LINUXOR.SK ... open source notes ...

Balabit - Networking element of the site 2 config.xml

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Hardware, cabling and networks

The complete <networking> element of the configuration that the site 2 cluster exported into its support bundle: host and domain name, the logical interfaces on the physical ports, the IPv4 and IPv6 routing tables and the DNS servers. It is the site 2 counterpart of the page Network settings (site 1), and the only network configuration of an SCB in my material that comes from the appliance itself rather than from a document.

ItemValue
Fileconfig.xml of the support bundle, element <config> > <xcb> > <networking>
Clusterdc2-s-xblb001, site 2
Firmware5.0.6
Exported2018-09-17 (support bundle of the site 2 cluster)
AnonymizationObject ids shortened to id035 … id040; the addresses are those of the shared address plan

The file

xml
    <networking>
      <ip_forwarding>
        <rules/>
      </ip_forwarding>
      <hostname>dc2-s-xblb001</hostname>
      <nickname>dc2-s-xblb001pro</nickname>
      <domainname>adm.example.net</domainname>
      <nics>
        <nic id="-9000" name="eth0">
          <speed>auto</speed>
          <interfaces>
            <interface id="id035" name="IBM">
              <vlantag>1010</vlantag>
              <addresses>
                <address id="1" family="ipv4">
                  <addr>10.12.16.81</addr>
                  <prefix>29</prefix>
                </address>
              </addresses>
            </interface>
          </interfaces>
        </nic>
        <nic id="-9001" name="eth1">
          <speed>auto</speed>
          <interfaces>
            <interface id="id036" name="PRO">
              <vlantag>1009</vlantag>
              <addresses>
                <address id="id037" family="ipv4">
                  <addr>10.12.16.65</addr>
                  <prefix>29</prefix>
                </address>
                <address id="id038" family="ipv6">
                  <addr>2001:db8:a2:c0e::f:1</addr>
                  <prefix>64</prefix>
                </address>
              </addresses>
            </interface>
          </interfaces>
        </nic>
        <nic id="-9002" name="eth2">
          <speed>auto</speed>
          <interfaces>
            <interface id="id039" name="BCK">
              <vlantag>1020</vlantag>
              <addresses>
                <address id="id040" family="ipv4">
                  <addr>10.12.18.225</addr>
                  <prefix>28</prefix>
                </address>
              </addresses>
            </interface>
          </interfaces>
        </nic>
        <nic id="-9003" name="eth4">
          <speed>auto</speed>
          <interfaces/>
        </nic>
        <nic id="-9004" name="eth5">
          <speed>auto</speed>
          <interfaces/>
        </nic>
      </nics>
      <routing4>
        <route>
          <addr>0.0.0.0</addr>
          <prefix>0</prefix>
          <gateway>10.12.16.70</gateway>
        </route>
        <route>
          <addr>10.19.204.64</addr>
          <prefix>26</prefix>
          <gateway>10.12.16.86</gateway>
        </route>
        <route>
          <addr>10.11.16.128</addr>
          <prefix>28</prefix>
          <gateway>10.12.16.86</gateway>
        </route>
        <route>
          <addr>10.11.16.208</addr>
          <prefix>28</prefix>
          <gateway>10.12.16.86</gateway>
        </route>
        <route>
          <addr>10.11.16.144</addr>
          <prefix>28</prefix>
          <gateway>10.12.16.86</gateway>
        </route>
        <route>
          <addr>10.11.18.144</addr>
          <prefix>28</prefix>
          <gateway>10.12.16.86</gateway>
        </route>
        <route>
          <addr>10.12.17.112</addr>
          <prefix>28</prefix>
          <gateway>10.12.16.86</gateway>
        </route>
        <route>
          <addr>10.11.20.0</addr>
          <prefix>25</prefix>
          <gateway>10.12.16.86</gateway>
        </route>
        <route>
          <addr>10.12.16.192</addr>
          <prefix>28</prefix>
          <gateway>10.12.16.86</gateway>
        </route>
      </routing4>
      <routing6/>
      <dns>
        <primary>10.11.16.145</primary>
        <secondary>10.11.18.145</secondary>
      </dns>
      <bridged/>
    </networking>
ElementWhat it says
<nic name="eth0">, interface IBM, <vlantag>1010</vlantag>, 10.12.16.81/29In-band management on port 1, as in site 1. Its address has the id 1; the SSH server, the administrators' web login and the SNMP agent of the appliance listen on <addr idref="1"/> elsewhere in the file, that is on this address
<nic name="eth1">, interface PRO, VLAN 1009, 10.12.16.65/29 and 2001:db8:a2:c0e::f:1/64The production address that users connect to, IPv4 and IPv6, on port 2
<nic name="eth2">, only interface BCK, VLAN 1020, 10.12.18.225/28Backup and archive towards the NetApp 10.12.18.236. There is no CLS2 interface in VLAN 1018: the site 2 L3 sheet plans 10.12.18.209 and 10.12.18.210 there, but the cluster was built without the redundant heartbeat, which the HA state of the same bundle confirms
eth4, eth5 with empty <interfaces/>The SFP+ ports 5 and 6, unused. eth3, the HA port, does not appear in this element at all
Default route via 10.12.16.70Inside the production network 10.12.16.64/29. The site 1 design has 10.11.17.70, which is in none of the site 1 cluster's networks
Routes via 10.12.16.8610.12.16.86 is in the in-band management network. The routes lead to 10.19.204.64/26 (a network of another site; the material does not say what it is), to the site 1 Sensu, Active Directory and Infoblox segments (10.11.16.128/28, 10.11.16.208/28, 10.11.16.144/28, 10.11.18.144/28), to 10.12.17.112/28 (the site 2 central syslog server 10.12.17.113 is in it), to the admin VPN 10.11.20.0/25, and to 10.12.16.192/28, where the site 2 RDP jump servers 10.12.16.193 and 10.12.16.201 of the connections are
<routing6/>Empty: no IPv6 route at all, where site 1 has a default IPv6 gateway. Whether the appliance learnt one from router advertisements the export does not show
<dns>The site 1 Infoblox appliances 10.11.16.145 and 10.11.18.145, the same as the NTP servers of this cluster
<ip_forwarding> with empty <rules/>, <bridged/>No forwarding rules and no bridged interfaces; as I understand them, these belong to transparent mode, which neither cluster used

Two remarks. The site 2 cluster uses Active Directory and Infoblox of site 1 (the AD servers in this file are dc1-a-vcad001 and dc1-a-vcad002), so its explicit routes point back to site 1; one of them also leads to the site 1 Sensu segment. And the SNMP agent of this cluster accepts queries only from 10.12.16.129, 10.12.16.130 and 10.12.16.131, for which there is no explicit route; replies to them would leave by the default route on the production port. Whether that worked is not recorded.

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
SCB 5.0.6, <nics> with VLAN-tagged <interface> elementsLogical interfaces with their own VLAN IDs are unchanged in SPS 9.0. 5.0.x LTS support was discontinued on 2020-05-28
<ip_forwarding> with no rulesIP forwarding between logical interfaces is how SPS 9.0 replaces the deprecated router mode; the build did not use it
IPv6 address only on PRO, empty <routing6/>IPv6 is still for monitored connections only; local services require IPv4

The format of the exported configuration in 9.0 was not part of the research, so I cannot say whether this element would still look the same.

← solutionz