LINUXOR.SK ... open source notes ...

Balabit - End-user client settings (both sites)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from End-user access

note<username> is the guide's own placeholder for the user's Active Directory account name, not something removed. Several values carry mistakes of the guide and are kept as written: Word turned the hyphen of -p and -P into an en dash –, the cloud team's OpenSSH line uses –P where ssh takes -p, and the cloud team's "to platform" scp line has the site 1 target and SCB address with the site 2 port. The table after the answers lists them.

Every client setting of the end-user access guide: per partner and site, the summary of the jump servers and the values a user types into MSTSC, PuTTY, OpenSSH, WinSCP and scp to reach a jump server through the SCB with inband destination selection. The port selects the connection on the SCB, the address after the first @ selects the jump server.

ItemValue
WhatThe end-user access guide, chapter 2 "End-user Access", every table
Clustersdc1-s-xblb001 (production address 10.11.16.65) and dc2-s-xblb001 (10.12.16.65)
Firmware at the time5 LTS; the site 2 cluster ran 5.0.6 in September 2018
SourceEnd-user access guide, version 0.5 of 2018-11-05 (status draft; version 0.5 added the cloud team of partner 1)
Not in itPartner 2 and partner 5 (no section), the site 2 connections of partner 1 and the organisation, the SCP connection of partner 4

The answers

ini
# Page / Field = value, as configured on dc1-s-xblb001 and dc2-s-xblb001, from the end-user access guide version 0.5 of 2018-11-05

PARTNER1 access > Site 1 > Summary of Jump Servers > PARTNER1_RDP_JumpServer / Target server/s = 10.11.16.201 (DC1-A-VCRDP002)
PARTNER1 access > Site 1 > Summary of Jump Servers > PARTNER1_RDP_JumpServer / Purpose = Windows Jump Server
PARTNER1 access > Site 1 > Summary of Jump Servers > PARTNER1_SSH_JumpServer / Target server/s = 10.11.17.81 / (DC1-A-VCJMP002)
PARTNER1 access > Site 1 > Summary of Jump Servers > PARTNER1_SSH_JumpServer / Purpose = Linux Jump Server
PARTNER1 access > Site 1 > Summary of Jump Servers > PARTNER1_SCP_SFTP_JumpServer / Target server/s = 10.11.17.129 (DC1-A-VCSCP001)
PARTNER1 access > Site 1 > Summary of Jump Servers > PARTNER1_SCP_SFTP_JumpServer / Purpose = Fileserver – copy files to/from platform

PARTNER1 access > Site 1 > MSTSC > PARTNER1_RDP_JumpServer / USERNAME = <username>
PARTNER1 access > Site 1 > MSTSC > PARTNER1_RDP_JumpServer / TARGET SERVER = 10.11.16.201 (PARTNER1_RDP_JumpServer)
PARTNER1 access > Site 1 > MSTSC > PARTNER1_RDP_JumpServer / SCB = 10.11.16.65
PARTNER1 access > Site 1 > MSTSC > PARTNER1_RDP_JumpServer / MSTSC - COMPUTER = 10.11.16.65
PARTNER1 access > Site 1 > MSTSC > PARTNER1_RDP_JumpServer / MSTSC – USER NAME = <username>@10.11.16.201
PARTNER1 access > Site 1 > MSTSC > PARTNER1_RDP_JumpServer / MSTSC - CREDENTIALS = Access credentials (User name and password) which will user want to use in RDP connection must be saved in MSTSC client.

PARTNER1 access > Site 1 > PuTTY > PARTNER1_SSH_JumpServer / USERNAME = <username>
PARTNER1 access > Site 1 > PuTTY > PARTNER1_SSH_JumpServer / TARGET SERVER = 10.11.17.81 (PARTNER1_SSH_JumpServer)
PARTNER1 access > Site 1 > PuTTY > PARTNER1_SSH_JumpServer / SCB = 10.11.16.65
PARTNER1 access > Site 1 > PuTTY > PARTNER1_SSH_JumpServer / PUTTY – HOSTNAME = <username>@10.11.17.81@10.11.16.65
PARTNER1 access > Site 1 > PuTTY > PARTNER1_SSH_JumpServer / PUTTY – PORT = 22

