Balabit - Connections in config.xml (site 2)
Balabit SCB Solution · Config document · referenced from Connection and channel policies
[removed sensitive data] is how the appliance itself writes a secret into a support bundle; here it stands for the RSA host key the SCB presents to SSH clients on each connection (as I understand it, its private part, which is why the appliance removed it). The file is from 2018-09-17: connections that the connection summary marks as configured in site 2 but that are missing here (partner 4 SCP/SFTP on 2213, the cloud team of partner 1 on 2210 to 2212) were added later or never.The <pol_connections> element of the exported configuration of the site 2 cluster: four SSH and four RDP connection policies, with every reference to the settings, channel, backup, archive, LDAP, indexer and audit policies as object ids. Unlike the tables of the site 1 design, this is what the appliance really ran.
| Item | Value |
|---|---|
| File | config.xml, the configuration export inside a support bundle |
| Cluster | dc2-s-xblb001, production address 10.12.16.65 and 2001:db8:a2:c0e::f:1 |
| Taken | 2018-09-17, firmware 5.0.6 |
| Element | <pol_connections>, child of <scb>, complete |
| Anonymization | Object ids shortened (id056 …); addresses and names follow the anonymized plan of this write-up |
| Site 2 design | None exists |
The file
<pol_connections> <connections proto="telnet"/> <connections proto="vnc"/> <connections proto="ica"/> <connections proto="http"/> <connections proto="ssh"> <connection id="id056" name="PARTNER1_SSH_JumpServer" enabled="yes"> <from> <network family="ipv4"> <addr>0.0.0.0</addr> <prefix>0</prefix> </network> <network family="ipv6"> <addr>::</addr> <prefix>0</prefix> </network> </from> <to> <network family="ipv4"> <addr>10.12.16.65</addr> <prefix>32</prefix> </network> <network family="ipv6"> <addr>2001:db8:a2:c0e::f:1</addr> <prefix>128</prefix> </network> </to> <ports> <port>22</port> </ports> <target choice="inband"> <domains> <domain port="22">10.12.17.81</domain> <domain port="22">2001:db8:a1:f94::/64</domain> <domain port="22">2001:db8:b1:f94::/64</domain> <domain port="22">2001:db8:a2:f94::/64</domain> <domain port="22">2001:db8:10de:f94::/64</domain> <domain port="22">2001:db8:215e:f94::/64</domain> <domain port="22">2001:db8:21de:f94::/64</domain> <domain port="22">2001:db8:315e:f94::/64</domain> <domain port="22">2001:db8:31de:f94::/64</domain> <domain port="22">2001:db8:325e:f94::/64</domain> <domain port="22">2001:db8:32de:f94::/64</domain> </domains> <dns_server/> </target> <snat choice="non-transparent"/> <server_host_key_plain choice="yes"> <server_key_check>accept-once</server_key_check> </server_host_key_plain> <server_host_key_x509 choice="no"/> <client_host_key_plain choice="yes"> <rsa_key type="rsa">[removed sensitive data]</rsa_key> </client_host_key_plain> <client_host_key_x509 choice="no"/> <authentication idref="-200"/> <channel idref="id047"/> <settings idref="id041"/> <backup idref="id028"/> <archive idref="id032"/> <ldap idref="id057"/> <indexing enabled="yes"> <level>2</level> <policy idref="-50000"/> </indexing> <audit idref="id058"/> <access/> <gwauth enabled="no" sameip="no"> <groups/> </gwauth> <log_audit_trail_downloads enabled="yes"/> </connection> <connection id="id059" name="ORG_SSH_JumpServer" enabled="yes"> <from> <network family="ipv4"> <addr>0.0.0.0</addr> <prefix>0</prefix> </network> <network family="ipv6"> <addr>::</addr> <prefix>0</prefix> </network> </from> <to> <network family="ipv4"> <addr>10.12.16.65</addr> <prefix>32</prefix> </network> <network family="ipv6"> <addr>2001:db8:a2:c0e::f:1</addr> <prefix>128</prefix> </network> </to> <ports> <port>2201</port> </ports> <target