
Register user (with OTP/TOTP)
Sign mTLS certificate (with USB Bunker)
Configure tunnel (RDP, SSH, OPC UA...)
Apply time-based policies (hours, days, expiration)
Reload configuration (no restart needed)
Tunnel active with dual authentication (mTLS + OTP) and PBAC policies. No cloud dependencies.