LINUXOR.SK ... open source notes ...

Balabit - Communication matrix (site 1)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Logical design and integrations and Modes of operation and connections

noteTwo rows of the out-of-band table send LDAPS to "AD server 2" at 10.11.18.210, which is node B's redundant heartbeat address; the second domain controller is 10.11.16.210. The IPMI rows use SMTPS 465 where the IPMI's own SMTP page says port 25. Do not copy those rows as they are.

The network flows that the design of the site 1 cluster asked to be opened: what the SCB itself needs, how administrators and users reach it, and what the IPMI modules of both appliances need. It is section 6.7 of the design, the four tables as one listing, rows exactly as in the document.

ItemValue
WhatSection 6.7 "Network communications requirements" of the design document
Clusterdc1-s-xblb001, site 1, nodes in datacenters A and B
Firmware at the timeSCB 5 LTS (the design shows 5.0.3)
Source documentDesign document of the site 1 cluster, version 0.5 of 2017-12-01, status draft
Not in itSyslog, SNMP from Sensu, NFS to the storage, the SCB's connections to the jump servers, IPv6, the ports added in 2018

The listing

output 51 lines
## Network communications requirements
### SCB Infrastructure communications
Following table summarizes infrastructure network communications from Balabit SCB appliances deployed in HA mode.
| Protocol | Source | Source Port | Destination | Destination Port | Description |
| UDP/TCP | 10.11.16.81 | 1024:65535 | 10.11.16.145 | 53 | DNS communication from Balabit SCB appliances deployed in HA mode to Infoblox cluster in Datacenter A. |
| UDP/TCP | 10.11.16.81 | 1024:65535 | 10.11.18.145 | 53 | DNS communication from Balabit SCB appliances deployed in HA mode to Infoblox cluster in Datacenter B. |
| UDP | 10.11.16.81 | 1024:65535 | 10.11.16.145 | 123 | NTP communication from Balabit SCB appliances deployed in HA mode to Infoblox cluster in Datacenter A. |
| UDP | 10.11.16.81 | 1024:65535 | 10.11.18.145 | 123 | NTP communication from Balabit SCB appliances deployed in HA mode to Infoblox cluster in Datacenter B. |
| TCP | 10.11.16.81 | 1024:65535 | 10.11.16.209 | 636 | LDAPS communication from Balabit SCB appliances deployed in HA mode to to AD server 1. |
| TCP | 10.11.16.81 | 1024:65535 | 10.11.16.210 | 636 | LDAPS communication from Balabit SCB appliances deployed in HA mode to to AD server 2. |
| TCP | 10.11.16.81 | 1024:65535 | 10.11.19.33 | 25 | SMTP (STARTTLS) communication from Balabit SCB appliances deployed in HA mode to Internal Email server. |

### SCB In-band management communications
Following table summarizes management/administrative network communications to Balabit SCB appliances deployed in HA mode.
| Protocol | Source | Source Port | Destination | Destination Port | Description |
| TCP | ORG_VPN | 1024:65535 | 10.11.16.81 | 443 | HTTPS management communication to Balabit SCB appliances deployed in HA mode. |
| TCP | ORG_VPN | 1024:65535 | 10.11.16.81 | 22 | SSH management communication to Balabit SCB appliances deployed in HA mode. |

### SCB User communications
Following table summarizes user/operation network communications to Balabit SCB appliances deployed in HA mode.
| Protocol | Source | Source Port | Destination | Destination Port | Description |
| TCP | PARTNER1_VPN | 1024:65535 | 10.11.16.65 | 22 | SSH communication to PARTNER1 JumpServers through Balabit SCB appliances deployed in HA mode. |
| TCP | PARTNER1_VPN | 1024:65535 | 10.11.16.65 | 222 | SCP communication to PARTNER1 JumpServers through Balabit SCB appliances deployed in HA mode. |
| TCP | PARTNER1_VPN | 1024:65535 | 10.11.16.65 | 3389 | RDP communication to PARTNER1 JumpServers through Balabit SCB appliances deployed in HA mode. |
| TCP | ORG_VPN | 1024:65535 | 10.11.16.65 | 2201 | SSH communication to ORG JumpServers through Balabit SCB appliances deployed in HA mode. |
| TCP | ORG _VPN | 1024:65535 | 10.11.16.65 | 2202 | RDP communication to ORG JumpServers through Balabit SCB appliances deployed in HA mode. |
| TCP | ORG _VPN | 1024:65535 | 10.11.16.65 | 2203 | SCP communication to ORG JumpServers through Balabit SCB appliances deployed in HA mode. |
| TCP | PARTNER2 _VPN | 1024:65535 | 10.11.16.65 | 2204 | RDP communication to PARTNER2 JumpServers through Balabit SCB appliances deployed in HA mode. |

