LINUXOR.SK ... open source notes ...

Balabit - Local services (site 1)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Basic settings, logging and monitoring

noteThe SNMP passwords of the user sensu are - in the design: they were not written down, and nothing here is a credential to copy.

The services the appliance itself offers, as opposed to the connections it proxies: the SSH server for the console, the two web logins, the SNMP agent that Sensu queries, and the built-in indexer of audit trails. Every listening service is bound to the in-band management address 10.11.16.81 only.

ItemValue
WhereSCB web interface, Basic Settings > Local Services
Clusterdc1-s-xblb001, site 1, both nodes (the setting is cluster-wide)
Firmware at the time5 LTS (5.0.3)
SourceMy design document, version 0.5 of 2017-12-01 (draft), chapters 7.2.4 to 7.2.8, "configuration from real implementation realized in production environment"
Not in itThe SNMP passwords, any SSH authorized key (none was set), the allowed clients of SSH and web (not restricted)

The answers

ini
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapters 7.2.4 to 7.2.8

Basic Settings > Local Services > SSH server / ENABLE = Yes
Basic Settings > Local Services > SSH server / ENABLE PASSWORD AUTHENTICATION = Yes
Basic Settings > Local Services > SSH server / AUTHORIZED KEYS = -
Basic Settings > Local Services > SSH server / LISTENING ADDRESSES = Address: 10.11.16.81 (IBM) / Port: 22
Basic Settings > Local Services > SSH server / RESTRICT CLIENTS = No
Basic Settings > Local Services > SSH server / PROTECT AGAINST BRUTE-FORCE ATTACKS = Yes

Basic Settings > Local Services > Web login (Admin and User) / LISTENING ADDRESSES = Address: 10.11.16.81 (IBM) / HTTP: 80 / HTTPS: 443
Basic Settings > Local Services > Web login (Admin and User) / RESTRICT CLIENTS = No
Basic Settings > Local Services > Web login (Admin and User) / PROTECT AGAINST BRUTE-FORCE ATTACKS = Yes

Basic Settings > Local Services > Web login (User only) / LISTENING ADDRESSES = -
Basic Settings > Local Services > Web login (User only) / RESTRICT CLIENTS = No
Basic Settings > Local Services > Web login (User only) / PROTECT AGAINST BRUTE-FORCE ATTACKS = Yes

Basic Settings > Local Services > SNMP server settings / ENABLED = Yes
Basic Settings > Local Services > SNMP server settings / SYSTEM LOCATION = Site 1
Basic Settings > Local Services > SNMP server settings / SYSTEM CONTACT = Example Org
Basic Settings > Local Services > SNMP server settings / SYSTEM DESCRIPTION = Balabit Shell Control Box
Basic Settings > Local Services > SNMP server settings / SNMP V2C AGENT = -
Basic Settings > Local Services > SNMP server settings / SNMP V3 AGENT = Yes
Basic Settings > Local Services > SNMP server settings / ALLOWED USERS = Username: sensu / Auth. method: SHA1 / Auth. password: - / Encryption method: AES / Encryption password: -
Basic Settings > Local Services > SNMP server settings / LISTENING ADDRESSES = Address: 10.11.16.81 (IBM) / Port: 161
Basic Settings > Local Services > SNMP server settings / RESTRICT CLIENTS = Yes
Basic Settings > Local Services > SNMP server settings / ALLOWED CLIENTS = Address: 10.11.16.129 / Netmask: 255.255.255.255

Basic Settings > Local Services > Indexer service / MAXIMUM PARALLEL AUDIT TRAILS TO INDEX ON BOX = 12
Basic Settings > Local Services > Indexer service / INDEXER KEYS = -
Basic Settings > Local Services > Indexer service / ENABLE REMOTE INDEXING = No
SettingWhat it means here
10.11.16.81 (IBM)The cluster address in the in-band management network, VLAN 1010 on physical port 1. Nothing local listens on the production address 10.11.16.65, where the users arrive
SSH password authentication on, no authorized keysThe console is reached with a password. The design says remote console access is for root; its access table says the only enabled account is admin; see Active Directory and access control
Restrict clients No (SSH, web)Any address that can route to 10.11.16.81 may try to log in. My notes' checklist for this page lists "Restrict Clients (Allowed clients)" under SSH and web, and a TODO names the admin VPN 10.11.20.0/25; the as-built page has no restriction. The design's communication table lists only ORG_VPN as a source for 10.11.16.81; the firewall rules that enforce it are not in my material
Brute-force protectionThe analysis quotes the vendor's defaults: 20 failed SSH logins block the address for ten minutes, five failed web logins deny further attempts for increasing periods
Web login (User only) -No separate login address for users. The analysis recommended one; as I understand it, it was not needed because gateway authentication was not used, so end users never log in to the web interface
SNMP v2c -, v3 YesOnly SNMPv3, with one user, sensu, SHA1 authentication and AES encryption
Allowed clients 10.11.16.129/32Only the Sensu server dc1-a-vcsns001 may query. The site 2 configuration allows three addresses, 10.12.16.129, 10.12.16.130 and 10.12.16.131
12 parallel audit trailsThe internal indexer; the appliance reports 24 CPU cores on the Alerting page. No external indexer and no indexer keys

The site 2 cluster has the same page in its exported config.xml of 2018-09-17 (element <services>): the same SSH and web settings, the same SNMP user and the same 12 indexer workers, with Site 2 as the location and the three client addresses above, which the material does not name. The design document of site 1 does not cover the SSH algorithms of the console here; they are listed in its chapter 8.1.2 (KEX diffie-hellman-group-exchange-sha256, ciphers aes256-ctr,aes128-ctr, MACs hmac-sha2-512,hmac-sha2-256).

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
Console SSH with KEX diffie-hellman-group-exchange-sha256, ciphers aes256-ctr,aes128-ctr, MACs hmac-sha2-512,hmac-sha2-256The same three lists are documented unchanged. Since SPS 7.4 the console no longer accepts SHA-1 based signature algorithms and uses RSA/SHA-256/512 (RFC 8332) when the client supports it
SSH server enabled for the consoleCompleting the Welcome Wizard disables SSH access; direct SSH access to the host is "not recommended or supported, except for troubleshooting purposes", and it is switched off automatically in sealed mode
Brute-force protection, 20 attempts, ten minutesUnchanged
Local services on the IPv4 management addressStill IPv4 only: IPv6 is for monitored connections, local services including the web login require IPv4
SNMPv3 with SHA1 and AESStill the only choices: MD5 or SHA1 for authentication, DES or AES for privacy; nothing stronger is documented
Internal indexer, 12 parallel trails, OCR in English and two further languagesInternal and external indexers remain. The OCR engine was replaced in 9.0 and the language list changed, so the indexer policy's languages have to be reviewed after an upgrade

The page would look much the same today. The weak point is not on it: SNMPv3 has not moved past SHA1, so the Sensu user's authentication is as strong as it was in 2017 and no stronger.

← solutionz