PARTNER1 access > Site 1 > OpenSSH > PARTNER1_SSH_JumpServer / USERNAME = <username>
PARTNER1 access > Site 1 > OpenSSH > PARTNER1_SSH_JumpServer / TARGET SERVER = 10.11.17.81 (PARTNER1_SSH_JumpServer)
PARTNER1 access > Site 1 > OpenSSH > PARTNER1_SSH_JumpServer / SCB = 10.11.16.65
PARTNER1 access > Site 1 > OpenSSH > PARTNER1_SSH_JumpServer / OPENSSH COMMAND = ssh <username>@10.11.17.81@10.11.16.65

PARTNER1 access > Site 1 > WinSCP > PARTNER1_SCP_SFTP_JumpServer / USERNAME = <username>
PARTNER1 access > Site 1 > WinSCP > PARTNER1_SCP_SFTP_JumpServer / TARGET SERVER = 10.11.17.129 (PARTNER1_SCP_SFTP_JumpServer)
PARTNER1 access > Site 1 > WinSCP > PARTNER1_SCP_SFTP_JumpServer / SCB = 10.11.16.65
PARTNER1 access > Site 1 > WinSCP > PARTNER1_SCP_SFTP_JumpServer / WINSCP – FILE PROTOCOL = SFTP
PARTNER1 access > Site 1 > WinSCP > PARTNER1_SCP_SFTP_JumpServer / WINSCP – HOSTNAME = 10.11.16.65
PARTNER1 access > Site 1 > WinSCP > PARTNER1_SCP_SFTP_JumpServer / WINSCP – PORT NUMBER = 222
PARTNER1 access > Site 1 > WinSCP > PARTNER1_SCP_SFTP_JumpServer / WINSCP – USER NAME = <username>@10.11.17.129

PARTNER1 access > Site 1 > OpenSSH > PARTNER1_SCP_SFTP_JumpServer / USERNAME = <username>
PARTNER1 access > Site 1 > OpenSSH > PARTNER1_SCP_SFTP_JumpServer / TARGET SERVER = 10.11.17.129 (PARTNER1_SCP_SFTP_JumpServer)
PARTNER1 access > Site 1 > OpenSSH > PARTNER1_SCP_SFTP_JumpServer / SCB = 10.11.16.65
PARTNER1 access > Site 1 > OpenSSH > PARTNER1_SCP_SFTP_JumpServer / OPENSSH COMMAND – to platform = scp –P 222  /tmp/file_to_upload  <username>@10.11.17.129@10.11.16.65:/upload/
PARTNER1 access > Site 1 > OpenSSH > PARTNER1_SCP_SFTP_JumpServer / OPENSSH COMMAND – from platform = scp –P 222  <username>@10.11.17.129@10.11.16.65:/upload/file_to_download  /tmp/

PARTNER1 CLOUD access > Site 2 > Summary of Jump Servers > CLOUD_PARTNER1_RDP_JumpServer / Target server/s = 10.19.17.33  / (DC6-A-VCRDP002)
PARTNER1 CLOUD access > Site 2 > Summary of Jump Servers > CLOUD_PARTNER1_RDP_JumpServer / Purpose = Windows Jump Server
PARTNER1 CLOUD access > Site 2 > Summary of Jump Servers > CLOUD_PARTNER1_SSH_JumpServer / Target server/s = 10.19.17.98 /  (DC6-A-VCOJP002)
PARTNER1 CLOUD access > Site 2 > Summary of Jump Servers > CLOUD_PARTNER1_SSH_JumpServer / Purpose = Linux Jump Server
PARTNER1 CLOUD access > Site 2 > Summary of Jump Servers > CLOUD_PARTNER1_SCP_SFTP_JumpServer / Target server/s = 10.19.17.225 (DC6-A-VCSCP002)
PARTNER1 CLOUD access > Site 2 > Summary of Jump Servers > CLOUD_PARTNER1_SCP_SFTP_JumpServer / Purpose = Fileserver – copy files to/from platform