Note: In first phase will be monitored only access from PARTNER1_VPN segment to the PARTNER1 Jump Servers but solution will be ready to monitor also access from ORG_VPN segment to the ORG Jump Servers.
### SCB Out-of-band communications
Following table summarizes network communications from/to Balabit SCB IPMI module.
| Protocol | Source | Source Port | Destination | Destination Port | Description |
| UDP/TCP | 10.11.15.29 | 1024:65535 | 10.11.16.145 | 	53 | DNS communication from Balabit SCB IPMI module in Datacenter A to Infoblox cluster in Datacenter A. |
| UDP/TCP | 10.11.15.29 | 1024:65535 | 10.11.18.145 | 	53 | DNS communication from Balabit SCB IPMI module in Datacenter A to Infoblox cluster in Datacenter B. |
| UDP/TCP | 10.11.23.29 | 1024:65535 | 10.11.16.145 | 	53 | DNS communication from Balabit SCB IPMI module in Datacenter B to Infoblox cluster in Datacenter A. |
| UDP/TCP | 10.11.23.29 | 1024:65535 | 10.11.18.145 | 	53 | DNS communication from Balabit SCB IPMI module in Datacenter B to Infoblox cluster in Datacenter B. |
| UDP | 10.11.15.29 | 1024:65535 | 10.11.16.145 | 	123 | NTPcommunication from Balabit SCB IPMI module in Datacenter A to Infoblox cluster in Datacenter A. |
| UDP | 10.11.15.29 | 1024:65535 | 10.11.18.145 | 123 | NTP communication from Balabit SCB IPMI module in Datacenter A to Infoblox cluster in Datacenter B. |
| UDP | 10.11.23.29 | 1024:65535 | 10.11.16.145 | 123 | NTP communication from Balabit SCB IPMI module in Datacenter B to Infoblox cluster in Datacenter A. |
| UDP | 10.11.23.29 | 1024:65535 | 10.11.18.145 | 123 | NTP communication from Balabit SCB IPMI module in Datacenter B to Infoblox cluster in Datacenter B. |
| TCP | 10.11.15.29 | 1024:65535 | 10.11.16.209 | 636 | LDAPS communication from Balabit SCB IPMI module in Datacenter A to AD server 1. |
| TCP | 10.11.15.29 | 1024:65535 | 10.11.18.210 | 636 | LDAPS communication from Balabit SCB IPMI module in Datacenter A to AD server 2 |
| TCP | 10.11.23.29 | 1024:65535 | 10.11.16.209 | 636 | LDAPS communication from Balabit SCB IPMI module in Datacenter B to AD server 1. |
| TCP | 10.11.23.29 | 1024:65535 | 10.11.18.210 | 636 | LDAPS communication from Balabit SCB IPMI module in Datacenter B to AD server 2 |
| TCP | 10.11.15.29 | 1024:65535 | 10.11.19.33 | 465 | SMTPS communication from Balabit SCB IPMI module in Datacenter A to Internal Email server. |
| TCP | 10.11.23.29 | 1024:65535 | 10.11.19.33 | 465 | SMTPS communication from Balabit SCB IPMI module in Datacenter B to Internal Email server. |
| TCP | Any | 1024:65535 | 10.11.15.29 | 443 | HTTPS communication to Balabit SCB IPMI module Web interface in Datacenter A. |
| TCP | Any | 1024:65535 | 10.11.23.29 | 443 | HTTPS communication to Balabit SCB IPMI module Web interface in Datacenter B. |
| TCP | Any | 1024:65535 | 10.11.15.29 | 5900 | IKVM (remote presense) communication to Balabit SCB IPMI module Web interface in Datacenter A. |
| TCP | Any | 1024:65535 | 10.11.23.29 | 5900 | IKVM (remote presence) communication to Balabit SCB IPMI module Web interface in Datacenter B. |
Column or valueMeaning
10.11.16.81The SCB cluster's address in the in-band management network (IBM, VLAN 1010); the source of the infrastructure flows and the address of the web interface and SSH console
10.11.16.65The cluster's address in the production network (PRO, VLAN 1009), where every user connection listens; its IPv6 address 2001:db8:a1:c0e::f:1 is not in the table
10.11.15.29, 10.11.23.29The IPMI modules of the appliance in datacenter A and in datacenter B, in the out-of-band network (VLAN 12)
10.11.16.145, 10.11.18.145The Infoblox pair, DNS and NTP
10.11.16.209, 10.11.16.210The two Active Directory domain controllers
10.11.19.33The mail service; in the Email Solution's later plan the virtual address of the internal mail pair
ORG_VPN, PARTNER1_VPN, PARTNER2 _VPNVPN networks named, not given; the SCB's routing table has 10.11.20.0/25 as the "admin VPN segment". The space in ORG _VPN and PARTNER2 _VPN is in the original
222, 2201 to 2204The non-default ports of the user connections, one per partner and protocol; see Modes of operation and connections
5900The IPMI's remote console (written "IKVM (remote presense)" in the first of the two rows)

The matrix describes the design of December 2017. It has no row for syslog to 10.11.17.113 (TCP 514), for the SNMPv3 queries from Sensu at 10.11.16.129, for NFS from the backup address 10.11.18.225 to the NetApp at 10.11.18.236, or for any flow from the SCB to the jump servers. The rows for the IPMI modules let "Any" reach the web interface and the console; nothing in the Source material says how the out-of-band network itself was restricted.

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
Every flow of the SCB itself from an IPv4 address; IPv6 only on the user addressUnchanged: IPv6 is for monitored connections only, local services need IPv4, and syslog, SMTP and backup targets are still entered as IPv4 addresses
LDAPS on TCP 636, server certificate not checked636 is still the port for TLS (389 for STARTTLS); certificate verification against a trust store is available (whether "no check" can still be chosen was not verified), and SHA-1-signed certificates are no longer trusted for LDAP since 6.0.4
SMTP on TCP 25 with STARTTLS, server certificate not checkedSTARTTLS is still offered, with an option to accept only certificates issued by a given CA
Management, user and backup traffic on separate addressesThe vendor recommends a dedicated interface for backups, syslog, SNMP and e-mail alerts, and monitored connections and web administration from separate networks where possible
IPMI modules of the two T-10 appliancesT-Series hardware reached its end of support on 2024-07-31
← solutionz