ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Linux Lab Project: Building a Linux Jump Box

    Scheduled Pinned Locked Moved IT Discussion
    centos 7sshserverjumpboxprojectsjump serverlinuxjump stationntg labscale hc3centosunixscale
    56 Posts 14 Posters 19.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller
      last edited by

      So a Jump system can be about smoothing access to make it faster. Or it can be amount making access more secure. Or both.

      It is, in many ways, about eliminating the free for all of access that is common with a VPN where you traditionally have many peers all able to access each other making access difficult to track and control.

      Which is why large shops traditionally use a jump box even on a LAN. So even if you had a VPN, you might still have the jump box.

      NashBrydgesN 1 Reply Last reply Reply Quote 0
      • NashBrydgesN
        NashBrydges @scottalanmiller
        last edited by

        @scottalanmiller said in Linux Lab Project: Building a Linux Jump Box:

        So a Jump system can be about smoothing access to make it faster. Or it can be amount making access more secure. Or both.

        It is, in many ways, about eliminating the free for all of access that is common with a VPN where you traditionally have many peers all able to access each other making access difficult to track and control.

        Which is why large shops traditionally use a jump box even on a LAN. So even if you had a VPN, you might still have the jump box.

        I had started typing out an entirely different response with scenarios comparing VPN and jump box and wasn't until the end that I saw where the jump box approach may be much simpler. It avoids having to manipulate multiple systems to provide a similar level of control (if I understood this correctly) over accessibility. Manage a single jump box instead of VPN, firewall, entity/authentication management...etc.

        scottalanmillerS 1 Reply Last reply Reply Quote 1
        • scottalanmillerS
          scottalanmiller @NashBrydges
          last edited by

          @NashBrydges said in Linux Lab Project: Building a Linux Jump Box:

          @scottalanmiller said in Linux Lab Project: Building a Linux Jump Box:

          So a Jump system can be about smoothing access to make it faster. Or it can be amount making access more secure. Or both.

          It is, in many ways, about eliminating the free for all of access that is common with a VPN where you traditionally have many peers all able to access each other making access difficult to track and control.

          Which is why large shops traditionally use a jump box even on a LAN. So even if you had a VPN, you might still have the jump box.

          I had started typing out an entirely different response with scenarios comparing VPN and jump box and wasn't until the end that I saw where the jump box approach may be much simpler. It avoids having to manipulate multiple systems to provide a similar level of control (if I understood this correctly) over accessibility. Manage a single jump box instead of VPN, firewall, entity/authentication management...etc.

          Correct. Now of course you can do some work with a VPN to make it kind of mimic a jump box. But it would be more work and still doesn't gap quite as well. VPNs have the advantage of allowing a direct connection. But that is part of what we are trying to avoid in many cases.

          NashBrydgesN 1 Reply Last reply Reply Quote 0
          • NashBrydgesN
            NashBrydges @scottalanmiller
            last edited by

            @scottalanmiller said in Linux Lab Project: Building a Linux Jump Box:

            @NashBrydges said in Linux Lab Project: Building a Linux Jump Box:

            @scottalanmiller said in Linux Lab Project: Building a Linux Jump Box:

            So a Jump system can be about smoothing access to make it faster. Or it can be amount making access more secure. Or both.

            It is, in many ways, about eliminating the free for all of access that is common with a VPN where you traditionally have many peers all able to access each other making access difficult to track and control.

            Which is why large shops traditionally use a jump box even on a LAN. So even if you had a VPN, you might still have the jump box.

            I had started typing out an entirely different response with scenarios comparing VPN and jump box and wasn't until the end that I saw where the jump box approach may be much simpler. It avoids having to manipulate multiple systems to provide a similar level of control (if I understood this correctly) over accessibility. Manage a single jump box instead of VPN, firewall, entity/authentication management...etc.

            Correct. Now of course you can do some work with a VPN to make it kind of mimic a jump box. But it would be more work and still doesn't gap quite as well. VPNs have the advantage of allowing a direct connection. But that is part of what we are trying to avoid in many cases.

            Right. Thanks for taking the time to walk me through this.

            1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller
              last edited by

              Think of a Jump box much like a man trap in a building. Does it keep all threats out? Of course not. But a man trap revolving door never allows the inside and outside air pressures to be directly exposed. A VPN opens the floodgates between two networks allowing things just looking for a route to flood across. It grows the LAN.

              NerdyDadN 1 Reply Last reply Reply Quote 1
              • NerdyDadN
                NerdyDad @scottalanmiller
                last edited by

                @scottalanmiller said in Linux Lab Project: Building a Linux Jump Box:

                Think of a Jump box much like a man trap in a building. Does it keep all threats out? Of course not. But a man trap revolving door never allows the inside and outside air pressures to be directly exposed. A VPN opens the floodgates between two networks allowing things just looking for a route to flood across. It grows the LAN.