PARTNER1 CLOUD access > Site 2 > MSTSC > CLOUD_PARTNER1_RDP_JumpServer / USERNAME = <username>
PARTNER1 CLOUD access > Site 2 > MSTSC > CLOUD_PARTNER1_RDP_JumpServer / TARGET SERVER = 10.19.17.33 (CLOUD_PARTNER1_RDP_JumpServer)
PARTNER1 CLOUD access > Site 2 > MSTSC > CLOUD_PARTNER1_RDP_JumpServer / SCB = 10.12.16.65
PARTNER1 CLOUD access > Site 2 > MSTSC > CLOUD_PARTNER1_RDP_JumpServer / MSTSC - COMPUTER = 10.12.16.65:2212
PARTNER1 CLOUD access > Site 2 > MSTSC > CLOUD_PARTNER1_RDP_JumpServer / MSTSC – USER NAME = <username>@10.19.17.33
PARTNER1 CLOUD access > Site 2 > MSTSC > CLOUD_PARTNER1_RDP_JumpServer / MSTSC - CREDENTIALS = Access credentials (User name and password) which will user want to use in RDP connection must be saved in MSTSC client.

PARTNER1 CLOUD access > Site 2 > PuTTY > CLOUD_PARTNER1_SSH_JumpServer / USERNAME = <username>
PARTNER1 CLOUD access > Site 2 > PuTTY > CLOUD_PARTNER1_SSH_JumpServer / TARGET SERVER = 10.19.17.98 (CLOUD_PARTNER1_SSH_JumpServer)
PARTNER1 CLOUD access > Site 2 > PuTTY > CLOUD_PARTNER1_SSH_JumpServer / SCB = 10.12.16.65
PARTNER1 CLOUD access > Site 2 > PuTTY > CLOUD_PARTNER1_SSH_JumpServer / PUTTY – HOSTNAME = <username>@10.19.17.98@10.12.16.65
PARTNER1 CLOUD access > Site 2 > PuTTY > CLOUD_PARTNER1_SSH_JumpServer / PUTTY – PORT = 2210

PARTNER1 CLOUD access > Site 2 > OpenSSH > CLOUD_PARTNER1_SSH_JumpServer / USERNAME = <username>
PARTNER1 CLOUD access > Site 2 > OpenSSH > CLOUD_PARTNER1_SSH_JumpServer / TARGET SERVER = 10.19.17.98 (CLOUD_PARTNER1_SSH_JumpServer)
PARTNER1 CLOUD access > Site 2 > OpenSSH > CLOUD_PARTNER1_SSH_JumpServer / SCB = 10.12.16.65
PARTNER1 CLOUD access > Site 2 > OpenSSH > CLOUD_PARTNER1_SSH_JumpServer / OPENSSH COMMAND = ssh –P 2210 <username>@10.19.17.98@10.12.16.65

PARTNER1 CLOUD access > Site 2 > WinSCP > CLOUD_PARTNER1_SCP_SFTP_JumpServer / USERNAME = <username>
PARTNER1 CLOUD access > Site 2 > WinSCP > CLOUD_PARTNER1_SCP_SFTP_JumpServer / TARGET SERVER = 10.19.17.225 (CLOUD_PARTNER1_SCP_SFTP_JumpServer)
PARTNER1 CLOUD access > Site 2 > WinSCP > CLOUD_PARTNER1_SCP_SFTP_JumpServer / SCB = 10.12.16.65
PARTNER1 CLOUD access > Site 2 > WinSCP > CLOUD_PARTNER1_SCP_SFTP_JumpServer / WINSCP – FILE PROTOCOL = SFTP
PARTNER1 CLOUD access > Site 2 > WinSCP > CLOUD_PARTNER1_SCP_SFTP_JumpServer / WINSCP – HOSTNAME = 10.12.16.65
PARTNER1 CLOUD access > Site 2 > WinSCP > CLOUD_PARTNER1_SCP_SFTP_JumpServer / WINSCP – PORT NUMBER = 2211
PARTNER1 CLOUD access > Site 2 > WinSCP > CLOUD_PARTNER1_SCP_SFTP_JumpServer / WINSCP – USER NAME = <username>@10.19.17.225

PARTNER1 CLOUD access > Site 2 > OpenSSH > CLOUD_PARTNER1_SCP_SFTP_JumpServer / USERNAME = <username>
PARTNER1 CLOUD access > Site 2 > OpenSSH > CLOUD_PARTNER1_SCP_SFTP_JumpServer / TARGET SERVER = 10.19.17.225 (CLOUD_PARTNER1_SCP_SFTP_JumpServer)
PARTNER1 CLOUD access > Site 2 > OpenSSH > CLOUD_PARTNER1_SCP_SFTP_JumpServer / SCB = 10.12.16.65
PARTNER1 CLOUD access > Site 2 > OpenSSH > CLOUD_PARTNER1_SCP_SFTP_JumpServer / OPENSSH COMMAND – to platform = scp –P 2211  /tmp/file_to_upload  <username>@10.11.17.129@10.11.16.65:/upload/
PARTNER1 CLOUD access > Site 2 > OpenSSH > CLOUD_PARTNER1_SCP_SFTP_JumpServer / OPENSSH COMMAND – from platform = scp –P 2211  <username>@10.19.17.225@10.12.16.65:/upload/file_to_download  /tmp/

