LINUXOR.SK ... open source notes ...

Balabit - Connections in config.xml (site 2)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Connection and channel policies

note[removed sensitive data] is how the appliance itself writes a secret into a support bundle; here it stands for the RSA host key the SCB presents to SSH clients on each connection (as I understand it, its private part, which is why the appliance removed it). The file is from 2018-09-17: connections that the connection summary marks as configured in site 2 but that are missing here (partner 4 SCP/SFTP on 2213, the cloud team of partner 1 on 2210 to 2212) were added later or never.

The <pol_connections> element of the exported configuration of the site 2 cluster: four SSH and four RDP connection policies, with every reference to the settings, channel, backup, archive, LDAP, indexer and audit policies as object ids. Unlike the tables of the site 1 design, this is what the appliance really ran.

ItemValue
Fileconfig.xml, the configuration export inside a support bundle
Clusterdc2-s-xblb001, production address 10.12.16.65 and 2001:db8:a2:c0e::f:1
Taken2018-09-17, firmware 5.0.6
Element<pol_connections>, child of <scb>, complete
AnonymizationObject ids shortened (id056 …); addresses and names follow the anonymized plan of this write-up
Site 2 designNone exists

The file

xml
    <pol_connections>
      <connections proto="telnet"/>
      <connections proto="vnc"/>
      <connections proto="ica"/>
      <connections proto="http"/>
      <connections proto="ssh">
        <connection id="id056" name="PARTNER1_SSH_JumpServer" enabled="yes">
          <from>
            <network family="ipv4">
              <addr>0.0.0.0</addr>
              <prefix>0</prefix>
            </network>
            <network family="ipv6">
              <addr>::</addr>
              <prefix>0</prefix>
            </network>
          </from>
          <to>
            <network family="ipv4">
              <addr>10.12.16.65</addr>
              <prefix>32</prefix>
            </network>
            <network family="ipv6">
              <addr>2001:db8:a2:c0e::f:1</addr>
              <prefix>128</prefix>
            </network>
          </to>
          <ports>
            <port>22</port>
          </ports>
          <target choice="inband">
            <domains>
              <domain port="22">10.12.17.81</domain>
              <domain port="22">2001:db8:a1:f94::/64</domain>
              <domain port="22">2001:db8:b1:f94::/64</domain>
              <domain port="22">2001:db8:a2:f94::/64</domain>
              <domain port="22">2001:db8:10de:f94::/64</domain>
              <domain port="22">2001:db8:215e:f94::/64</domain>
              <domain port="22">2001:db8:21de:f94::/64</domain>
              <domain port="22">2001:db8:315e:f94::/64</domain>
              <domain port="22">2001:db8:31de:f94::/64</domain>
              <domain port="22">2001:db8:325e:f94::/64</domain>
              <domain port="22">2001:db8:32de:f94::/64</domain>
            </domains>
            <dns_server/>
          </target>
          <snat choice="non-transparent"/>
          <server_host_key_plain choice="yes">
            <server_key_check>accept-once</server_key_check>
          </server_host_key_plain>
          <server_host_key_x509 choice="no"/>
          <client_host_key_plain choice="yes">
            <rsa_key type="rsa">[removed sensitive data]</rsa_key>
          </client_host_key_plain>
          <client_host_key_x509 choice="no"/>
          <authentication idref="-200"/>
          <channel idref="id047"/>
          <settings idref="id041"/>
          <backup idref="id028"/>
          <archive idref="id032"/>
          <ldap idref="id057"/>
          <indexing enabled="yes">
            <level>2</level>
            <policy idref="-50000"/>
          </indexing>
          <audit idref="id058"/>
          <access/>
          <gwauth enabled="no" sameip="no">
            <groups/>
          </gwauth>
          <log_audit_trail_downloads enabled="yes"/>
        </connection>
        <connection id="id059" name="ORG_SSH_JumpServer" enabled="yes">
          <from>
            <network family="ipv4">
              <addr>0.0.0.0</addr>
              <prefix>0</prefix>
            </network>
            <network family="ipv6">
              <addr>::</addr>
              <prefix>0</prefix>
            </network>
          </from>
          <to>
            <network family="ipv4">
              <addr>10.12.16.65</addr>
              <prefix>32</prefix>
            </network>
            <network family="ipv6">
              <addr>2001:db8:a2:c0e::f:1</addr>
              <prefix>128</prefix>
            </network>
          </to>
          <ports>
            <port>2201</port>
          </ports>
          <target choice="inband">
            <domains>
              <domain port="22">10.12.16.177</domain>
              <domain port="22">2001:db8:a1:f95::/64</domain>
              <domain port="22">2001:db8:b1:f95::/64</domain>
              <domain port="22">2001:db8:a2:f95::/64</domain>
              <domain port="22">2001:db8:10de:f95::/64</domain>
              <domain port="22">2001:db8:215e:f95::/64</domain>
              <domain port="22">2001:db8:21de:f95::/64</domain>
              <domain port="22">2001:db8:315e:f95::/64</domain>
              <domain port="22">2001:db8:31de:f95::/64</domain>
              <domain port="22">2001:db8:325e:f95::/64</domain>
              <domain port="22">2001:db8:32de:f95::/64</domain>
            </domains>
            <dns_server/>
          </target>
