LINUXOR.SK ... open source notes ...

Balabit - Network settings (site 1)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Hardware, cabling and networks

noteThe default IPv4 gateway 10.11.17.70 is in none of the networks of the SCB's interfaces as they are listed here, so, as I read it, the appliance could not have reached it. Every other route goes through 10.11.16.86, which is in the in-band management network. See the table below; do not copy the default route without checking it.

The page Basic Settings > Network of the site 1 cluster: the logical interfaces on the physical ports, the IPv4 and IPv6 routing tables and the names of the cluster. Physical interface 4 (HA) is not on this page; it belongs to the High availability page.

ItemValue
WhereSCB web interface, Basic Settings > Network (Interfaces, Routing table, Naming)
Clusterdc1-s-xblb001, nodes dc1-a-ablb001 and dc1-b-ablb001 (the addresses marked VIP in the sheet move with the master; 10.11.18.209 is node A's own)
Firmware at the time5 LTS (5.0.3)
SourceMy design document, version 0.5 of 2017-12-01 (draft), chapters 7.2.1 to 7.2.3, "configuration from real implementation realized in production environment"
Site 2The same page as an exported file: the networking element of the site 2 config.xml

The answers

ini
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapters 7.2.1 to 7.2.3

Basic Settings > Network > Interfaces > Physical Interface 1 / Label on box = EXT (1)
Basic Settings > Network > Interfaces > Physical Interface 1 / Speed = Auto negotiation
Basic Settings > Network > Interfaces > Physical Interface 1 / VLAN ID = 1010
Basic Settings > Network > Interfaces > Physical Interface 1 / Address = 10.11.16.81
Basic Settings > Network > Interfaces > Physical Interface 1 / Prefix = 29
Basic Settings > Network > Interfaces > Physical Interface 1 / Name = IBM
Basic Settings > Network > Interfaces > Physical Interface 1 / System name = eth0.1010

Basic Settings > Network > Interfaces > Physical Interface 2 / Label on box = MGMT (2)
Basic Settings > Network > Interfaces > Physical Interface 2 / Speed = Auto negotiation
Basic Settings > Network > Interfaces > Physical Interface 2 / VLAN ID = 1009
Basic Settings > Network > Interfaces > Physical Interface 2 / Address = 10.11.16.65
Basic Settings > Network > Interfaces > Physical Interface 2 / Prefix = 29
Basic Settings > Network > Interfaces > Physical Interface 2 / Name = PRO
Basic Settings > Network > Interfaces > Physical Interface 2 / System name = eth1.1009
Basic Settings > Network > Interfaces > Physical Interface 2, second address / Address = 2001:db8:a1:c0e::f:1
Basic Settings > Network > Interfaces > Physical Interface 2, second address / Prefix = 64

Basic Settings > Network > Interfaces > Physical Interface 3 / Label on box = INT (3)
Basic Settings > Network > Interfaces > Physical Interface 3 / Speed = Auto negotiation
Basic Settings > Network > Interfaces > Physical Interface 3 / VLAN ID = 1018
Basic Settings > Network > Interfaces > Physical Interface 3 / Address = 10.11.18.209
Basic Settings > Network > Interfaces > Physical Interface 3 / Prefix = 28
Basic Settings > Network > Interfaces > Physical Interface 3 / Name = CLS2
Basic Settings > Network > Interfaces > Physical Interface 3 / System name = eth2.1018
Basic Settings > Network > Interfaces > Physical Interface 3, second VLAN / VLAN ID = 1020
Basic Settings > Network > Interfaces > Physical Interface 3, second VLAN / Address = 10.11.18.225
Basic Settings > Network > Interfaces > Physical Interface 3, second VLAN / Prefix = 28
Basic Settings > Network > Interfaces > Physical Interface 3, second VLAN / Name = BCK
Basic Settings > Network > Interfaces > Physical Interface 3, second VLAN / System name = eth2.1020

Basic Settings > Network > Interfaces > Physical Interface 5 / Label on box = (5)
Basic Settings > Network > Interfaces > Physical Interface 5 / Speed = Auto negotiation
Basic Settings > Network > Interfaces > Physical Interface 5 / VLAN ID = -
Basic Settings > Network > Interfaces > Physical Interface 5 / Address = -
Basic Settings > Network > Interfaces > Physical Interface 5 / Prefix = -
Basic Settings > Network > Interfaces > Physical Interface 5 / Name = -
Basic Settings > Network > Interfaces > Physical Interface 5 / System name = -

Basic Settings > Network > Interfaces > Physical Interface 6 / Label on box = (6)
Basic Settings > Network > Interfaces > Physical Interface 6 / Speed = Auto negotiation
Basic Settings > Network > Interfaces > Physical Interface 6 / VLAN ID = -
Basic Settings > Network > Interfaces > Physical Interface 6 / Address = -
Basic Settings > Network > Interfaces > Physical Interface 6 / Prefix = -
Basic Settings > Network > Interfaces > Physical Interface 6 / Name = -
Basic Settings > Network > Interfaces > Physical Interface 6 / System name = -

