Balabit - RDP connections (site 1)
Balabit SCB Solution · Config document · referenced from Connection and channel policies
ORG_RDP_JumpServer in my design carries NAME = PARTNER1_RDP_JumpServer, a copy-and-paste slip in the document: two connections cannot share a name, and the user access guide and the site 2 configuration call it ORG_RDP_JumpServer. It is kept below as written.The three RDP connection policies of the site 1 cluster as recorded in December 2017: one per company, each on its own port of the production address, each leading to one Windows jump server (two addresses for partner 2).
| Item | Value |
|---|---|
| Where | SCB web interface, RDP Control > Connections |
| Cluster | dc1-s-xblb001, production address 10.11.16.65 and 2001:db8:a1:c0e::f:1 |
| Firmware at the time | 5 LTS (5.0.3) |
| Source | My design document, version 0.5 of 2017-12-01 (draft), chapter 7.5.1 |
| Not in it | The later connections of partner 3 (port 2207) and of the cloud team of partner 1 (2212), which are only in the connection summary and the user access guide |
The answers
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapter 7.5.1 RDP Control > Connections > PARTNER1_RDP_JumpServer > BASIC SETTINGS / ENABLED = Yes RDP Control > Connections > PARTNER1_RDP_JumpServer > BASIC SETTINGS / NAME = PARTNER1_RDP_JumpServer RDP Control > Connections > PARTNER1_RDP_JumpServer > BASIC SETTINGS / FROM = 0.0.0.0/0 / ::/0 RDP Control > Connections > PARTNER1_RDP_JumpServer > BASIC SETTINGS / TO = 10.11.16.65/32 / 2001:db8:a1:c0e::f:1/128 RDP Control > Connections > PARTNER1_RDP_JumpServer > BASIC SETTINGS / PORT = 3389 RDP Control > Connections > PARTNER1_RDP_JumpServer > TARGET / INBAND DESTINATION SELECTION = TARGETS - DOMAIN (PORT): / 10.11.16.201 (3389) / EXCEPTIONS - DOMAIN (PORT): / N/A / APPEND DOMAINS – DOMAIN: / N/A / DNS SERVER: / N/A RDP Control > Connections > PARTNER1_RDP_JumpServer > SNAT / USE THE IP ADDRESS OF SCB = Yes RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / ACT AS A REMOTE DESKTOP GATEWAY = No RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / VERIFY SERVER CERTIFICATE = No RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / ENABLE INDEXING / PRIORITY / INDEXING POLICY = Yes / normal / default RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / CONNECTION RATE LIMIT = RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / CHANNEL DATABASE CLEANUP = RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / RDP SETTINGS = PARTNER1_RDP RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / AUDIT POLICY = default RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / LDAP SERVER = AD.EXAMPLE.NET RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / BACKUP POLICY = PARTNER1-BACKUP RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / CREDENTIAL STORE = RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / CHANNEL POLICY = PARTNER1-TERMINAL-ONLY RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / SIGNING CA = RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / USERMAPPING POLICY = RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / ARCHIVE/CLEANUP POLICY = PARTNER1-ARCHIVE RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / AA PLUGIN = RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / GATEWAY AUTHENTICATION = No RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / LOG AUDIT TRAILS DOWNLOADS = Yes RDP Control > Connections > ORG_RDP_JumpServer > BASIC SETTINGS / ENABLED = Yes RDP Control > Connections > ORG_RDP_JumpServer > BASIC SETTINGS / NAME = PARTNER1_RDP_JumpServer RDP Control > Connections > ORG_RDP_JumpServer > BASIC SETTINGS / FROM = 0.0.0.0/0 / ::/0 RDP Control > Connections > ORG_RDP_JumpServer > BASIC SETTINGS / TO = 10.11.16.65/32 / 2001:db8:a1:c0e::f:1/128 RDP Control > Connections > ORG_RDP_JumpServer > BASIC SETTINGS / PORT = 2202 RDP Control > Connections > ORG_RDP_JumpServer > TARGET / INBAND DESTINATION SELECTION = TARGETS - DOMAIN (PORT): / 10.11.16.193 (3389) / EXCEPTIONS - DOMAIN (PORT): / N/A / APPEND DOMAINS – DOMAIN: / N/A / DNS SERVER: / N/A RDP Control > Connections > ORG_RDP_JumpServer > SNAT / USE THE IP ADDRESS OF SCB = Yes RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / ACT AS A REMOTE DESKTOP GATEWAY = No RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / VERIFY SERVER CERTIFICATE = No RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / ENABLE INDEXING / PRIORITY / INDEXING POLICY = Yes / normal / default RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / CONNECTION RATE LIMIT = RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / CHANNEL DATABASE CLEANUP = RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / RDP SETTINGS = ORG_RDP RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / AUDIT POLICY = default RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / LDAP SERVER = AD.EXAMPLE.NET RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / BACKUP POLICY = ORG-BACKUP RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / CREDENTIAL STORE = RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / CHANNEL POLICY = ORG-TERMINAL-ONLY RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / SIGNING CA = RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / USERMAPPING POLICY = RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / ARCHIVE/CLEANUP POLICY = ORG-ARCHIVE RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / AA PLUGIN = RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / GATEWAY AUTHENTICATION = No RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / LOG AUDIT TRAILS DOWNLOADS = Yes RDP Control > Connections > PARTNER2_RDP_JumpServer > BASIC SETTINGS / ENABLED = Yes RDP Control > Connections > PARTNER2_RDP_JumpServer > BASIC SETTINGS / NAME = PARTNER2_RDP_JumpServer RDP Control > Connections > PARTNER2_RDP_JumpServer > BASIC SETTINGS / FROM = 10.11.20.192/26 / ::/0 RDP Control > Connections > PARTNER2_RDP_JumpServer > BASIC SETTINGS / TO = 10.11.16.65/32 / 2001:db8:a1:c0e::f:1/128 RDP Control > Connections > PARTNER2_RDP_JumpServer > BASIC SETTINGS / PORT = 2204 RDP Control > Connections > PARTNER2_RDP_JumpServer > TARGET / INBAND DESTINATION SELECTION = TARGETS - DOMAIN (PORT): / 10.11.19.177 (3389) / 2001:db8:a1:b5f::f:1 (3389) / EXCEPTIONS - DOMAIN (PORT): / N/A / APPEND DOMAINS – DOMAIN: / N/A / DNS SERVER: / N/A RDP Control > Connections > PARTNER2_RDP_JumpServer > SNAT / USE THE IP ADDRESS OF SCB = Yes RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / ACT AS A REMOTE DESKTOP GATEWAY = No RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / VERIFY SERVER CERTIFICATE = No RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / ENABLE INDEXING / PRIORITY / INDEXING POLICY = Yes / normal / default RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / CONNECTION RATE LIMIT = RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / CHANNEL DATABASE CLEANUP = RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / RDP SETTINGS = PARTNER2_RDP RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / AUDIT POLICY = default RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / LDAP SERVER = AD.EXAMPLE.NET RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / BACKUP POLICY = PARTNER2-BACKUP RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / CREDENTIAL STORE = RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / CHANNEL POLICY = PARTNER2-TERMINAL-ONLY RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / SIGNING CA = RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / USERMAPPING POLICY = RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / ARCHIVE/CLEANUP POLICY = PARTNER2-ARCHIVE RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / AA PLUGIN = RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / GATEWAY AUTHENTICATION = No RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / LOG AUDIT TRAILS DOWNLOADS = Yes
| Field | What it means |
|---|---|
| FROM | Client networks allowed to use the connection. Any address for partner 1 and the organisation; 10.11.20.192/26 (IPv4) for partner 2 |
| TO, PORT | The SCB address and port the client connects to; the port selects the connection |
| INBAND DESTINATION SELECTION | The targets the user may name in the username, each with its port. Anything else is refused |
| USE THE IP ADDRESS OF SCB | Source NAT: the jump server sees the SCB's address, not the client's |
| ACT AS A REMOTE DESKTOP GATEWAY = No | The SCB does not play an RD Gateway; the client speaks plain RDP to it |
| VERIFY SERVER CERTIFICATE = No | The SCB accepts any certificate of the jump server |
| ENABLE INDEXING | The trails are indexed with the default indexer policy at normal priority, so the screen content can be searched |
| RDP SETTINGS, CHANNEL POLICY, BACKUP POLICY, ARCHIVE/CLEANUP POLICY | The per-company objects: RDP settings, channel policies, backup and archive policies |
| AUDIT POLICY = default, LDAP SERVER = AD.EXAMPLE.NET | Shared by every connection: audit policy, LDAP server policy |
| Empty fields | No rate limit, no per-connection database cleanup (the global 180 days apply), no credential store, no usermapping, no AA plugin, no signing CA |
| LOG AUDIT TRAILS DOWNLOADS = Yes | Every download of a trail from the web interface is logged |
The partner 2 target 10.11.19.177 is not one of the jump servers listed in the design's chapter 4.1.8. The later connection summary gives that address to dc1-a-vcrdp003, as the second target of PARTNER3_RDP_JumpServer, whose clients come from the same 10.11.20.192/26. The documents do not say whether the partner 2 connection was renamed or replaced.
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
| USE THE IP ADDRESS OF SCB = Yes | Still the default ("use the IP address of a SPS logical interface"); the alternatives are the client's original address or a fixed address |
| ACT AS A REMOTE DESKTOP GATEWAY = No | The RD Gateway mode still exists |
| VERIFY SERVER CERTIFICATE = No | SPS does not allow RDP connections to Windows servers that use SHA-1 signed certificates |
| GATEWAY AUTHENTICATION = No | The vendor's security checklist, in SCB 5 and SPS 9.0 alike: "Always use gateway authentication to authenticate clients. Do not trust the source IP address of a connection, or the result of server authentication." |
| Inband destination selection | The syntax is unchanged; since 8.0 LTS SPS no longer splits RDP UPN user names into user and domain |
The settings in the table are still documented in SPS 9.0; the rest of the page was not checked. The checklist's sentence on gateway authentication describes exactly what this design did not do.