Skip to main content

SHIELD Edge Link Function Specification

SHIELD Edge Link is

  • Access Control Service (IAP)
  • Proxy Relay Service (In/Outbound)- The basic Proxy performs both Inbound and Outbound roles.
  • Remote Access to Desktop/Console

It consists of a total of 3 main services, each responsible for functions such as user authentication and access control, internal↔external communication relay, and remote access.


Access Control Service (IAP)

This is a service that provides user authentication-based access control, JWT token validation, and ZTCAP policy application. It verifies external user requests through user authentication and conditional policy validation, allowing safe access to internal systems.

numberMajor CategorySubcategorySubcategoryDescriptionNoteDocument Link
1User Authentication ManagementIAP CertificationPerforming Basic Authentication ProcessWhen external users connect, perform user account authentication through IAP (SSO, OAuth, etc.).
2Conditional PolicyConditional User Authentication PolicyStrengthening user authentication based on context through the application of conditional policies such as access location, time, and session management.
3Internal Access Target ManagementRegistration of Internal Work SystemEnter connection target information- Enter the customer business system address (internal network URL/IP)
- Specify Subdomain (External Access Address)
- Select Connection Relay Server (Edge Server)
- Write a description (note)
4Modify Connection TargetChange of access information for the existing registered internal system
Modify Internal Address, Subdomain, and Connection Server
5Delete Connection TargetDelete Access Information for Decommissioned Systems
6Connection List ManagementView Connection ListView All Registration RecordsExternal access address, internal actual address, connection relay server, status display
7Filter/SearchConditional SearchSystem name, subdomain, can be queried by status
8Status CheckCheck Relay Server (Edge) Status- Active: The authentication information connected to the server is valid and accessible.
- Inactive: Authentication information has expired or been invalidated, making access impossible.
It is not a value set directly by the administrator, but rather a status that the system automatically reflects.
9Live Status CheckCheck server connectivity in real-time when the Live button is clicked.
10Access History ManagementLog ManagementUser Access History ManagementRecord and manage internal system access history
Statistics inquiry (by user/by URL), check block history available

Proxy Relay Service (In/Outbound)

The basic Proxy is a relay proxy service that performs both Inbound and Outbound roles.

numberMajor CategorySubcategorySubcategoryDescriptionNoteDocument Link
1Connection RelayExternal → Internal RelayConnection Request RelaySafely relay external user access requests to internal systems
2Internal to External RelayConnection Request RelaySafely relay external access requests from internal users to external systems
3Register/Delete Relay Server IPRegistering or Deleting Public IP for External Access
4Access ControlURL Access ControlAllow/Deny URL SettingsRegistering and Managing Allowed External Access URLs
5ACL Rule ManagementSetting and Managing Access Allow/Deny Rules
6Access LoggingLog ManagementAccess Log RecordInternal ↔ External Access History Recording and Management
7Log InquiryAccess Log View and Search

Desktop / Remote Console Access (Coming Soon)

SHIELD Edge Link is a built-in service that provides remote access features such as SSH and RDP through a browser-based interface.

numberMajor CategorySubcategorySubcategoryDetailed DescriptionNoteDocument Link
1Remote AccessAccessing Company PCRemote Desktop AccessProvides a connection feature that allows remote control of the company PC screen through a web browser.
2Accessing the Internal ServerRemote Console AccessProviding a console access environment to input commands to the internal server through a web browser