All Products
Search
Document Center

ApsaraDB for MyBase:Access a Windows host via a bastion host

Last Updated:Jun 20, 2026

This topic describes how to connect to a Windows host by using a bastion host.

Prerequisites

  • The ApsaraDB for MyBase cluster uses the SQL Server engine.
  • OS permissions are enabled for the ApsaraDB for MyBase cluster. For more information, see Create a cluster.
  • A host account is created. For more information, see Create a host account.
Note To connect to a Linux host by using a bastion host, see Connect to a Linux host by using a bastion host.

Authorize a bastion host

  1. Log on to the ApsaraDB for MyBase console.

  2. In the upper-left corner of the page, select a region.

  3. Find the target cluster and click Details in the Actions column.

  4. In the left-side navigation pane, click Bastion Hosts. Find the target bastion host and click Associate with Bastion Host in the Actions column.

  5. Select the target host and click Next.

  6. Create a bastion host account.

    1. Click Create Bastion Host Account. In the Create Bastion Host Account dialog box, configure the following parameters.

      Parameter

      Description

      username

      The username for the bastion host account. The username must meet the following requirements:

      • Must not exceed 50 characters.

      • Must include characters from at least three of the following categories: uppercase letters, lowercase letters, digits, and special characters.

      • The supported special characters are _-.%.

      password

      The password for the bastion host account. The password must meet the following requirements:

      • Must be 8 to 64 characters in length.

      • Must contain uppercase letters, lowercase letters, digits, and special characters.

      • Examples of special characters include @,#,$.

      confirm password

      Re-enter the password to confirm.

      name

      The user's name. The name cannot exceed 100 characters.

      email address

      Optional. The user's email address.

      phone number

      Optional. The user's phone number.

    2. Click Create.

  7. Authorize a host.

    1. Find the target bastion host account and click Authorize Host in the Actions column. This action redirects you to the Bastionhost console.

    2. On the Users page, find the target bastion host account and click Authorize Host in the Actions column.

    3. On the Authorized Hosts tab, click Authorize Host.

    4. In the Authorize Host panel, select the target host and click OK.

      Note

      After the authorization is complete, return to the Authorize Host wizard. In the Authorized Hosts column, click View Authorized Hosts to view the authorized hosts.

Connect via a bastion host

  1. On your local Windows host, open Remote Desktop Connection (Mstsc).

  2. Enter the Bastionhost O&M address and click Connect.

    The O&M address is in the following format: <O&M address>:63389. For example, kagp******-public.bastionhost.aliyuncs.com:63389.

    The default RDP port is 63389. To change the O&M port of the Bastionhost instance, see Configure a bastion host.

  3. In the Remote Desktop Connection dialog box, click Yes.

  4. In the login dialog box, enter your Bastionhost username and password, and then click Login.

  5. If two-factor authentication is enabled for the Bastionhost user, enter the verification code.

    For more information about how to configure two-factor authentication for a Bastionhost user, see Enable two-factor authentication.

  6. Find the host.
    In the connection list of the Main window, find the target host by its Hostname, IP, Username, and Port.
  7. On the asset management page, double-click the host you want to manage to log on to the target host.

    This page lists the connection information for the hosts that you can manage, such as Hostname, IP, Username, and Port.