Balabit - Network settings (site 1)
Balabit SCB Solution · Config document · referenced from Hardware, cabling and networks
noteThe default IPv4 gateway
10.11.17.70 is in none of the networks of the SCB's interfaces as they are listed here, so, as I read it, the appliance could not have reached it. Every other route goes through 10.11.16.86, which is in the in-band management network. See the table below; do not copy the default route without checking it.The page Basic Settings > Network of the site 1 cluster: the logical interfaces on the physical ports, the IPv4 and IPv6 routing tables and the names of the cluster. Physical interface 4 (HA) is not on this page; it belongs to the High availability page.
| Item | Value |
|---|---|
| Where | SCB web interface, Basic Settings > Network (Interfaces, Routing table, Naming) |
| Cluster | dc1-s-xblb001, nodes dc1-a-ablb001 and dc1-b-ablb001 (the addresses marked VIP in the sheet move with the master; 10.11.18.209 is node A's own) |
| Firmware at the time | 5 LTS (5.0.3) |
| Source | My design document, version 0.5 of 2017-12-01 (draft), chapters 7.2.1 to 7.2.3, "configuration from real implementation realized in production environment" |
| Site 2 | The same page as an exported file: the networking element of the site 2 config.xml |
The answers
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapters 7.2.1 to 7.2.3 Basic Settings > Network > Interfaces > Physical Interface 1 / Label on box = EXT (1) Basic Settings > Network > Interfaces > Physical Interface 1 / Speed = Auto negotiation Basic Settings > Network > Interfaces > Physical Interface 1 / VLAN ID = 1010 Basic Settings > Network > Interfaces > Physical Interface 1 / Address = 10.11.16.81 Basic Settings > Network > Interfaces > Physical Interface 1 / Prefix = 29 Basic Settings > Network > Interfaces > Physical Interface 1 / Name = IBM Basic Settings > Network > Interfaces > Physical Interface 1 / System name = eth0.1010 Basic Settings > Network > Interfaces > Physical Interface 2 / Label on box = MGMT (2) Basic Settings > Network > Interfaces > Physical Interface 2 / Speed = Auto negotiation Basic Settings > Network > Interfaces > Physical Interface 2 / VLAN ID = 1009 Basic Settings > Network > Interfaces > Physical Interface 2 / Address = 10.11.16.65 Basic Settings > Network > Interfaces > Physical Interface 2 / Prefix = 29 Basic Settings > Network > Interfaces > Physical Interface 2 / Name = PRO Basic Settings > Network > Interfaces > Physical Interface 2 / System name = eth1.1009 Basic Settings > Network > Interfaces > Physical Interface 2, second address / Address = 2001:db8:a1:c0e::f:1 Basic Settings > Network > Interfaces > Physical Interface 2, second address / Prefix = 64 Basic Settings > Network > Interfaces > Physical Interface 3 / Label on box = INT (3) Basic Settings > Network > Interfaces > Physical Interface 3 / Speed = Auto negotiation Basic Settings > Network > Interfaces > Physical Interface 3 / VLAN ID = 1018 Basic Settings > Network > Interfaces > Physical Interface 3 / Address = 10.11.18.209 Basic Settings > Network > Interfaces > Physical Interface 3 / Prefix = 28 Basic Settings > Network > Interfaces > Physical Interface 3 / Name = CLS2 Basic Settings > Network > Interfaces > Physical Interface 3 / System name = eth2.1018 Basic Settings > Network > Interfaces > Physical Interface 3, second VLAN / VLAN ID = 1020 Basic Settings > Network > Interfaces > Physical Interface 3, second VLAN / Address = 10.11.18.225 Basic Settings > Network > Interfaces > Physical Interface 3, second VLAN / Prefix = 28 Basic Settings > Network > Interfaces > Physical Interface 3, second VLAN / Name = BCK Basic Settings > Network > Interfaces > Physical Interface 3, second VLAN / System name = eth2.1020 Basic Settings > Network > Interfaces > Physical Interface 5 / Label on box = (5) Basic Settings > Network > Interfaces > Physical Interface 5 / Speed = Auto negotiation Basic Settings > Network > Interfaces > Physical Interface 5 / VLAN ID = - Basic Settings > Network > Interfaces > Physical Interface 5 / Address = - Basic Settings > Network > Interfaces > Physical Interface 5 / Prefix = - Basic Settings > Network > Interfaces > Physical Interface 5 / Name = - Basic Settings > Network > Interfaces > Physical Interface 5 / System name = - Basic Settings > Network > Interfaces > Physical Interface 6 / Label on box = (6) Basic Settings > Network > Interfaces > Physical Interface 6 / Speed = Auto negotiation Basic Settings > Network > Interfaces > Physical Interface 6 / VLAN ID = - Basic Settings > Network > Interfaces > Physical Interface 6 / Address = - Basic Settings > Network > Interfaces > Physical Interface 6 / Prefix = - Basic Settings > Network > Interfaces > Physical Interface 6 / Name = - Basic Settings > Network > Interfaces > Physical Interface 6 / System name = - Basic Settings > Network > Routing table > IPv4 route 1 / Network = 0.0.0.0 Basic Settings > Network > Routing table > IPv4 route 1 / Prefix = 0 Basic Settings > Network > Routing table > IPv4 route 1 / Gateway = 10.11.17.70 Basic Settings > Network > Routing table > IPv4 route 1 / Description = Default IPv4 gateway. Basic Settings > Network > Routing table > IPv4 route 2 / Network = 10.11.20.0 Basic Settings > Network > Routing table > IPv4 route 2 / Prefix = 25 Basic