Balabit - Local services (site 1)
Balabit SCB Solution · Config document · referenced from Basic settings, logging and monitoring
sensu are - in the design: they were not written down, and nothing here is a credential to copy.The services the appliance itself offers, as opposed to the connections it proxies: the SSH server for the console, the two web logins, the SNMP agent that Sensu queries, and the built-in indexer of audit trails. Every listening service is bound to the in-band management address 10.11.16.81 only.
| Item | Value |
|---|---|
| Where | SCB web interface, Basic Settings > Local Services |
| Cluster | dc1-s-xblb001, site 1, both nodes (the setting is cluster-wide) |
| Firmware at the time | 5 LTS (5.0.3) |
| Source | My design document, version 0.5 of 2017-12-01 (draft), chapters 7.2.4 to 7.2.8, "configuration from real implementation realized in production environment" |
| Not in it | The SNMP passwords, any SSH authorized key (none was set), the allowed clients of SSH and web (not restricted) |
The answers
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapters 7.2.4 to 7.2.8 Basic Settings > Local Services > SSH server / ENABLE = Yes Basic Settings > Local Services > SSH server / ENABLE PASSWORD AUTHENTICATION = Yes Basic Settings > Local Services > SSH server / AUTHORIZED KEYS = - Basic Settings > Local Services > SSH server / LISTENING ADDRESSES = Address: 10.11.16.81 (IBM) / Port: 22 Basic Settings > Local Services > SSH server / RESTRICT CLIENTS = No Basic Settings > Local Services > SSH server / PROTECT AGAINST BRUTE-FORCE ATTACKS = Yes Basic Settings > Local Services > Web login (Admin and User) / LISTENING ADDRESSES = Address: 10.11.16.81 (IBM) / HTTP: 80 / HTTPS: 443 Basic Settings > Local Services > Web login (Admin and User) / RESTRICT CLIENTS = No Basic Settings > Local Services > Web login (Admin and User) / PROTECT AGAINST BRUTE-FORCE ATTACKS = Yes Basic Settings > Local Services > Web login (User only) / LISTENING ADDRESSES = - Basic Settings > Local Services > Web login (User only) / RESTRICT CLIENTS = No Basic Settings > Local Services > Web login (User only) / PROTECT AGAINST BRUTE-FORCE ATTACKS = Yes Basic Settings > Local Services > SNMP server settings / ENABLED = Yes Basic Settings > Local Services > SNMP server settings / SYSTEM LOCATION = Site 1 Basic Settings > Local Services > SNMP server settings / SYSTEM CONTACT = Example Org Basic Settings > Local Services > SNMP server settings / SYSTEM DESCRIPTION = Balabit Shell Control Box Basic Settings > Local Services > SNMP server settings / SNMP V2C AGENT = - Basic Settings > Local Services > SNMP server settings / SNMP V3 AGENT = Yes Basic Settings > Local Services > SNMP server settings / ALLOWED USERS = Username: sensu / Auth. method: SHA1 / Auth. password: - / Encryption method: AES / Encryption password: - Basic Settings > Local Services > SNMP server settings / LISTENING ADDRESSES = Address: 10.11.16.81 (IBM) / Port: 161 Basic Settings > Local Services > SNMP server settings / RESTRICT CLIENTS = Yes Basic Settings > Local Services > SNMP server settings / ALLOWED CLIENTS = Address: 10.11.16.129 / Netmask: 255.255.255.255 Basic Settings > Local Services > Indexer service / MAXIMUM PARALLEL AUDIT TRAILS TO INDEX ON BOX = 12 Basic Settings > Local Services > Indexer service / INDEXER KEYS = - Basic Settings > Local Services > Indexer service / ENABLE REMOTE INDEXING = No
| Setting | What it means here |
|---|---|
10.11.16.81 (IBM) | The cluster address in the in-band management network, VLAN 1010 on physical port 1. Nothing local listens on the production address 10.11.16.65, where the users arrive |
| SSH password authentication on, no authorized keys | The console is reached with a password. The design says remote console access is for root; its access table says the only enabled account is admin; see Active Directory and access control |
| Restrict clients No (SSH, web) | Any address that can route to 10.11.16.81 may try to log in. My notes' checklist for this page lists "Restrict Clients (Allowed clients)" under SSH and web, and a TODO names the admin VPN 10.11.20.0/25; the as-built page has no restriction. The design's communication table lists only ORG_VPN as a source for 10.11.16.81; the firewall rules that enforce it are not in my material |
| Brute-force protection | The analysis quotes the vendor's defaults: 20 failed SSH logins block the address for ten minutes, five failed web logins deny further attempts for increasing periods |
Web login (User only) - | No separate login address for users. The analysis recommended one; as I understand it, it was not needed because gateway authentication was not used, so end users never log in to the web interface |
SNMP v2c -, v3 Yes | Only SNMPv3, with one user, sensu, SHA1 authentication and AES encryption |
Allowed clients 10.11.16.129/32 | Only the Sensu server dc1-a-vcsns001 may query. The site 2 configuration allows three addresses, 10.12.16.129, 10.12.16.130 and 10.12.16.131 |
| 12 parallel audit trails | The internal indexer; the appliance reports 24 CPU cores on the Alerting page. No external indexer and no indexer keys |
The site 2 cluster has the same page in its exported config.xml of 2018-09-17 (element <services>): the same SSH and web settings, the same SNMP user and the same 12 indexer workers, with Site 2 as the location and the three client addresses above, which the material does not name. The design document of site 1 does not cover the SSH algorithms of the console here; they are listed in its chapter 8.1.2 (KEX diffie-hellman-group-exchange-sha256, ciphers aes256-ctr,aes128-ctr, MACs hmac-sha2-512,hmac-sha2-256).
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
Console SSH with KEX diffie-hellman-group-exchange-sha256, ciphers aes256-ctr,aes128-ctr, MACs hmac-sha2-512,hmac-sha2-256 | The same three lists are documented unchanged. Since SPS 7.4 the console no longer accepts SHA-1 based signature algorithms and uses RSA/SHA-256/512 (RFC 8332) when the client supports it |
| SSH server enabled for the console | Completing the Welcome Wizard disables SSH access; direct SSH access to the host is "not recommended or supported, except for troubleshooting purposes", and it is switched off automatically in sealed mode |
| Brute-force protection, 20 attempts, ten minutes | Unchanged |
| Local services on the IPv4 management address | Still IPv4 only: IPv6 is for monitored connections, local services including the web login require IPv4 |
| SNMPv3 with SHA1 and AES | Still the only choices: MD5 or SHA1 for authentication, DES or AES for privacy; nothing stronger is documented |
| Internal indexer, 12 parallel trails, OCR in English and two further languages | Internal and external indexers remain. The OCR engine was replaced in 9.0 and the language list changed, so the indexer policy's languages have to be reviewed after an upgrade |
The page would look much the same today. The weak point is not on it: SNMPv3 has not moved past SHA1, so the Sensu user's authentication is as strong as it was in 2017 and no stronger.