme.md) or import cert from your PKI - Create user certificat with script if you need (see Readme.md)
In "authelia-conf/auth.conf" :
When you add new web portal admin, you must to modify in file:
access_control:
default_policy: deny
rules:
- domain: bastion_portal_admin.exemple.com
policy: two_factor
You will try if work fine (check on https://bastion_portal_admin.exemple.com), and if it's ok then you can apply local firewall rule on web portal admin (ex: portal_admin.exemple.com) to accept only "bastion (reverse proxy nginx)" address IP.
Choose user or group to give access, can use doc: https://www.authelia.com/docs/configuration/access-control.html
In "nginx_guac.conf":
You can config authentification guacamole in "docker-compose_guacamole.yml", by default TOTP is enable.
Use environment variable to config auth (openid, cas, header, ldap, radius, duo), example:
LDAP_HOSTNAME=xxx.fr
LDAP_USER_BASE_DN=
LDAP_PORT=636
Ref: https://github.com/apache/guacamole-client/blob/master/guacamole-docker/bin/start.sh
docker-compose up -d
Connect to guacamole : https://bastion.your_domaine.fr/ and change default password ( username is guacadmin with password guacadmin ).
When you add new RDP/VNC/SSH acces and it's work fine, you must apply local firewall rule (iptables/netfilter or windows firewall) on RDP/VNC/SSH to accept only "bastion (guacamole)" address IP.
If you have added VHOST portal admin to protect, try if work fine: https://vhost_admin_portal/
Content type
Image
Digest
Size
125.8 MB
Last updated
over 4 years ago
docker pull lprat/guacd