                Any drawbacks of jump box over VPN?

                scottalanmillerS 1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @NerdyDad
                  last edited by

                  @NerdyDad said in Linux Lab Project: Building a Linux Jump Box:

                  @scottalanmiller said in Linux Lab Project: Building a Linux Jump Box:

                  Think of a Jump box much like a man trap in a building. Does it keep all threats out? Of course not. But a man trap revolving door never allows the inside and outside air pressures to be directly exposed. A VPN opens the floodgates between two networks allowing things just looking for a route to flood across. It grows the LAN.

                  Any drawbacks of jump box over VPN?

                  Depends, if you WANT full access for other things, then yes. Like a VPN let's you map drives directly to your desktop. Those are things I normally seek to avoid. But, you can't deny that it is handy. A VPN is basically "less security", by moving you back to the LAN-based network security model. It's like the dark side, it's faster and easier, but ultimately it consumes you.

                  VPNs are fast and easy, no need to really secure things. And then ransomware pwns you.

                  1 Reply Last reply Reply Quote 1
                  • scottalanmillerS
                    scottalanmiller
                    last edited by

                    VPNs are handy because you can do things like map a drive or run VoIP over them. But you can do all of those things in other ways too, if needed.

                    1 Reply Last reply Reply Quote 1
                    • NerdyDadN
                      NerdyDad
                      last edited by

                      With a JumpBox instead of a VPN, you would still be able to administer systems remotely, as if you were in front of the console. But, you would not be able to download files or stream media with a jump box. Am I understanding this correctly?

                      scottalanmillerS 1 Reply Last reply Reply Quote 1
                      • scottalanmillerS
                        scottalanmiller @NerdyDad
                        last edited by

                        @NerdyDad said in Linux Lab Project: Building a Linux Jump Box:

                        With a JumpBox instead of a VPN, you would still be able to administer systems remotely, as if you were in front of the console. But, you would not be able to download files or stream media with a jump box. Am I understanding this correctly?

                        That's correct. And that's an important part of the gapping.

                        1 Reply Last reply Reply Quote 1
                        • scottalanmillerS
                          scottalanmiller
                          last edited by

                          Ideally, as an admin, you would not want to hear audio from a server, or copy a file from your desktop to a server.

                          JaredBuschJ 1 Reply Last reply Reply Quote 2
                          • A
                            Alex Sage
                            last edited by

                            I understand that theory is that you setup all your security on the jumpbox and don't worry as much about the other systems... but doesn't a jumpbox provide a single target for penetration? Can't someone who gains access to the jumpbox access every other system that user has access too? I understand that your using keys, and not passwords...

                            scottalanmillerS 2 Replies Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller @Alex Sage
                              last edited by

                              @aaronstuder said in Linux Lab Project: Building a Linux Jump Box:

                              I understand that theory is that you setup all your security on the jumpbox and don't worry as much about the other systems... but doesn't a jumpbox provide a single target for penetration? Can't someone who gains access to the jumpbox access every other system that user has access too? I understand that your using keys, and not passwords...

                              The general theory should not be Jump security instead of others. It should be in addition to.

                              1 Reply Last reply Reply Quote 1
                              • scottalanmillerS
                                scottalanmiller @Alex Sage
                                last edited by

                                @aaronstuder said in Linux Lab Project: Building a Linux Jump Box:

                                I understand that your using keys, and not passwords...

                                You can use both. Of course if you use the Jump box solely to easy access and not to enhance it, you carry the risk of the Jump box being compromised. But you can mitigate this by increasing the security of the Jump box, adding security between the Jump box and the other hosts or both.

                                1 Reply Last reply Reply Quote 1
                                • JaredBuschJ
                                  JaredBusch @scottalanmiller
                                  last edited by

                                  @scottalanmiller said in Linux Lab Project: Building a Linux Jump Box:

                                  Ideally, as an admin, you would not want to hear audio from a server, or copy a file from your desktop to a server.

                                  As an admin, I upload new firmware to the /tftpboot folder all the time. Or I want to download, mass update, and re up config files. So if I cannot transfer files with SCP, how does this help me?

                                  scottalanmillerS 1 Reply Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller @JaredBusch
                                    last edited by

                                    @JaredBusch said in Linux Lab Project: Building a Linux Jump Box:

                                    @scottalanmiller said in Linux Lab Project: Building a Linux Jump Box:

                                    Ideally, as an admin, you would not want to hear audio from a server, or copy a file from your desktop to a server.

