
lwz8v (lwz8v) asked a question.
I have ASA agent installed on my bastion hosts and other internal servers.
Have configured servers to use bastion hosts, so that I am able to ssh to these internal servers via bastion host from my client machine.
Now I wanted to to first ssh to bastion host, do some activity, then ssh to other internal server which is managed by ASA.
I am having trouble to make it work, How can I forward the ephemeral certificates used by client to bastion host connectivity and use same for bastion to internal server ssh?

Hello Parvez,
Are all the servers enrolled as per the following KB ? -https://help.okta.com/en/prod/Content/Topics/Adv_Server_Access/docs/sftd.htm
If everything is done as per the above document I recommend raising a support ticket with details of the flow so that it can be further looked into.