Balabit - Workstation hosts file
Balabit SCB Solution · Config document · referenced from Basic settings, logging and monitoring, Certificates and keys and Operations, upgrades and troubleshooting
dc1-s-xblb001.adm.example.net and scb.example.net are the production address 10.11.16.65, and only dc1-s-xblm001.adm.example.net is the management address 10.11.16.81. Do not copy the file to a workstation that also connects to jump servers through scb.example.net.The lines an administrator added to the hosts file of the Windows workstation, so that the names of the site 1 cluster resolved to its management address over the VPN. With them, the web interface and the SSH console could be opened by name.
| Item | Value |
|---|---|
| File | C:\Windows\System32\drivers\etc\hosts, edited in Notepad started as administrator |
| On which host | The administrator's workstation, connected to the organisation's VPN |
| Cluster | dc1-s-xblb001, in-band management address 10.11.16.81 |
| Source | Operation how-to, section "Insert hostname records in the local hosts file" |
| Used by | The sections "Access Balabit SCB through WEB GUI" and "through SSH" of the same how-to, which say for each name "hostname record must be in local hosts file" |
The file
# BALABIT SCB 10.11.16.81 dc1-s-xblb001.adm.example.net 10.11.16.81 dc1-s-xblm001.adm.example.net 10.11.16.81 scb.example.net
| Line | What it does |
|---|---|
# BALABIT SCB | A comment that marks the block, so it can be found and removed later |
dc1-s-xblb001.adm.example.net | The cluster name that chapter 8 of the design gives for web and SSH access, with the address 10.11.16.81. The DNS table of the same design gives this name the production address 10.11.16.65 |
dc1-s-xblm001.adm.example.net | The older management name, which the DNS table has at 10.11.16.81 and which the SCB's own CA and its certificates carry |
scb.example.net | The user-facing name: the DNS table, the design's examples and the user access guide all put it on 10.11.16.65, where the connections listen. On a workstation with this line, scb.example.net:2201 would go to the management address, where no connection is configured |
The how-to does not say why the names had to be in the hosts file instead of in DNS. My guess is that the records were not yet created in the Infoblox, or that the VPN client did not use it as resolver; the notes have no record of either. For the web interface, as I read it, pointing all three names at the management address would fit the organisation-CA certificate for the cluster, if it had been installed, which the documents do not show: it carries dc1-s-xblm001, dc1-s-xblb001 and scb.example.net as alternative names, so a browser would accept any of them at 10.11.16.81. The server certificate of the SCB's own CA, which the design says the web interface uses, names only dc1-s-xblm001 and the address. The certificates are the subject of Certificates and keys, the DNS records that of Hardware, cabling and networks.