LINUXOR.SK ... open source notes ...

Balabit - RDP connections (site 1)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Connection and channel policies

noteThe table of ORG_RDP_JumpServer in my design carries NAME = PARTNER1_RDP_JumpServer, a copy-and-paste slip in the document: two connections cannot share a name, and the user access guide and the site 2 configuration call it ORG_RDP_JumpServer. It is kept below as written.

The three RDP connection policies of the site 1 cluster as recorded in December 2017: one per company, each on its own port of the production address, each leading to one Windows jump server (two addresses for partner 2).

ItemValue
WhereSCB web interface, RDP Control > Connections
Clusterdc1-s-xblb001, production address 10.11.16.65 and 2001:db8:a1:c0e::f:1
Firmware at the time5 LTS (5.0.3)
SourceMy design document, version 0.5 of 2017-12-01 (draft), chapter 7.5.1
Not in itThe later connections of partner 3 (port 2207) and of the cloud team of partner 1 (2212), which are only in the connection summary and the user access guide

The answers

ini
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapter 7.5.1

RDP Control > Connections > PARTNER1_RDP_JumpServer > BASIC SETTINGS / ENABLED = Yes
RDP Control > Connections > PARTNER1_RDP_JumpServer > BASIC SETTINGS / NAME = PARTNER1_RDP_JumpServer
RDP Control > Connections > PARTNER1_RDP_JumpServer > BASIC SETTINGS / FROM = 0.0.0.0/0 / ::/0
RDP Control > Connections > PARTNER1_RDP_JumpServer > BASIC SETTINGS / TO = 10.11.16.65/32 / 2001:db8:a1:c0e::f:1/128
RDP Control > Connections > PARTNER1_RDP_JumpServer > BASIC SETTINGS / PORT = 3389
RDP Control > Connections > PARTNER1_RDP_JumpServer > TARGET / INBAND DESTINATION SELECTION = TARGETS - DOMAIN (PORT): / 10.11.16.201 (3389) / EXCEPTIONS - DOMAIN (PORT): / N/A / APPEND DOMAINS – DOMAIN: / N/A / DNS SERVER: / N/A
RDP Control > Connections > PARTNER1_RDP_JumpServer > SNAT / USE THE IP ADDRESS OF SCB = Yes
RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / ACT AS A REMOTE DESKTOP GATEWAY = No
RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / VERIFY SERVER CERTIFICATE = No
RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / ENABLE INDEXING / PRIORITY / INDEXING POLICY = Yes / normal / default
RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / CONNECTION RATE LIMIT = 
RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / CHANNEL DATABASE CLEANUP = 
RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / RDP SETTINGS = PARTNER1_RDP
RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / AUDIT POLICY = default
RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / LDAP SERVER = AD.EXAMPLE.NET
RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / BACKUP POLICY = PARTNER1-BACKUP
RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / CREDENTIAL STORE = 
RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / CHANNEL POLICY = PARTNER1-TERMINAL-ONLY
RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / SIGNING CA = 
RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / USERMAPPING POLICY = 
RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / ARCHIVE/CLEANUP POLICY = PARTNER1-ARCHIVE
RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / AA PLUGIN = 
RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / GATEWAY AUTHENTICATION = No
RDP Control > Connections > PARTNER1_RDP_JumpServer > OTHER SETTINGS / LOG AUDIT TRAILS DOWNLOADS = Yes

RDP Control > Connections > ORG_RDP_JumpServer > BASIC SETTINGS / ENABLED = Yes
RDP Control > Connections > ORG_RDP_JumpServer > BASIC SETTINGS / NAME = PARTNER1_RDP_JumpServer
RDP Control > Connections > ORG_RDP_JumpServer > BASIC SETTINGS / FROM = 0.0.0.0/0 / ::/0
RDP Control > Connections > ORG_RDP_JumpServer > BASIC SETTINGS / TO = 10.11.16.65/32 / 2001:db8:a1:c0e::f:1/128
RDP Control > Connections > ORG_RDP_JumpServer > BASIC SETTINGS / PORT = 2202
RDP Control > Connections > ORG_RDP_JumpServer > TARGET / INBAND DESTINATION SELECTION = TARGETS - DOMAIN (PORT): / 10.11.16.193 (3389) / EXCEPTIONS - DOMAIN (PORT): / N/A / APPEND DOMAINS – DOMAIN: / N/A / DNS SERVER: / N/A
RDP Control > Connections > ORG_RDP_JumpServer > SNAT / USE THE IP ADDRESS OF SCB = Yes
RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / ACT AS A REMOTE DESKTOP GATEWAY = No
RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / VERIFY SERVER CERTIFICATE = No
RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / ENABLE INDEXING / PRIORITY / INDEXING POLICY = Yes / normal / default
RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / CONNECTION RATE LIMIT = 
RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / CHANNEL DATABASE CLEANUP = 
RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / RDP SETTINGS = ORG_RDP
RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / AUDIT POLICY = default
RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / LDAP SERVER = AD.EXAMPLE.NET
RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / BACKUP POLICY = ORG-BACKUP
RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / CREDENTIAL STORE = 
RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / CHANNEL POLICY = ORG-TERMINAL-ONLY
RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / SIGNING CA = 
RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / USERMAPPING POLICY = 
RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / ARCHIVE/CLEANUP POLICY = ORG-ARCHIVE
RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / AA PLUGIN = 
RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / GATEWAY AUTHENTICATION = No
RDP Control > Connections > ORG_RDP_JumpServer > OTHER SETTINGS / LOG AUDIT TRAILS DOWNLOADS = Yes