Basic Settings > Network > Routing table > IPv4 route 1 / Network = 0.0.0.0
Basic Settings > Network > Routing table > IPv4 route 1 / Prefix = 0
Basic Settings > Network > Routing table > IPv4 route 1 / Gateway = 10.11.17.70
Basic Settings > Network > Routing table > IPv4 route 1 / Description = Default IPv4 gateway.
Basic Settings > Network > Routing table > IPv4 route 2 / Network = 10.11.20.0
Basic Settings > Network > Routing table > IPv4 route 2 / Prefix = 25
Basic Settings > Network > Routing table > IPv4 route 2 / Gateway = 10.11.16.86
Basic Settings > Network > Routing table > IPv4 route 2 / Description = Route to admin VPN segment.
Basic Settings > Network > Routing table > IPv4 route 3 / Network = 10.11.16.128
Basic Settings > Network > Routing table > IPv4 route 3 / Prefix = 28
Basic Settings > Network > Routing table > IPv4 route 3 / Gateway = 10.11.16.86
Basic Settings > Network > Routing table > IPv4 route 3 / Description = Route to Sensu segment.
Basic Settings > Network > Routing table > IPv4 route 4 / Network = 10.11.16.208
Basic Settings > Network > Routing table > IPv4 route 4 / Prefix = 28
Basic Settings > Network > Routing table > IPv4 route 4 / Gateway = 10.11.16.86
Basic Settings > Network > Routing table > IPv4 route 4 / Description = Route to AD segment.
Basic Settings > Network > Routing table > IPv4 route 5 / Network = 10.11.16.144
Basic Settings > Network > Routing table > IPv4 route 5 / Prefix = 28
Basic Settings > Network > Routing table > IPv4 route 5 / Gateway = 10.11.16.86
Basic Settings > Network > Routing table > IPv4 route 5 / Description = Route to InfoBlox segment - datacenter A.
Basic Settings > Network > Routing table > IPv4 route 6 / Network = 10.11.18.144
Basic Settings > Network > Routing table > IPv4 route 6 / Prefix = 28
Basic Settings > Network > Routing table > IPv4 route 6 / Gateway = 10.11.16.86
Basic Settings > Network > Routing table > IPv4 route 6 / Description = Route to InfoBlox segment - datacenter B.
Basic Settings > Network > Routing table > IPv6 route 1 / Network = ::
Basic Settings > Network > Routing table > IPv6 route 1 / Prefix = 0
Basic Settings > Network > Routing table > IPv6 route 1 / Gateway = 2001:db8:a1:c0e::1
Basic Settings > Network > Routing table > IPv6 route 1 / Description = Default IPv6 gateway.

Basic Settings > Network > Naming / HOSTNAME = dc1-s-xblb001
Basic Settings > Network > Naming / NICKNAME = dc1-s-xblb001pro
Basic Settings > Network > Naming / DNS SEARCH DOMAIN = adm.example.net
Basic Settings > Network > Naming / PRIMARY DNS SERVER = 10.11.16.145
Basic Settings > Network > Naming / SECONDARY DNS SERVER = 10.11.18.145
AnswerWhat it means
Label on box EXT (1) with Name IBMThe labels printed on the appliance and the roles given to the ports cross over: port 1, labelled EXT, carries the in-band management network (IBM) where administrators reach the web interface and SSH; port 2, labelled MGMT, carries the production network (PRO) where the users' sessions arrive. The labels are the vendor's; the design's interface names follow the roles
VLAN ID with System name eth0.1010Every logical interface is VLAN-tagged on its port; the switch ports are trunks, see the switch port configuration
Physical Interface 3, two VLANsThe redundant heartbeat (CLS2, VLAN 1018) and the backup and archive network towards the NetApp (BCK, VLAN 1020) share port 3. 10.11.18.209 is node A's own address; node B's 10.11.18.210 is set on the High availability page
Physical Interfaces 5 and 6The two SFP+ ports; not used
IPv4 route 1, Gateway 10.11.17.70Outside 10.11.16.80/29, 10.11.16.64/29, 10.11.18.208/28 and 10.11.18.224/28. The exported configuration of the site 2 cluster has 10.12.16.70 as its default gateway, which is inside its production network 10.12.16.64/29; by analogy, 10.11.16.70 in the site 1 production network was probably meant here. That is my inference; the material holds no site 1 export to check it
Routes 2 to 6 via 10.11.16.86Admin VPN, Sensu, Active Directory and both Infoblox segments are reached through a gateway in the in-band management network; as I read it, so that replies to administrators and the infrastructure traffic leave by port 1 and not by the default route
NICKNAME dc1-s-xblb001proThe same string as the name the L3 sheet gives to the production address 10.11.16.65, dc1-s-xblb001pro.adm.example.net; the design does not say what the nickname was used for

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
Balabit SCB 5 LTS (5.0.3) on SCB T-10 appliancesThe product is One Identity Safeguard for Privileged Sessions (SPS); 9.0 is the current release (September 2026). 5.0.x LTS support was discontinued on 2020-05-28, T-Series hardware reached End of Support on 2024-07-31, and SPS 8.0 is not supported on T-Series
VLAN-tagged logical interfaces on physical ports 1 to 3Unchanged: any number of logical interfaces per physical interface, each with its own VLAN ID. New note: SPS does not support two hosts using the same IP address on different VLAN groups
Management (IBM) and user traffic (PRO) on separate networksThe security checklist recommends exactly that: monitored connections and administrative access should originate from separate networks
IPv6 only on the production interfaceStill the rule: IPv6 is for monitored connections; local services, the web login included, require IPv4
SFP+ ports 5 and 6 unusedOn the current 3500 and 4000 appliances the SFP+ ports are available for proxy traffic and local services

Nothing on this page would be configured differently for that reason alone; the platform under it is what is gone. Moving off a T-10 means new hardware and the vendor's data migration between SPS instances, not an in-place upgrade.

← solutionz