choice="inband"> <domains> <domain port="22">10.12.16.177</domain> <domain port="22">2001:db8:a1:f95::/64</domain> <domain port="22">2001:db8:b1:f95::/64</domain> <domain port="22">2001:db8:a2:f95::/64</domain> <domain port="22">2001:db8:10de:f95::/64</domain> <domain port="22">2001:db8:215e:f95::/64</domain> <domain port="22">2001:db8:21de:f95::/64</domain> <domain port="22">2001:db8:315e:f95::/64</domain> <domain port="22">2001:db8:31de:f95::/64</domain> <domain port="22">2001:db8:325e:f95::/64</domain> <domain port="22">2001:db8:32de:f95::/64</domain> </domains> <dns_server/> </target> <snat choice="non-transparent"/> <server_host_key_plain choice="yes"> <server_key_check>accept-once</server_key_check> </server_host_key_plain> <server_host_key_x509 choice="no"/> <client_host_key_plain choice="yes"> <rsa_key type="rsa">[removed sensitive data]</rsa_key> </client_host_key_plain> <client_host_key_x509 choice="no"/> <authentication idref="-200"/> <channel idref="id049"/> <settings idref="id042"/> <backup idref="id027"/> <archive idref="id031"/> <ldap idref="id057"/> <indexing enabled="yes"> <level>2</level> <policy idref="-50000"/> </indexing> <audit idref="id058"/> <access/> <gwauth enabled="no" sameip="no"> <groups/> </gwauth> <log_audit_trail_downloads enabled="yes"/> </connection> <connection id="id060" name="PARTNER1_SCP_SFTP_JumpServer" enabled="yes"> <from> <network family="ipv4"> <addr>0.0.0.0</addr> <prefix>0</prefix> </network> <network family="ipv6"> <addr>::</addr> <prefix>0</prefix> </network> </from> <to> <network family="ipv4"> <addr>10.12.16.65</addr> <prefix>32</prefix> </network> <network family="ipv6"> <addr>2001:db8:a2:c0e::f:1</addr> <prefix>128</prefix> </network> </to> <ports> <port>222</port> </ports> <target choice="inband"> <domains> <domain port="22">10.12.17.129</domain> </domains> <dns_server/> </target> <snat choice="non-transparent"/> <server_host_key_plain choice="yes"> <server_key_check>accept-once</server_key_check> </server_host_key_plain> <server_host_key_x509 choice="no"/> <client_host_key_plain choice="yes"> <rsa_key type="rsa">[removed sensitive data]</rsa_key> </client_host_key_plain> <client_host_key_x509 choice="no"/> <authentication idref="-200"/> <channel idref="id050"/> <settings idref="id041"/> <backup idref="id028"/> <archive idref="id032"/> <ldap idref="id057"/> <indexing enabled="yes"> <level>2</level> <policy idref="-50000"/> </indexing> <audit idref="id058"/> <access/> <gwauth enabled="no" sameip="no"> <groups/> </gwauth> <log_audit_trail_downloads enabled="yes"/> </connection> <connection id="id061" name="ORG_SCP_SFTP_JumpServer" enabled="yes"> <from> <network family="ipv4"> <addr>0.0.0.0</addr> <prefix>0</prefix> </network> <network family="ipv6"> <addr>::</addr> <prefix>0</prefix> </network> </from> <to> <network family="ipv4"> <addr>10.12.16.65</addr> <prefix>32</prefix> </network> <network family="ipv6"> <addr>2001:db8:a2:c0e::f:1</addr> <prefix>128</prefix> </network> </to> <ports> <port>2203</port> </ports> <target choice="inband"> <domains> <domain port="22">10.12.17.129</domain> </domains> <dns_server/> </target> <snat choice="non-transparent"/> <server_host_key_plain choice="yes"> <server_key_check>accept-once</server_key_check> </server_host_key_plain> <server_host_key_x509 choice="no"/> <client_host_key_plain choice="yes"> <rsa_key type="rsa">[removed sensitive data]</rsa_key> </client_host_key_plain> <client_host_key_x509 choice="no"/> <authentication idref="-200"/> <channel idref="id051"/> <settings idref="id042"/> <backup idref="id027"/> <archive idref="id031"/> <ldap idref="id057"/> <indexing