You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将Azure虚拟机接入企业VPN并实现应用RDP自动化?

Got it, let's walk through setting up this solution step by step—we need your Azure Windows Server 2016 VM (running UiPath) to connect to the customer's SSTP VPN, RDP into their internal VM for automation, and still keep your ability to remote into the Azure VM itself. Here's how to pull it off:

Step 1: Configure the SSTP VPN Client on Azure VM

Windows Server 2016 has a built-in SSTP client, so no extra software is needed. Follow these steps to set up the connection:

  • Open Network and Sharing Center (search it in the Start menu), then click Set up a new connection or network.
  • Select Connect to a workplace and click Next.
  • Choose Use my Internet connection (VPN).
  • Enter the VPN address vpn.customer.com, give the connection a clear name (like Customer-SSTP-VPN), check Allow other people to use this connection (critical for UiPath's service account to access it), then click Create.
  • Right-click the new VPN connection, select Properties:
    • Go to the Security tab: Confirm VPN type is set to SSTP, and data encryption is set to Require encryption (disconnect if server declines).
    • Click Advanced settings: Make sure Use pre-shared key for authentication is unchecked (since you're using username/password auth).
    • Switch to the Networking tab: Uncheck Internet Protocol Version 6 (TCP/IPv6) (optional, reduces potential conflicts). Double-click Internet Protocol Version 4 (TCP/IPv4), click Advanced, then uncheck "Use default gateway on remote network". This is non-negotiable—if you leave this checked, all traffic from the Azure VM will route through the VPN, and your remote RDP connection to the Azure VM will drop.
Step 2: Automate VPN Connection for UiPath

UiPath needs to automatically establish the VPN before accessing the internal VM. Here's how to handle this securely:

  • Use Windows' built-in rasdial command to trigger the VPN connection. Create a batch file (e.g., Connect-Customer-VPN.bat) with:
    rasdial "Customer-SSTP-VPN" "your-vpn-username" "your-vpn-password"
    
  • To avoid hardcoding passwords (never a good idea), store the VPN credentials in Windows Credential Manager:
    1. Open Credential Manager from the Start menu, go to Windows Credentials.
    2. Click Add a Windows credential.
    3. Enter the Internet/network address as vpn.customer.com, then input your VPN username and password. Save it.
      Now you can simplify the rasdial command to:
    rasdial "Customer-SSTP-VPN" "your-vpn-username"
    
  • In your UiPath workflow, use the Invoke Process activity to run this batch file. Ensure the UiRobot service is running under an account with permissions to create VPN connections (local admin is safe here).
Step 3: Set Up RDP Automation to the Customer's Internal VM

Once the VPN is connected, UiPath can access the internal VM via RDP:

  • First, confirm the customer has whitelisted the Azure VM's VPN-assigned IP address in their internal VM's RDP allow list (or their network firewall allows RDP traffic from that IP).
  • In UiPath, you can use either the built-in Remote Desktop activity, or run the mstsc.exe command via Invoke Process:
    mstsc /v:internal-vm-ip-or-hostname /u:internal-vm-username /p:internal-vm-password
    
  • For secure password handling, store the internal VM's credentials in UiPath's Credential Store or Windows Credential Manager, then reference them in your workflow instead of hardcoding.
  • If the customer uses a non-default RDP port (not 3389), add it to the command: mstsc /v:internal-vm-ip:custom-port
Step 4: Keep Your Remote Access to the Azure VM Intact

We already addressed the critical default gateway setting in Step 1, but double-check these to avoid losing access:

  • Verify your Azure NSG (Network Security Group) allows inbound traffic on your Azure VM's RDP port (default 3389) from your local IP address.
  • If you use a custom RDP port for the Azure VM, ensure it's open in both the NSG and the Azure VM's Windows Firewall.
  • Test this: After connecting the VPN, try remote-desktoping into the Azure VM—you should still connect without issues.
Step 5: Troubleshooting Common Hiccups
  • VPN connection fails: Double-check your VPN credentials, confirm the customer's VPN gateway allows the Azure VM's public IP, and ensure SSTP is enabled on the Azure VM (it's default on Server 2016).
  • Can't RDP to internal VM: Ping the internal VM's IP from the Azure VM (command line: ping internal-vm-ip) to confirm VPN connectivity. Ask the customer to verify their internal firewall allows RDP from the Azure VM's VPN IP, and that RDP is enabled on the internal VM.
  • UiRobot can't connect VPN: Check that the UiRobot service account has permission to create VPN connections. Test running the batch file manually under that account to confirm it works.
  • Azure VM RDP drops after VPN connects: Go back to Step 1 and make sure you unchecked "Use default gateway on remote network" in the VPN's IPv4 settings—this is the most common cause of this issue.

内容的提问来源于stack exchange,提问作者sebastian87

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 03:33:38