          <snat choice="non-transparent"/>
          <server_host_key_plain choice="yes">
            <server_key_check>accept-once</server_key_check>
          </server_host_key_plain>
          <server_host_key_x509 choice="no"/>
          <client_host_key_plain choice="yes">
            <rsa_key type="rsa">[removed sensitive data]</rsa_key>
          </client_host_key_plain>
          <client_host_key_x509 choice="no"/>
          <authentication idref="-200"/>
          <channel idref="id049"/>
          <settings idref="id042"/>
          <backup idref="id027"/>
          <archive idref="id031"/>
          <ldap idref="id057"/>
          <indexing enabled="yes">
            <level>2</level>
            <policy idref="-50000"/>
          </indexing>
          <audit idref="id058"/>
          <access/>
          <gwauth enabled="no" sameip="no">
            <groups/>
          </gwauth>
          <log_audit_trail_downloads enabled="yes"/>
        </connection>
        <connection id="id060" name="PARTNER1_SCP_SFTP_JumpServer" enabled="yes">
          <from>
            <network family="ipv4">
              <addr>0.0.0.0</addr>
              <prefix>0</prefix>
            </network>
            <network family="ipv6">
              <addr>::</addr>
              <prefix>0</prefix>
            </network>
          </from>
          <to>
            <network family="ipv4">
              <addr>10.12.16.65</addr>
              <prefix>32</prefix>
            </network>
            <network family="ipv6">
              <addr>2001:db8:a2:c0e::f:1</addr>
              <prefix>128</prefix>
            </network>
          </to>
          <ports>
            <port>222</port>
          </ports>
          <target choice="inband">
            <domains>
              <domain port="22">10.12.17.129</domain>
            </domains>
            <dns_server/>
          </target>
          <snat choice="non-transparent"/>
          <server_host_key_plain choice="yes">
            <server_key_check>accept-once</server_key_check>
          </server_host_key_plain>
          <server_host_key_x509 choice="no"/>
          <client_host_key_plain choice="yes">
            <rsa_key type="rsa">[removed sensitive data]</rsa_key>
          </client_host_key_plain>
          <client_host_key_x509 choice="no"/>
          <authentication idref="-200"/>
          <channel idref="id050"/>
          <settings idref="id041"/>
          <backup idref="id028"/>
          <archive idref="id032"/>
          <ldap idref="id057"/>
          <indexing enabled="yes">
            <level>2</level>
            <policy idref="-50000"/>
          </indexing>
          <audit idref="id058"/>
          <access/>
          <gwauth enabled="no" sameip="no">
            <groups/>
          </gwauth>
          <log_audit_trail_downloads enabled="yes"/>
        </connection>
        <connection id="id061" name="ORG_SCP_SFTP_JumpServer" enabled="yes">
          <from>
            <network family="ipv4">
              <addr>0.0.0.0</addr>
              <prefix>0</prefix>
            </network>
            <network family="ipv6">
              <addr>::</addr>
              <prefix>0</prefix>
            </network>
          </from>
          <to>
            <network family="ipv4">
              <addr>10.12.16.65</addr>
              <prefix>32</prefix>
            </network>
            <network family="ipv6">
              <addr>2001:db8:a2:c0e::f:1</addr>
              <prefix>128</prefix>
            </network>
          </to>
          <ports>
            <port>2203</port>
          </ports>
          <target choice="inband">
            <domains>
              <domain port="22">10.12.17.129</domain>
            </domains>
            <dns_server/>
          </target>
          <snat choice="non-transparent"/>
          <server_host_key_plain choice="yes">
            <server_key_check>accept-once</server_key_check>
          </server_host_key_plain>
          <server_host_key_x509 choice="no"/>
          <client_host_key_plain choice="yes">
            <rsa_key type="rsa">[removed sensitive data]</rsa_key>
          </client_host_key_plain>
          <client_host_key_x509 choice="no"/>
          <authentication idref="-200"/>
          <channel idref="id051"/>
          <settings idref="id042"/>
          <backup idref="id027"/>
          <archive idref="id031"/>
          <ldap idref="id057"/>
          <indexing enabled="yes">
            <level>2</level>
            <policy idref="-50000"/>
          </indexing>
          <audit idref="id058"/>
          <access/>
          <gwauth enabled="no" sameip="no">
            <groups/>
          </gwauth>
          <log_audit_trail_downloads enabled="yes"/>
        </connection>
      </connections>
      <connections proto="rdp">
        <connection id="id062" name="PARTNER1_RDP_JumpServer" enabled="yes">
          <from>
            <network family="ipv4">
              <addr>0.0.0.0</addr>
              <prefix>0</prefix>
            </network>
            <network family="ipv6">
              <addr>::</addr>
              <prefix>0</prefix>
            </network>
          </from>
          <to>
            <network family="ipv4">
              <addr>10.12.16.65</addr>
              <prefix>32</prefix>
            </network>
            <network family="ipv6">
              <addr>2001:db8:a2:c0e::f:1</addr>
              <prefix>128</prefix>
            </network>
          </to>
          <ports>
            <port>3389</port>
          </ports>
          <target choice="inband">
            <domains>