enabled="yes"> <level>2</level> <policy idref="-50000"/> </indexing> <audit idref="id058"/> <access/> <gwauth enabled="no" sameip="no"> <groups/> </gwauth> <log_audit_trail_downloads enabled="yes"/> </connection> </connections> <connections proto="rdp"> <connection id="id062" name="PARTNER1_RDP_JumpServer" enabled="yes"> <from> <network family="ipv4"> <addr>0.0.0.0</addr> <prefix>0</prefix> </network> <network family="ipv6"> <addr>::</addr> <prefix>0</prefix> </network> </from> <to> <network family="ipv4"> <addr>10.12.16.65</addr> <prefix>32</prefix> </network> <network family="ipv6"> <addr>2001:db8:a2:c0e::f:1</addr> <prefix>128</prefix> </network> </to> <ports> <port>3389</port> </ports> <target choice="inband"> <domains> <domain port="3389">10.12.16.201</domain> </domains> <dns_server/> </target> <snat choice="non-transparent"/> <act_as_ts_gw choice="no"/> <server_certificate_check choice="no"/> <channel idref="id052"/> <settings idref="id043"/> <backup idref="id028"/> <archive idref="id032"/> <ldap idref="id057"/> <indexing enabled="yes"> <level>2</level> <policy idref="-50000"/> </indexing> <audit idref="id058"/> <access/> <gwauth enabled="no" sameip="no"> <groups/> </gwauth> <log_audit_trail_downloads enabled="yes"/> </connection> <connection id="id063" name="ORG_RDP_JumpServer" enabled="yes"> <from> <network family="ipv4"> <addr>0.0.0.0</addr> <prefix>0</prefix> </network> <network family="ipv6"> <addr>::</addr> <prefix>0</prefix> </network> </from> <to> <network family="ipv4"> <addr>10.12.16.65</addr> <prefix>32</prefix> </network> <network family="ipv6"> <addr>2001:db8:a2:c0e::f:1</addr> <prefix>128</prefix> </network> </to> <ports> <port>2202</port> </ports> <target choice="inband"> <domains> <domain port="3389">10.12.16.193</domain> </domains> <dns_server/> </target> <snat choice="non-transparent"/> <act_as_ts_gw choice="no"/> <server_certificate_check choice="no"/> <channel idref="id053"/> <settings idref="id044"/> <backup idref="id027"/> <archive idref="id031"/> <ldap idref="id057"/> <indexing enabled="yes"> <level>2</level> <policy idref="-50000"/> </indexing> <audit idref="id058"/> <access/> <gwauth enabled="no" sameip="no"> <groups/> </gwauth> <log_audit_trail_downloads enabled="yes"/> </connection> <connection id="id064" name="PARTNER2_RDP_JumpServer" enabled="yes"> <from> <network family="ipv4"> <addr>10.19.204.192</addr> <prefix>26</prefix> </network> <network family="ipv6"> <addr>::</addr> <prefix>0</prefix> </network> </from> <to> <network family="ipv4"> <addr>10.12.16.65</addr> <prefix>32</prefix> </network> <network family="ipv6"> <addr>2001:db8:a2:c0e::f:1</addr> <prefix>128</prefix> </network> </to> <ports> <port>2204</port> </ports> <target choice="inband"> <domains> <domain port="3389">10.12.19.177</domain> <domain port="3389">2001:db8:a2:b5f::f:1</domain> </domains> <dns_server/> </target> <snat choice="non-transparent"/> <act_as_ts_gw choice="no"/> <server_certificate_check choice="no"/> <channel idref="id054"/> <settings idref="id045"/> <backup idref="id029"/> <archive idref="id033"/> <ldap idref="id057"/> <indexing enabled="yes"> <level>2</level> <policy idref="-50000"/> </indexing> <audit idref="id058"/> <access/> <gwauth enabled="no" sameip="no"> <groups/> </gwauth> <log_audit_trail_downloads enabled="yes"/> </connection> <connection id="id065" name="PARTNER4_RDP_JumpServer" enabled="yes"> <from> <network family="ipv4"> <addr>0.0.0.0</addr> <prefix>0</prefix> </network> <network family="ipv6"> <addr>::</addr> <prefix>0</prefix> </network> </from> <to> <network family="ipv4"> <addr>10.12.16.65</addr> <prefix>32</prefix> </network> <network