PARTNER3 access > Site 1 > Summary of Jump Servers > PARTNER3_RDP_JumpServer / Target server/s = 10.11.16.193 / (DC1-A-VCRDP001) / 10.11.19.177 / (DC1-A-VCRDP003)
PARTNER3 access > Site 1 > Summary of Jump Servers > PARTNER3_RDP_JumpServer / Purpose = Windows Jump Server 1 / Windows Jump Server 2 (network management consoles)
PARTNER3 access > Site 1 > Summary of Jump Servers > PARTNER3_SSH_JumpServer / Target server/s = 10.11.16.177 / (DC1-A-VCJMP001)
PARTNER3 access > Site 1 > Summary of Jump Servers > PARTNER3_SSH_JumpServer / Purpose = Linux Jump Server
PARTNER3 access > Site 1 > Summary of Jump Servers > PARTNER3_SCP_SFTP_JumpServer / Target server/s = 10.11.17.129 (DC1-A-VCSCP001)
PARTNER3 access > Site 1 > Summary of Jump Servers > PARTNER3_SCP_SFTP_JumpServer / Purpose = Fileserver – copy files to/from platform

PARTNER3 access > Site 1 > MSTSC > PARTNER3_RDP_JumpServer1 / USERNAME = <username>
PARTNER3 access > Site 1 > MSTSC > PARTNER3_RDP_JumpServer1 / TARGET SERVER = 10.11.16.193 (PARTNER3_RDP_JumpServer1)
PARTNER3 access > Site 1 > MSTSC > PARTNER3_RDP_JumpServer1 / SCB = 10.11.16.65 (scb.example.net)
PARTNER3 access > Site 1 > MSTSC > PARTNER3_RDP_JumpServer1 / MSTSC - COMPUTER = 10.11.16.65:2207
PARTNER3 access > Site 1 > MSTSC > PARTNER3_RDP_JumpServer1 / MSTSC – USER NAME = <username>@10.11.16.193
PARTNER3 access > Site 1 > MSTSC > PARTNER3_RDP_JumpServer1 / MSTSC - CREDENTIALS = Access credentials (User name and password) which will user want to use in RDP connection must be saved in MSTSC client.

PARTNER3 access > Site 1 > MSTSC > PARTNER3_RDP_JumpServer2 / USERNAME = <username>
PARTNER3 access > Site 1 > MSTSC > PARTNER3_RDP_JumpServer2 / TARGET SERVER = 10.11.19.177 (PARTNER3_RDP_JumpServer2 - management consoles)
PARTNER3 access > Site 1 > MSTSC > PARTNER3_RDP_JumpServer2 / SCB = 10.11.16.65 (scb.example.net)
PARTNER3 access > Site 1 > MSTSC > PARTNER3_RDP_JumpServer2 / MSTSC - COMPUTER = 10.11.16.65:2207
PARTNER3 access > Site 1 > MSTSC > PARTNER3_RDP_JumpServer2 / MSTSC – USER NAME = <username>@10.11.19.177
PARTNER3 access > Site 1 > MSTSC > PARTNER3_RDP_JumpServer2 / MSTSC - CREDENTIALS = Access credentials (User name and password) which will user want to use in RDP connection must be saved in MSTSC client.