              <domain port="3389">10.12.16.201</domain>
            </domains>
            <dns_server/>
          </target>
          <snat choice="non-transparent"/>
          <act_as_ts_gw choice="no"/>
          <server_certificate_check choice="no"/>
          <channel idref="id052"/>
          <settings idref="id043"/>
          <backup idref="id028"/>
          <archive idref="id032"/>
          <ldap idref="id057"/>
          <indexing enabled="yes">
            <level>2</level>
            <policy idref="-50000"/>
          </indexing>
          <audit idref="id058"/>
          <access/>
          <gwauth enabled="no" sameip="no">
            <groups/>
          </gwauth>
          <log_audit_trail_downloads enabled="yes"/>
        </connection>
        <connection id="id063" name="ORG_RDP_JumpServer" enabled="yes">
          <from>
            <network family="ipv4">
              <addr>0.0.0.0</addr>
              <prefix>0</prefix>
            </network>
            <network family="ipv6">
              <addr>::</addr>
              <prefix>0</prefix>
            </network>
          </from>
          <to>
            <network family="ipv4">
              <addr>10.12.16.65</addr>
              <prefix>32</prefix>
            </network>
            <network family="ipv6">
              <addr>2001:db8:a2:c0e::f:1</addr>
              <prefix>128</prefix>
            </network>
          </to>
          <ports>
            <port>2202</port>
          </ports>
          <target choice="inband">
            <domains>
              <domain port="3389">10.12.16.193</domain>
            </domains>
            <dns_server/>
          </target>
          <snat choice="non-transparent"/>
          <act_as_ts_gw choice="no"/>
          <server_certificate_check choice="no"/>
          <channel idref="id053"/>
          <settings idref="id044"/>
          <backup idref="id027"/>
          <archive idref="id031"/>
          <ldap idref="id057"/>
          <indexing enabled="yes">
            <level>2</level>
            <policy idref="-50000"/>
          </indexing>
          <audit idref="id058"/>
          <access/>
          <gwauth enabled="no" sameip="no">
            <groups/>
          </gwauth>
          <log_audit_trail_downloads enabled="yes"/>
        </connection>
        <connection id="id064" name="PARTNER2_RDP_JumpServer" enabled="yes">
          <from>
            <network family="ipv4">
              <addr>10.19.204.192</addr>
              <prefix>26</prefix>
            </network>
            <network family="ipv6">
              <addr>::</addr>
              <prefix>0</prefix>
            </network>
          </from>
          <to>
            <network family="ipv4">
              <addr>10.12.16.65</addr>
              <prefix>32</prefix>
            </network>
            <network family="ipv6">
              <addr>2001:db8:a2:c0e::f:1</addr>
              <prefix>128</prefix>
            </network>
          </to>
          <ports>
            <port>2204</port>
          </ports>
          <target choice="inband">
            <domains>
              <domain port="3389">10.12.19.177</domain>
              <domain port="3389">2001:db8:a2:b5f::f:1</domain>
            </domains>
            <dns_server/>
          </target>
          <snat choice="non-transparent"/>
          <act_as_ts_gw choice="no"/>
          <server_certificate_check choice="no"/>
          <channel idref="id054"/>
          <settings idref="id045"/>
          <backup idref="id029"/>
          <archive idref="id033"/>
          <ldap idref="id057"/>
          <indexing enabled="yes">
            <level>2</level>
            <policy idref="-50000"/>
          </indexing>
          <audit idref="id058"/>
          <access/>
          <gwauth enabled="no" sameip="no">
            <groups/>
          </gwauth>
          <log_audit_trail_downloads enabled="yes"/>
        </connection>
        <connection id="id065" name="PARTNER4_RDP_JumpServer" enabled="yes">
          <from>
            <network family="ipv4">
              <addr>0.0.0.0</addr>
              <prefix>0</prefix>
            </network>
            <network family="ipv6">
              <addr>::</addr>
              <prefix>0</prefix>
            </network>
          </from>
          <to>
            <network family="ipv4">
              <addr>10.12.16.65</addr>
              <prefix>32</prefix>
            </network>
            <network family="ipv6">
              <addr>2001:db8:a2:c0e::f:1</addr>
              <prefix>128</prefix>
            </network>
          </to>
          <ports>
            <port>2208</port>
          </ports>
          <target choice="inband">
            <domains>
              <domain port="3389">10.12.19.209</domain>
              <domain port="3389">2001:db8:a2:b5d::a:1</domain>
            </domains>
            <dns_server/>
          </target>
          <snat choice="non-transparent"/>
          <act_as_ts_gw choice="no"/>
          <server_certificate_check choice="no"/>
          <channel idref="id055"/>
          <settings idref="id046"/>
          <backup idref="id030"/>
          <archive idref="id034"/>
          <ldap idref="id057"/>
          <indexing enabled="yes">
            <level>2</level>
            <policy idref="-50000"/>
          </indexing>
          <audit idref="id058"/>
          <access/>
          <gwauth enabled="no" sameip="no">
            <groups/>
          </gwauth>
          <log_audit_trail_downloads enabled="yes"/>
        </connection>
      </connections>
    </pol_connections>