family="ipv6"> <addr>2001:db8:a2:c0e::f:1</addr> <prefix>128</prefix> </network> </to> <ports> <port>2208</port> </ports> <target choice="inband"> <domains> <domain port="3389">10.12.19.209</domain> <domain port="3389">2001:db8:a2:b5d::a:1</domain> </domains> <dns_server/> </target> <snat choice="non-transparent"/> <act_as_ts_gw choice="no"/> <server_certificate_check choice="no"/> <channel idref="id055"/> <settings idref="id046"/> <backup idref="id030"/> <archive idref="id034"/> <ldap idref="id057"/> <indexing enabled="yes"> <level>2</level> <policy idref="-50000"/> </indexing> <audit idref="id058"/> <access/> <gwauth enabled="no" sameip="no"> <groups/> </gwauth> <log_audit_trail_downloads enabled="yes"/> </connection> </connections> </pol_connections>
The object ids resolve to these names elsewhere in the same file:
| Id | Object |
|---|---|
id041, id042 | SSH settings PARTNER1_SSH, ORG_SSH |
id043 … id046 | RDP settings PARTNER1_RDP, ORG_RDP, PARTNER2_RDP, PARTNER4_RDP |
id047, id049 | SSH channel policies PARTNER1-SSH-ONLY, ORG-SSH-ONLY (shell with content policy no-WINSCP, X11) |
id050, id051 | SSH channel policies PARTNER1-SCP-SFTP-ONLY, ORG-SCP-SFTP-only (SCP, SFTP) |
id052 … id055 | RDP channel policies PARTNER1-TERMINAL-ONLY, ORG-TERMINAL-ONLY, PARTNER2-TERMINAL-ONLY, PARTNER4-TERMINAL-ONLY |
id027 … id030 | Backup policies ORG-BACKUP, PARTNER1-BACKUP, PARTNER2-BACKUP, PARTNER4-BACKUP |
id031 … id034 | Archive/cleanup policies ORG-ARCHIVE, PARTNER1-ARCHIVE, PARTNER2-ARCHIVE, PARTNER4-ARCHIVE (the policies) |
id057 | LDAP server policy AD.EXAMPLE.NET, pointing to the site 1 domain controllers |
id058 | Audit policy default |
-200 | Built-in SSH authentication policy base |
-50000 | Built-in indexer policy default |
The elements that are not obvious from their names:
| Element | What it means |
|---|---|
<target choice="inband">, <domain port="…"> | Inband destination selection with the allowed targets and their ports |
<snat choice="non-transparent"/> | Source NAT to the SCB's address, the "USE THE IP ADDRESS OF SCB = Yes" of the site 1 design (my reading of the value) |
<server_key_check>accept-once</server_key_check> | "Accept key for the first time" |
<indexing enabled="yes">, <level>2</level> | Indexing on; the site 1 design shows "priority normal", and I assume level 2 is that |
<access/>, <gwauth enabled="no"> | No four-eyes access rules, no gateway authentication |
What differs from the site 1 design: the SCP/SFTP connections reference the SCP/SFTP channel policies; ORG_SSH_JumpServer listens on 2201, where the connection summary has 2210 for IPv4 and 2201 for IPv6; PARTNER2_RDP_JumpServer accepts IPv4 clients only from 10.19.204.192/26; PARTNER4_RDP_JumpServer (2208, to 10.12.19.209 and 2001:db8:a2:b5d::a:1) accepts any client, where the connection summary gives 10.12.20.0/27.
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
<server_host_key_x509 choice="no"/>, <client_host_key_x509 choice="no"/> | X.509 host certificates for SSH have been removed |
<rsa_key type="rsa"> host key | ssh-rsa is "Not recommended" and will be disabled in a future release; RSA with SHA-2 signatures or Ed25519 remain |
<server_key_check>accept-once</server_key_check> | The checklist asks for host key verification in SSH connection policies |
<snat choice="non-transparent"/> | Using the SPS logical interface address is still the default |
<gwauth enabled="no"> | The checklist: "Always use gateway authentication to authenticate clients." |
<server_certificate_check choice="no"/> (RDP) | SPS refuses RDP to Windows servers with SHA-1 signed certificates |
The structure of a connection policy is the same in SPS 9.0; the SSH host key options are where this element would need work.