Settings > Network > Routing table > IPv4 route 2 / Gateway = 10.11.16.86 Basic Settings > Network > Routing table > IPv4 route 2 / Description = Route to admin VPN segment. Basic Settings > Network > Routing table > IPv4 route 3 / Network = 10.11.16.128 Basic Settings > Network > Routing table > IPv4 route 3 / Prefix = 28 Basic Settings > Network > Routing table > IPv4 route 3 / Gateway = 10.11.16.86 Basic Settings > Network > Routing table > IPv4 route 3 / Description = Route to Sensu segment. Basic Settings > Network > Routing table > IPv4 route 4 / Network = 10.11.16.208 Basic Settings > Network > Routing table > IPv4 route 4 / Prefix = 28 Basic Settings > Network > Routing table > IPv4 route 4 / Gateway = 10.11.16.86 Basic Settings > Network > Routing table > IPv4 route 4 / Description = Route to AD segment. Basic Settings > Network > Routing table > IPv4 route 5 / Network = 10.11.16.144 Basic Settings > Network > Routing table > IPv4 route 5 / Prefix = 28 Basic Settings > Network > Routing table > IPv4 route 5 / Gateway = 10.11.16.86 Basic Settings > Network > Routing table > IPv4 route 5 / Description = Route to InfoBlox segment - datacenter A. Basic Settings > Network > Routing table > IPv4 route 6 / Network = 10.11.18.144 Basic Settings > Network > Routing table > IPv4 route 6 / Prefix = 28 Basic Settings > Network > Routing table > IPv4 route 6 / Gateway = 10.11.16.86 Basic Settings > Network > Routing table > IPv4 route 6 / Description = Route to InfoBlox segment - datacenter B. Basic Settings > Network > Routing table > IPv6 route 1 / Network = :: Basic Settings > Network > Routing table > IPv6 route 1 / Prefix = 0 Basic Settings > Network > Routing table > IPv6 route 1 / Gateway = 2001:db8:a1:c0e::1 Basic Settings > Network > Routing table > IPv6 route 1 / Description = Default IPv6 gateway. Basic Settings > Network > Naming / HOSTNAME = dc1-s-xblb001 Basic Settings > Network > Naming / NICKNAME = dc1-s-xblb001pro Basic Settings > Network > Naming / DNS SEARCH DOMAIN = adm.example.net Basic Settings > Network > Naming / PRIMARY DNS SERVER = 10.11.16.145 Basic Settings > Network > Naming / SECONDARY DNS SERVER = 10.11.18.145
| Answer | What it means |
|---|---|
Label on box EXT (1) with Name IBM | The labels printed on the appliance and the roles given to the ports cross over: port 1, labelled EXT, carries the in-band management network (IBM) where administrators reach the web interface and SSH; port 2, labelled MGMT, carries the production network (PRO) where the users' sessions arrive. The labels are the vendor's; the design's interface names follow the roles |
VLAN ID with System name eth0.1010 | Every logical interface is VLAN-tagged on its port; the switch ports are trunks, see the switch port configuration |
| Physical Interface 3, two VLANs | The redundant heartbeat (CLS2, VLAN 1018) and the backup and archive network towards the NetApp (BCK, VLAN 1020) share port 3. 10.11.18.209 is node A's own address; node B's 10.11.18.210 is set on the High availability page |
| Physical Interfaces 5 and 6 | The two SFP+ ports; not used |
IPv4 route 1, Gateway 10.11.17.70 | Outside 10.11.16.80/29, 10.11.16.64/29, 10.11.18.208/28 and 10.11.18.224/28. The exported configuration of the site 2 cluster has 10.12.16.70 as its default gateway, which is inside its production network 10.12.16.64/29; by analogy, 10.11.16.70 in the site 1 production network was probably meant here. That is my inference; the material holds no site 1 export to check it |
Routes 2 to 6 via 10.11.16.86 | Admin VPN, Sensu, Active Directory and both Infoblox segments are reached through a gateway in the in-band management network; as I read it, so that replies to administrators and the infrastructure traffic leave by port 1 and not by the default route |
NICKNAME dc1-s-xblb001pro | The same string as the name the L3 sheet gives to the production address 10.11.16.65, dc1-s-xblb001pro.adm.example.net; the design does not say what the nickname was used for |
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
| Balabit SCB 5 LTS (5.0.3) on SCB T-10 appliances | The product is One Identity Safeguard for Privileged Sessions (SPS); 9.0 is the current release (September 2026). 5.0.x LTS support was discontinued on 2020-05-28, T-Series hardware reached End of Support on 2024-07-31, and SPS 8.0 is not supported on T-Series |
| VLAN-tagged logical interfaces on physical ports 1 to 3 | Unchanged: any number of logical interfaces per physical interface, each with its own VLAN ID. New note: SPS does not support two hosts using the same IP address on different VLAN groups |
| Management (IBM) and user traffic (PRO) on separate networks | The security checklist recommends exactly that: monitored connections and administrative access should originate from separate networks |
| IPv6 only on the production interface | Still the rule: IPv6 is for monitored connections; local services, the web login included, require IPv4 |
| SFP+ ports 5 and 6 unused | On the current 3500 and 4000 appliances the SFP+ ports are available for proxy traffic and local services |
Nothing on this page would be configured differently for that reason alone; the platform under it is what is gone. Moving off a T-10 means new hardware and the vendor's data migration between SPS instances, not an in-place upgrade.