PARTNER3 access > Site 1 > PuTTY > PARTNER3_SSH_JumpServer / USERNAME = <username>
PARTNER3 access > Site 1 > PuTTY > PARTNER3_SSH_JumpServer / TARGET SERVER = 10.11.16.177 (PARTNER3_SSH_JumpServer)
PARTNER3 access > Site 1 > PuTTY > PARTNER3_SSH_JumpServer / SCB = 10.11.16.65 (scb.example.net)
PARTNER3 access > Site 1 > PuTTY > PARTNER3_SSH_JumpServer / PUTTY – HOSTNAME = <username>@10.11.16.177@10.11.16.65
PARTNER3 access > Site 1 > PuTTY > PARTNER3_SSH_JumpServer / PUTTY – PORT = 2205

PARTNER3 access > Site 1 > OpenSSH > PARTNER3_SSH_JumpServer / USERNAME = <username>
PARTNER3 access > Site 1 > OpenSSH > PARTNER3_SSH_JumpServer / TARGET SERVER = 10.11.16.177 (PARTNER3_SSH_JumpServer)
PARTNER3 access > Site 1 > OpenSSH > PARTNER3_SSH_JumpServer / SCB = 10.11.16.65 (scb.example.net)
PARTNER3 access > Site 1 > OpenSSH > PARTNER3_SSH_JumpServer / OPENSSH COMMAND = ssh –p 2205 <username>@10.11.16.177@10.11.16.65

PARTNER3 access > Site 1 > WinSCP > PARTNER3_SCP_SFTP_JumpServer / USERNAME = <username>
PARTNER3 access > Site 1 > WinSCP > PARTNER3_SCP_SFTP_JumpServer / TARGET SERVER = 10.11.17.129 (PARTNER3_SCP_SFTP_JumpServer)
PARTNER3 access > Site 1 > WinSCP > PARTNER3_SCP_SFTP_JumpServer / SCB = 10.11.16.65 (scb.example.net)
PARTNER3 access > Site 1 > WinSCP > PARTNER3_SCP_SFTP_JumpServer / WINSCP – FILE PROTOCOL = SFTP
PARTNER3 access > Site 1 > WinSCP > PARTNER3_SCP_SFTP_JumpServer / WINSCP – HOSTNAME = 10.11.16.65
PARTNER3 access > Site 1 > WinSCP > PARTNER3_SCP_SFTP_JumpServer / WINSCP – PORT NUMBER = 2206
PARTNER3 access > Site 1 > WinSCP > PARTNER3_SCP_SFTP_JumpServer / WINSCP – USER NAME = <username>@10.11.17.129

PARTNER3 access > Site 1 > OpenSSH > PARTNER3_SCP_SFTP_JumpServer / USERNAME = <username>
PARTNER3 access > Site 1 > OpenSSH > PARTNER3_SCP_SFTP_JumpServer / TARGET SERVER = 10.11.17.129 (PARTNER3_SCP_SFTP_JumpServer)
PARTNER3 access > Site 1 > OpenSSH > PARTNER3_SCP_SFTP_JumpServer / SCB = 10.11.16.65 (scb.example.net)
PARTNER3 access > Site 1 > OpenSSH > PARTNER3_SCP_SFTP_JumpServer / OPENSSH COMMAND / (to platform) = scp –P 2206 /tmp/file_to_upload <username>@10.11.17.129@10.11.16.65:/home/<username>
PARTNER3 access > Site 1 > OpenSSH > PARTNER3_SCP_SFTP_JumpServer / OPENSSH COMMAND / (from platform) = scp –P 2206 <username>@10.11.17.129@10.11.16.65:/home/<username> /tmp/file_to_download

ORG access > Site 1 > Summary of Jump Servers > ORG_RDP_JumpServer / Target server/s = 10.11.16.193 / (DC1-A-VCRDP001)
ORG access > Site 1 > Summary of Jump Servers > ORG_RDP_JumpServer / Purpose = Windows Jump Server
ORG access > Site 1 > Summary of Jump Servers > ORG_SSH_JumpServer / Target server/s = 10.11.16.177 / (DC1-A-VCJMP001)
ORG access > Site 1 > Summary of Jump Servers > ORG_SSH_JumpServer / Purpose = Linux Jump Server
ORG access > Site 1 > Summary of Jump Servers > ORG_SCP_SFTP_JumpServer / Target server/s = 10.11.17.129 (DC1-A-VCSCP001)
ORG access > Site 1 > Summary of Jump Servers > ORG_SCP_SFTP_JumpServer / Purpose = Fileserver – copy files to/from platform

ORG access > Site 1 > MSTSC > ORG_RDP_JumpServer / USERNAME = <username>
ORG access > Site 1 > MSTSC > ORG_RDP_JumpServer / TARGET SERVER = 10.11.16.193 (ORG_RDP_JumpServer)
ORG access > Site 1 > MSTSC > ORG_RDP_JumpServer / SCB = 10.11.16.65 (scb.example.net)
ORG access > Site 1 > MSTSC > ORG_RDP_JumpServer / MSTSC - COMPUTER = 10.11.16.65:2202
ORG access > Site 1 > MSTSC > ORG_RDP_JumpServer / MSTSC – USER NAME = <username>@10.11.16.193
ORG access > Site 1 > MSTSC > ORG_RDP_JumpServer / MSTSC - CREDENTIALS = Access credentials (User name and password) which will user want to use in RDP connection must be saved in MSTSC client.