The object ids resolve to these names elsewhere in the same file:

IdObject
id041, id042SSH settings PARTNER1_SSH, ORG_SSH
id043 … id046RDP settings PARTNER1_RDP, ORG_RDP, PARTNER2_RDP, PARTNER4_RDP
id047, id049SSH channel policies PARTNER1-SSH-ONLY, ORG-SSH-ONLY (shell with content policy no-WINSCP, X11)
id050, id051SSH channel policies PARTNER1-SCP-SFTP-ONLY, ORG-SCP-SFTP-only (SCP, SFTP)
id052 … id055RDP channel policies PARTNER1-TERMINAL-ONLY, ORG-TERMINAL-ONLY, PARTNER2-TERMINAL-ONLY, PARTNER4-TERMINAL-ONLY
id027 … id030Backup policies ORG-BACKUP, PARTNER1-BACKUP, PARTNER2-BACKUP, PARTNER4-BACKUP
id031 … id034Archive/cleanup policies ORG-ARCHIVE, PARTNER1-ARCHIVE, PARTNER2-ARCHIVE, PARTNER4-ARCHIVE (the policies)
id057LDAP server policy AD.EXAMPLE.NET, pointing to the site 1 domain controllers
id058Audit policy default
-200Built-in SSH authentication policy base
-50000Built-in indexer policy default

The elements that are not obvious from their names:

ElementWhat it means
<target choice="inband">, <domain port="…">Inband destination selection with the allowed targets and their ports
<snat choice="non-transparent"/>Source NAT to the SCB's address, the "USE THE IP ADDRESS OF SCB = Yes" of the site 1 design (my reading of the value)
<server_key_check>accept-once</server_key_check>"Accept key for the first time"
<indexing enabled="yes">, <level>2</level>Indexing on; the site 1 design shows "priority normal", and I assume level 2 is that
<access/>, <gwauth enabled="no">No four-eyes access rules, no gateway authentication

What differs from the site 1 design: the SCP/SFTP connections reference the SCP/SFTP channel policies; ORG_SSH_JumpServer listens on 2201, where the connection summary has 2210 for IPv4 and 2201 for IPv6; PARTNER2_RDP_JumpServer accepts IPv4 clients only from 10.19.204.192/26; PARTNER4_RDP_JumpServer (2208, to 10.12.19.209 and 2001:db8:a2:b5d::a:1) accepts any client, where the connection summary gives 10.12.20.0/27.

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
<server_host_key_x509 choice="no"/>, <client_host_key_x509 choice="no"/>X.509 host certificates for SSH have been removed
<rsa_key type="rsa"> host keyssh-rsa is "Not recommended" and will be disabled in a future release; RSA with SHA-2 signatures or Ed25519 remain
<server_key_check>accept-once</server_key_check>The checklist asks for host key verification in SSH connection policies
<snat choice="non-transparent"/>Using the SPS logical interface address is still the default
<gwauth enabled="no">The checklist: "Always use gateway authentication to authenticate clients."
<server_certificate_check choice="no"/> (RDP)SPS refuses RDP to Windows servers with SHA-1 signed certificates

The structure of a connection policy is the same in SPS 9.0; the SSH host key options are where this element would need work.

← solutionz