PortaOne Support can access PortaBilling/PortaSwitch installations to monitor systems and troubleshoot issues. This article explains how access is secured, ensuring service providers retain full control and visibility.
Access to the installation is established through PortaOne's internal access servers. To connect, the support team uses key-based or password authentication combined with an individual one-time password (OTP). These access servers route all connections to the service provider's installation and are fully redundant.
Remote access methods
The support team uses two types of access:
- SSH protocol v2 – for remote access to the servers in the installation. Authentication uses key-based credentials.
- HTTPS (via PortaOne corporate proxy) – for accessing the web interface in a browser. The proxy routes traffic between the support team's device and the installation.
For stricter access control (e.g., due to corporate security policies or legal requirements), a VPN connection can be set up between the service provider's installation and PortaOne access servers instead of the default direct access. See how to configure site-to-site VPN tunnels for PortaSwitch here.
Dedicated users for the support team
Dedicated users are created for the support team to access the admin web interface, the configuration server web interface, and the command-line interface (SSH). This enables PortaOne Support to centrally manage access parameters such as support team passwords and IP restrictions.
These user passwords are reset automatically on a regular basis. If other security measures are already in place (like access only via VPN), user passwords may be changed less frequently.
Support team permissions and activity logs
After the initial setup, the pre-created entities (such as tariffs, products, and a customer) allow the support team to verify system operation. During troubleshooting, additional entities may be created. However, the support team never modifies any entities created by your administrators. Any other actions, such as configuration changes or service restarts that may disrupt the provided services, are performed only with the service provider’s approval.
All actions and connection activity are logged both on PortaOne access servers and on the service provider's installation, including SSH sessions, HTTPS access, and entity creation/modification.
The support team communicates only with the service provider’s team members authorized in the issue tracking system. New users are added to that list only after approval by the authorised service provider's staff.