                                    As an admin, I upload new firmware to the /tftpboot folder all the time. Or I want to download, mass update, and re up config files. So if I cannot transfer files with SCP, how does this help me?

                                    You can use SCP, SCP is just an extension of the SSH protocol. The Jump box would be an SSH proxy. So you can do that trivially. Is it the recommend way to do this? Not normally, no. Do a lot of us do it because it is easy, yes. But ideally you want your file server to not be the jump box. You can easily make a non-jump file server for that task in another VM.

                                    JaredBuschJ 1 Reply Last reply Reply Quote 0
                                    • JaredBuschJ
                                      JaredBusch @scottalanmiller
                                      last edited by JaredBusch

                                      @scottalanmiller said in Linux Lab Project: Building a Linux Jump Box:

                                      @JaredBusch said in Linux Lab Project: Building a Linux Jump Box:

                                      @scottalanmiller said in Linux Lab Project: Building a Linux Jump Box:

                                      Ideally, as an admin, you would not want to hear audio from a server, or copy a file from your desktop to a server.

                                      As an admin, I upload new firmware to the /tftpboot folder all the time. Or I want to download, mass update, and re up config files. So if I cannot transfer files with SCP, how does this help me?

                                      You can use SCP, SCP is just an extension of the SSH protocol. The Jump box would be an SSH proxy. So you can do that trivially. Is it the recommend way to do this? Not normally, no. Do a lot of us do it because it is easy, yes. But ideally you want your file server to not be the jump box. You can easily make a non-jump file server for that task in another VM.

                                      Who said anything about a file server? Each PBX is a unique system with nothing tying them together except me managing them.

                                      Korora Desktop in Chicago -> Jump box -> Vultr node 1 (PBX A )
                                      Korora Desktop in Chicago -> Jump box -> Vultr node 2 (PBX B )
                                      Korora Desktop in Chicago -> Jump box -> Internal Node 1 (PBX C )

                                      scottalanmillerS 1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @JaredBusch
                                        last edited by

                                        @JaredBusch said in Linux Lab Project: Building a Linux Jump Box:

                                        @scottalanmiller said in Linux Lab Project: Building a Linux Jump Box:

                                        @JaredBusch said in Linux Lab Project: Building a Linux Jump Box:

                                        @scottalanmiller said in Linux Lab Project: Building a Linux Jump Box:

                                        Ideally, as an admin, you would not want to hear audio from a server, or copy a file from your desktop to a server.

                                        As an admin, I upload new firmware to the /tftpboot folder all the time. Or I want to download, mass update, and re up config files. So if I cannot transfer files with SCP, how does this help me?

                                        You can use SCP, SCP is just an extension of the SSH protocol. The Jump box would be an SSH proxy. So you can do that trivially. Is it the recommend way to do this? Not normally, no. Do a lot of us do it because it is easy, yes. But ideally you want your file server to not be the jump box. You can easily make a non-jump file server for that task in another VM.

                                        Who said anything about a file server? Each PBX is a unique system with nothing tying them together except me managing them.

                                        Korora Desktop in Chicago -> Jump box -> Vultr node 1 (PBX A )
                                        Korora Desktop in Chicago -> Jump box -> Vultr node 2 (PBX B )
                                        Korora Desktop in Chicago -> Jump box -> Internal Node 1 (PBX C )

                                        Oh, I misunderstood. You are uploading to the TFTP folder of the individual servers, not a central one on your jump box that you are using the jump box to push out. TFTP is a file server, but you have many of them that your jump is sending to, not one that they all pull from.

                                        1 Reply Last reply Reply Quote 0
                                        • black3dynamiteB
                                          black3dynamite
                                          last edited by

                                          How would a jump box used when access a Windows environment? Would I need to setup a jump box with a desktop environment like xfce or windows manager like i3. And then use something like Remmina to remote into a Windows Admin box to manage Servers and such.

                                          RamblingBipedR scottalanmillerS 2 Replies Last reply Reply Quote 0
                                          • RamblingBipedR
                                            RamblingBiped @black3dynamite
                                            last edited by RamblingBiped

                                            @black3dynamite said in Linux Lab Project: Building a Linux Jump Box:

                                            How would a jump box used when access a Windows environment? Would I need to setup a jump box with a desktop environment like xfce or windows manager like i3. And then use something like Remmina to remote into a Windows Admin box to manage Servers and such.

                                            You could setup SSH tunneling and just do secure RDP sessions over SSH. No desktop environment required on your jumpbox.

                                            http://www.linuxjournal.com/content/ssh-tunneling-poor-techies-vpn

                                            black3dynamiteB scottalanmillerS 2 Replies Last reply Reply Quote 3
                                            • 1
                                            • 2
                                            • 3
                                            • 3 / 3
                                            • First post
                                              Last post