RDP Control > Connections > PARTNER2_RDP_JumpServer > BASIC SETTINGS / ENABLED = Yes
RDP Control > Connections > PARTNER2_RDP_JumpServer > BASIC SETTINGS / NAME = PARTNER2_RDP_JumpServer
RDP Control > Connections > PARTNER2_RDP_JumpServer > BASIC SETTINGS / FROM = 10.11.20.192/26 / ::/0
RDP Control > Connections > PARTNER2_RDP_JumpServer > BASIC SETTINGS / TO = 10.11.16.65/32 / 2001:db8:a1:c0e::f:1/128
RDP Control > Connections > PARTNER2_RDP_JumpServer > BASIC SETTINGS / PORT = 2204
RDP Control > Connections > PARTNER2_RDP_JumpServer > TARGET / INBAND DESTINATION SELECTION = TARGETS - DOMAIN (PORT): / 10.11.19.177 (3389) / 2001:db8:a1:b5f::f:1 (3389) / EXCEPTIONS - DOMAIN (PORT): / N/A / APPEND DOMAINS – DOMAIN: / N/A / DNS SERVER: / N/A
RDP Control > Connections > PARTNER2_RDP_JumpServer > SNAT / USE THE IP ADDRESS OF SCB = Yes
RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / ACT AS A REMOTE DESKTOP GATEWAY = No
RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / VERIFY SERVER CERTIFICATE = No
RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / ENABLE INDEXING / PRIORITY / INDEXING POLICY = Yes / normal / default
RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / CONNECTION RATE LIMIT = 
RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / CHANNEL DATABASE CLEANUP = 
RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / RDP SETTINGS = PARTNER2_RDP
RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / AUDIT POLICY = default
RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / LDAP SERVER = AD.EXAMPLE.NET
RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / BACKUP POLICY = PARTNER2-BACKUP
RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / CREDENTIAL STORE = 
RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / CHANNEL POLICY = PARTNER2-TERMINAL-ONLY
RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / SIGNING CA = 
RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / USERMAPPING POLICY = 
RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / ARCHIVE/CLEANUP POLICY = PARTNER2-ARCHIVE
RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / AA PLUGIN = 
RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / GATEWAY AUTHENTICATION = No
RDP Control > Connections > PARTNER2_RDP_JumpServer > OTHER SETTINGS / LOG AUDIT TRAILS DOWNLOADS = Yes
FieldWhat it means
FROMClient networks allowed to use the connection. Any address for partner 1 and the organisation; 10.11.20.192/26 (IPv4) for partner 2
TO, PORTThe SCB address and port the client connects to; the port selects the connection
INBAND DESTINATION SELECTIONThe targets the user may name in the username, each with its port. Anything else is refused
USE THE IP ADDRESS OF SCBSource NAT: the jump server sees the SCB's address, not the client's
ACT AS A REMOTE DESKTOP GATEWAY = NoThe SCB does not play an RD Gateway; the client speaks plain RDP to it
VERIFY SERVER CERTIFICATE = NoThe SCB accepts any certificate of the jump server
ENABLE INDEXINGThe trails are indexed with the default indexer policy at normal priority, so the screen content can be searched
RDP SETTINGS, CHANNEL POLICY, BACKUP POLICY, ARCHIVE/CLEANUP POLICYThe per-company objects: RDP settings, channel policies, backup and archive policies
AUDIT POLICY = default, LDAP SERVER = AD.EXAMPLE.NETShared by every connection: audit policy, LDAP server policy
Empty fieldsNo rate limit, no per-connection database cleanup (the global 180 days apply), no credential store, no usermapping, no AA plugin, no signing CA
LOG AUDIT TRAILS DOWNLOADS = YesEvery download of a trail from the web interface is logged

The partner 2 target 10.11.19.177 is not one of the jump servers listed in the design's chapter 4.1.8. The later connection summary gives that address to dc1-a-vcrdp003, as the second target of PARTNER3_RDP_JumpServer, whose clients come from the same 10.11.20.192/26. The documents do not say whether the partner 2 connection was renamed or replaced.

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
USE THE IP ADDRESS OF SCB = YesStill the default ("use the IP address of a SPS logical interface"); the alternatives are the client's original address or a fixed address
ACT AS A REMOTE DESKTOP GATEWAY = NoThe RD Gateway mode still exists
VERIFY SERVER CERTIFICATE = NoSPS does not allow RDP connections to Windows servers that use SHA-1 signed certificates
GATEWAY AUTHENTICATION = NoThe vendor's security checklist, in SCB 5 and SPS 9.0 alike: "Always use gateway authentication to authenticate clients. Do not trust the source IP address of a connection, or the result of server authentication."
Inband destination selectionThe syntax is unchanged; since 8.0 LTS SPS no longer splits RDP UPN user names into user and domain

The settings in the table are still documented in SPS 9.0; the rest of the page was not checked. The checklist's sentence on gateway authentication describes exactly what this design did not do.

← solutionz