Balabit - Networking element of the site 2 config.xml
Balabit SCB Solution · Config document · referenced from Hardware, cabling and networks
The complete <networking> element of the configuration that the site 2 cluster exported into its support bundle: host and domain name, the logical interfaces on the physical ports, the IPv4 and IPv6 routing tables and the DNS servers. It is the site 2 counterpart of the page Network settings (site 1), and the only network configuration of an SCB in my material that comes from the appliance itself rather than from a document.
| Item | Value |
|---|---|
| File | config.xml of the support bundle, element <config> > <xcb> > <networking> |
| Cluster | dc2-s-xblb001, site 2 |
| Firmware | 5.0.6 |
| Exported | 2018-09-17 (support bundle of the site 2 cluster) |
| Anonymization | Object ids shortened to id035 … id040; the addresses are those of the shared address plan |
The file
<networking> <ip_forwarding> <rules/> </ip_forwarding> <hostname>dc2-s-xblb001</hostname> <nickname>dc2-s-xblb001pro</nickname> <domainname>adm.example.net</domainname> <nics> <nic id="-9000" name="eth0"> <speed>auto</speed> <interfaces> <interface id="id035" name="IBM"> <vlantag>1010</vlantag> <addresses> <address id="1" family="ipv4"> <addr>10.12.16.81</addr> <prefix>29</prefix> </address> </addresses> </interface> </interfaces> </nic> <nic id="-9001" name="eth1"> <speed>auto</speed> <interfaces> <interface id="id036" name="PRO"> <vlantag>1009</vlantag> <addresses> <address id="id037" family="ipv4"> <addr>10.12.16.65</addr> <prefix>29</prefix> </address> <address id="id038" family="ipv6"> <addr>2001:db8:a2:c0e::f:1</addr> <prefix>64</prefix> </address> </addresses> </interface> </interfaces> </nic> <nic id="-9002" name="eth2"> <speed>auto</speed> <interfaces> <interface id="id039" name="BCK"> <vlantag>1020</vlantag> <addresses> <address id="id040" family="ipv4"> <addr>10.12.18.225</addr> <prefix>28</prefix> </address> </addresses> </interface> </interfaces> </nic> <nic id="-9003" name="eth4"> <speed>auto</speed> <interfaces/> </nic> <nic id="-9004" name="eth5"> <speed>auto</speed> <interfaces/> </nic> </nics> <routing4> <route> <addr>0.0.0.0</addr> <prefix>0</prefix> <gateway>10.12.16.70</gateway> </route> <route> <addr>10.19.204.64</addr> <prefix>26</prefix> <gateway>10.12.16.86</gateway> </route> <route> <addr>10.11.16.128</addr> <prefix>28</prefix> <gateway>10.12.16.86</gateway> </route> <route> <addr>10.11.16.208</addr> <prefix>28</prefix> <gateway>10.12.16.86</gateway> </route> <route> <addr>10.11.16.144</addr> <prefix>28</prefix> <gateway>10.12.16.86</gateway> </route> <route> <addr>10.11.18.144</addr> <prefix>28</prefix> <gateway>10.12.16.86</gateway> </route> <route> <addr>10.12.17.112</addr> <prefix>28</prefix> <gateway>10.12.16.86</gateway> </route> <route> <addr>10.11.20.0</addr> <prefix>25</prefix> <gateway>10.12.16.86</gateway> </route> <route> <addr>10.12.16.192</addr> <prefix>28</prefix> <gateway>10.12.16.86</gateway> </route> </routing4> <routing6/> <dns> <primary>10.11.16.145</primary> <secondary>10.11.18.145</secondary> </dns> <bridged/> </networking>
| Element | What it says |
|---|---|
<nic name="eth0">, interface IBM, <vlantag>1010</vlantag>, 10.12.16.81/29 | In-band management on port 1, as in site 1. Its address has the id 1; the SSH server, the administrators' web login and the SNMP agent of the appliance listen on <addr idref="1"/> elsewhere in the file, that is on this address |
<nic name="eth1">, interface PRO, VLAN 1009, 10.12.16.65/29 and 2001:db8:a2:c0e::f:1/64 | The production address that users connect to, IPv4 and IPv6, on port 2 |
<nic name="eth2">, only interface BCK, VLAN 1020, 10.12.18.225/28 | Backup and archive towards the NetApp 10.12.18.236. There is no CLS2 interface in VLAN 1018: the site 2 L3 sheet plans 10.12.18.209 and 10.12.18.210 there, but the cluster was built without the redundant heartbeat, which the HA state of the same bundle confirms |
eth4, eth5 with empty <interfaces/> | The SFP+ ports 5 and 6, unused. eth3, the HA port, does not appear in this element at all |
Default route via 10.12.16.70 | Inside the production network 10.12.16.64/29. The site 1 design has 10.11.17.70, which is in none of the site 1 cluster's networks |
Routes via 10.12.16.86 | 10.12.16.86 is in the in-band management network. The routes lead to 10.19.204.64/26 (a network of another site; the material does not say what it is), to the site 1 Sensu, Active Directory and Infoblox segments (10.11.16.128/28, 10.11.16.208/28, 10.11.16.144/28, 10.11.18.144/28), to 10.12.17.112/28 (the site 2 central syslog server 10.12.17.113 is in it), to the admin VPN 10.11.20.0/25, and to 10.12.16.192/28, where the site 2 RDP jump servers 10.12.16.193 and 10.12.16.201 of the connections are |
<routing6/> | Empty: no IPv6 route at all, where site 1 has a default IPv6 gateway. Whether the appliance learnt one from router advertisements the export does not show |
<dns> | The site 1 Infoblox appliances 10.11.16.145 and 10.11.18.145, the same as the NTP servers of this cluster |
<ip_forwarding> with empty <rules/>, <bridged/> | No forwarding rules and no bridged interfaces; as I understand them, these belong to transparent mode, which neither cluster used |
Two remarks. The site 2 cluster uses Active Directory and Infoblox of site 1 (the AD servers in this file are dc1-a-vcad001 and dc1-a-vcad002), so its explicit routes point back to site 1; one of them also leads to the site 1 Sensu segment. And the SNMP agent of this cluster accepts queries only from 10.12.16.129, 10.12.16.130 and 10.12.16.131, for which there is no explicit route; replies to them would leave by the default route on the production port. Whether that worked is not recorded.
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
SCB 5.0.6, <nics> with VLAN-tagged <interface> elements | Logical interfaces with their own VLAN IDs are unchanged in SPS 9.0. 5.0.x LTS support was discontinued on 2020-05-28 |
<ip_forwarding> with no rules | IP forwarding between logical interfaces is how SPS 9.0 replaces the deprecated router mode; the build did not use it |
IPv6 address only on PRO, empty <routing6/> | IPv6 is still for monitored connections only; local services require IPv4 |
The format of the exported configuration in 9.0 was not part of the research, so I cannot say whether this element would still look the same.