All Posts

Remote Access

10 min read

 min read

September 24, 2026

Replacing RDP, SSH and VNC: one central gateway to your IT infrastructure

RDP, SSH and VNC pile up over the years, stay exposed, and are hard to control. Here is how a single central access gateway replaces them and makes internal and external access secure, auditable, and NIS2-ready.

Jan Zeppernick - Amitego CEO

Jan Zeppernick

Management

Introduction

In most IT environments, RDP, SSH and VNC have accumulated over the years. A Windows server is maintained over RDP, a Linux box over SSH, a machine on the shop floor over VNC. Each access was set up on its own, usually with its own firewall rule, its own password, and documentation that is rarely current. The result is a patchwork of open paths into the infrastructure that nobody fully oversees.

Each of these protocols is powerful and useful on its own. The problem is not the single protocol, it is the sum of them: many open ports, many credentials, many ways in. This article explains how a single central gateway replaces that sprawl, for internal admins and external vendors alike.

Key Takeaways

  • RDP, SSH and VNC are powerful but hard to secure and audit one by one.
  • Open protocol ports and broad VPN access are among the most common entry points for attackers.
  • A single central gateway consolidates all privileged access at one controlled point.
  • Internal admins and external vendors use the same secured path, with individual identities, just-in-time access, and full session recording.
  • This meets NIS2, KRITIS, and ISO 27001 requirements for access control and auditability.

The problem: a protocol landscape that grew over years

In most IT environments, RDP, SSH and VNC have piled up over the years. Each access was created on its own, often with its own firewall rule, its own password, and documentation that is rarely current. The outcome is a patchwork of open routes into the infrastructure that no one fully controls.

Each protocol is powerful and useful in isolation. The problem is not the individual protocol but the sum of them: many open ports, many credentials, many ways in. For how quickly an exposed protocol gets exploited, see our article on securing remote desktop access.

Why direct protocol access and VPNs no longer cut it

The classic answer is a VPN. The external vendor or the admin working from home gets a VPN account and is then inside the network. But a VPN only authenticates the tunnel, not the individual action. Whoever is in the tunnel often sees a whole network segment instead of just the one system they are supposed to maintain.

Three weaknesses keep recurring: no visibility into what actually happens in a session, shared credentials that make individual actions impossible to attribute, and access that is rarely revoked once granted. This is exactly where a Zero Trust architecture starts: no access is trusted by default.

The idea: a single point of entry

Instead of exposing every server directly through its protocol, a central access gateway brings all privileged access together at one point. Users no longer connect directly to the target system, they connect to the gateway. The gateway verifies identity, authorizes access to exactly one system for exactly one task, and establishes the connection in the background. RDP, SSH and VNC keep running, but encapsulated behind the gateway rather than exposed on the network.

For the user it stays simple: one entry point, usually right in the browser, with no client to install. For security, everything changes, because every access runs through the same controlled path.

How the gateway works

A well-built access gateway combines several functions:

  • The target protocols RDP, SSH and VNC are terminated at the gateway. No agent needs to be installed on the target systems, and their ports stay closed to the outside.
  • Every user has an individual identity with multi-factor authentication. Shared accounts disappear.
  • Permissions follow the principle of least privilege and are granted just in time, only for the duration of the task.
  • Every session is fully recorded and can be watched live or cut off instantly if needed.
  • All access is captured in a tamper-proof audit log.

Many uncontrolled routes become one, where identity, authorization, and proof come together. At its core, this is Privileged Access Management in practice.

Internal and external over the same path

The biggest practical win: internal administrators and external vendors use the same gateway. The external maintenance technician no longer gets VPN access into the network, but time-limited, recorded access to exactly the system they need to service. For how to onboard external partners in a controlled way, see our article on third-party access, and in the KRITIS context, vendor access at utilities.

For internal teams, the difference between office and home office disappears, because access no longer depends on location but on identity and authorization. That fits the requirements of secure remote work.

What it means for compliance

From a regulatory angle, a central gateway is more than convenience. The NIS2 directive requires access control, multi-factor authentication, and demonstrable control of privileged access. A gateway that records every session and documents every access delivers exactly that evidence. The same applies to KRITIS rules, the GDPR, and standards such as ISO 27001.

Migration: retire RDP, SSH and VNC without disrupting operations

The switch does not have to be a major project. A phased approach works well in practice: first inventory all open access paths, then move the most critical systems behind the gateway, then close the protocol ports to the outside. An agentless solution can be connected without rolling out software on every target system and without disrupting day-to-day operations.

What to look for when choosing a solution

Three things decide it: can the solution be audited in a tamper-proof way, proving every session completely? Can it run on-premise and keep control in your own house? And does it connect external and internal users over the same path? This is exactly what VISULOX by amitego is built for: an agentless access gateway that encapsulates RDP, SSH and VNC, records sessions, and is ready to use in under two days. The VISULOX product overview gives you the full picture.

Contact

Your Direct Path to Secure Remote Access

Speak directly with a cybersecurity expert.

Personal Meeting
Personal Meeting
Personal Meeting

Conclusion

RDP, SSH and VNC are not going away, but they no longer belong exposed on the network. A single central gateway turns many uncontrolled routes into one controlled path: the same identity, the same recording, the same auditability for internal and external users. That lowers risk, simplifies operations, and meets regulatory requirements. If you start with an inventory today, you have already done most of the work. For more, see What is Privileged Access Management?

Jan Zeppernick - Amitego CEO

Jan Zeppernick

Management

Jan has over 12 years of consulting experience at PwC and Ernst & Young, focusing on information security and compliance for critical infrastructure and the automotive industry. As a certified ISO 27001 Lead Auditor and strategy expert, he advises organizations on establishing and auditing security management systems in accordance with ISO 27001 and TISAX.