ORG access > Site 1 > PuTTY > ORG_SSH_JumpServer / USERNAME = <username>
ORG access > Site 1 > PuTTY > ORG_SSH_JumpServer / TARGET SERVER = 10.11.16.177 (ORG_SSH_JumpServer)
ORG access > Site 1 > PuTTY > ORG_SSH_JumpServer / SCB = 10.11.16.65 (scb.example.net)
ORG access > Site 1 > PuTTY > ORG_SSH_JumpServer / PUTTY – HOSTNAME = <username>@10.11.16.177@10.11.16.65
ORG access > Site 1 > PuTTY > ORG_SSH_JumpServer / PUTTY – PORT = 2201

ORG access > Site 1 > OpenSSH > ORG_SSH_JumpServer / USERNAME = <username>
ORG access > Site 1 > OpenSSH > ORG_SSH_JumpServer / TARGET SERVER = 10.11.16.177 (ORG_SSH_JumpServer)
ORG access > Site 1 > OpenSSH > ORG_SSH_JumpServer / SCB = 10.11.16.65 (scb.example.net)
ORG access > Site 1 > OpenSSH > ORG_SSH_JumpServer / OPENSSH COMMAND = ssh –p 2201 <username>@10.11.16.177@10.11.16.65

ORG access > Site 1 > WinSCP > ORG_SCP_SFTP_JumpServer / USERNAME = <username>
ORG access > Site 1 > WinSCP > ORG_SCP_SFTP_JumpServer / TARGET SERVER = 10.11.17.129 (ORG_SCP_SFTP_JumpServer)
ORG access > Site 1 > WinSCP > ORG_SCP_SFTP_JumpServer / SCB = 10.11.16.65 (scb.example.net)
ORG access > Site 1 > WinSCP > ORG_SCP_SFTP_JumpServer / WINSCP – FILE PROTOCOL = SFTP
ORG access > Site 1 > WinSCP > ORG_SCP_SFTP_JumpServer / WINSCP – HOSTNAME = 10.11.16.65
ORG access > Site 1 > WinSCP > ORG_SCP_SFTP_JumpServer / WINSCP – PORT NUMBER = 2203
ORG access > Site 1 > WinSCP > ORG_SCP_SFTP_JumpServer / WINSCP – USER NAME = <username>@10.11.17.129

ORG access > Site 1 > OpenSSH > ORG_SCP_SFTP_JumpServer / USERNAME = <username>
ORG access > Site 1 > OpenSSH > ORG_SCP_SFTP_JumpServer / TARGET SERVER = 10.11.17.129 (ORG_SCP_SFTP_JumpServer)
ORG access > Site 1 > OpenSSH > ORG_SCP_SFTP_JumpServer / SCB = 10.11.16.65 (scb.example.net)
ORG access > Site 1 > OpenSSH > ORG_SCP_SFTP_JumpServer / OPENSSH COMMAND / (to platform) = scp –P 2203 /tmp/file_to_upload <username>@10.11.17.129@10.11.16.65:/home/<username>
ORG access > Site 1 > OpenSSH > ORG_SCP_SFTP_JumpServer / OPENSSH COMMAND / (from platform) = scp –P 2203 <username>@10.11.17.129@10.11.16.65:/home/<username> /tmp/file_to_download

PARTNER4 access > Site 2 > Summary of Jump Servers > PARTNER4_RDP_JumpServer / Target server/s = 10.12.19.209 / (DC2-A-VCRDP004)
PARTNER4 access > Site 2 > Summary of Jump Servers > PARTNER4_RDP_JumpServer / Purpose = Windows Jump Server

PARTNER4 access > Site 2 > MSTSC > PARTNER4_RDP_JumpServer / USERNAME = <username>
PARTNER4 access > Site 2 > MSTSC > PARTNER4_RDP_JumpServer / TARGET SERVER = 10.12.19.209 (PARTNER4_RDP_JumpServer)
PARTNER4 access > Site 2 > MSTSC > PARTNER4_RDP_JumpServer / SCB = 10.12.16.65
PARTNER4 access > Site 2 > MSTSC > PARTNER4_RDP_JumpServer / MSTSC - COMPUTER = 10.12.16.65:2208
PARTNER4 access > Site 2 > MSTSC > PARTNER4_RDP_JumpServer / MSTSC – USER NAME = <username>@10.12.19.209
PARTNER4 access > Site 2 > MSTSC > PARTNER4_RDP_JumpServer / MSTSC - CREDENTIALS = Access credentials (User name and password) which will user want to use in RDP connection must be saved in MSTSC client.

The page path is the guide's section, location and client; the connection name after the last > is the one in brackets after the target server in each table. Two field names had a line break in the guide (OPENSSH COMMAND over (to platform)); here they keep the / join, OPENSSH COMMAND / (to platform). The two OpenSSH tables of partner 1 write the same field with an en dash instead (OPENSSH COMMAND – to platform), as in the guide.

LineWhat it means or what is wrong
MSTSC - COMPUTER = 10.11.16.65No port: partner 1's RDP connection listens on 3389, the default of the Remote Desktop client. Every other RDP connection needs :port after the address
MSTSC – USER NAME = <username>@<target>The target goes into the user name; the SCB takes it out and connects to that address. The guide wants the credentials saved in the client; as I understand it, that is because the SCB relays the password to the jump server and the client has to send it with the first request
PUTTY – HOSTNAME = <username>@<target>@<scb>The whole string goes into the host name field; the client connects to the address after the last @ and offers the rest, <username>@<target>, as the user name, which is what the SCB reads the target from
–p, –PAn en dash, not a hyphen: the guide was written in Word, which replaced the character. Typed as shown, ssh and scp take –p for a file or host name. The hyphen is meant: -p for ssh, -P for scp
ssh –P 2210 (cloud team, OpenSSH)Wrong option even with a hyphen: the port option of ssh is lower-case -p; upper-case -P is the port option of scp only
scp –P 2211 … <username>@10.11.17.129@10.11.16.65:/upload/ (cloud team, to platform)Target and SCB of partner 1 in site 1 with the port of the cloud team in site 2; the "from platform" line next to it has the right 10.19.17.225@10.12.16.65
Target server/s = 10.19.17.98 (cloud team, SSH)The connection summary has 10.19.17.96 for dc6-a-vcojp002. Which one was configured on the SCB I cannot tell: the site 2 config.xml of September 2018 has no cloud connection yet
Location – Site 2 (cloud team)The SCB is the site 2 cluster; the jump servers are in site 6 (DC6-…, 10.19.17.x)
:/upload/ and :/home/<username>Partner 1 uploads into the upload directory of the file server; partner 3 and the organisation copy into their home directory, which the Linux jump servers mount under /home/<username>/data/
WINSCP – FILE PROTOCOL = SFTPAlways SFTP: WinSCP in SCP mode transfers files in a shell channel, which the SCB would not record as file operations, and in site 2 the content policy no-WINSCP ends such sessions; in the site 1 design it is defined but not referenced
(PARTNER3_RDP_JumpServer2 - management consoles), (network management consoles)The guide's only description of the second Windows jump server of partner 3; both jump servers are reached on the same port 2207 and told apart by the address in the user name

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
<username>@<target>@<scb> in PuTTY, OpenSSH, WinSCP and scp; <username>@<target> in MSTSCThe same inband syntax; a target given as host name must comply with RFC 5890 since 6.1.0
RDP user name with the target appendedSince 8.0 LTS an RDP user principal name is no longer split into a local user name and a domain
WinSCP with the file protocol SFTPStill the vendor's advice, with the same content policy against WinSCP in SCP mode; the current WinSCP is 6.5.7
PuTTY 0.65, built-in RDP clients up to Windows 10The 9.0 guide still names PuTTY 0.65 as tested; the supported RDP clients are those of Windows Server 2016 to 2022, Windows 10 and Windows 11

The syntax is still documented; whether today's clients still connect depends on the SSH algorithm lists of the connections (see End-user access). What has also moved is the list of clients the vendor tests.

← solutionz