[{"data":1,"prerenderedAt":91},["ShallowReactive",2],{"seo-verification":3,"marketplace-app-en-bastion-host":6},{"google":4,"bing":5},"EycwPY2XMyTkVzas3n1ygeNJFGAH513qrMjfDljzsMQ","",{"slug":7,"name":8,"description":9,"phase":10,"docsUrl":11,"logo":12,"github":13,"tagline":14,"longDescription":15,"features":16,"useCases":23,"steps":33,"faq":46,"specs":59,"compatibleOs":68,"relatedApps":70,"relatedPosts":86,"category":88},"bastion-host","Bastion Host","A secure entry point to your infrastructure. A configured, hardened SSH jump host with centralised audit logs.",1,"https:\u002F\u002Fservorbit.com\u002Fblog\u002Fheberger-bastion-host-vps","\u002Fbrand\u002Flogo\u002Fservorbit-m.svg",null,"A secure, hardened SSH entry point to your infrastructure, with centralised auditing.","A bastion (SSH jump host) is the single, hardened entry point through which all administrative connections to your private servers pass. Rather than exposing every machine, you expose only one reinforced host that is monitored and logged — drastically reducing your infrastructure's attack surface.\n\nDeployed on a dedicated VPS, this template configures and hardens the SSH service (attempt limiting, connection grace periods, disabling of unnecessary options), installs fail2ban to automatically ban malicious IPs, and enables system auditing (auditd) and a UFW firewall. SSH forwarding stays enabled to act as a jump to your internal servers, while keeping a centralised access log.",[17,18,19,20,21,22],"Hardened SSH: attempt limiting, grace period, unnecessary options disabled","fail2ban: automatic IP banning after repeated failures","System auditing (auditd) for traceability of access and commands","Pre-configured UFW firewall (SSH allowed, everything else closed)","SSH forwarding retained for jumping to private servers","Attack surface reduced to a single monitored entry point",[24,27,30],{"title":25,"body":26},"Access to private servers","Centralise all administrative connections through a single hardened host, instead of exposing each server on the Internet.",{"title":28,"body":29},"Access traceability","Keep a centralised log of who connects, when and to which servers, for auditing and compliance.",{"title":31,"body":32},"Attack surface reduction","Close direct SSH access to your internal machines and expose only a single reinforced, monitored entry point.",[34,37,40,43],{"title":35,"body":36},"Create the VPS","A VPS with 1 GB RAM, Ubuntu 22.04. The \"Bastion Host\" template hardens SSH and installs fail2ban, auditd and UFW automatically.",{"title":38,"body":39},"Add your public key","Add your public SSH key to the bastion (`~\u002F.ssh\u002Fauthorized_keys`) before disabling password authentication.",{"title":41,"body":42},"Configure the jump","From your machine, use the bastion as a `ProxyJump` (`ssh -J bastion utilisateur@serveur-prive`) to reach your internal servers.",{"title":44,"body":45},"Lock down direct access","Restrict SSH access on your private servers to the bastion's IP through their firewall, to close off any direct connection.",[47,50,53,56],{"q":48,"a":49},"What is a bastion (jump host)?","A bastion is a hardened server that acts as the single entry point to a private infrastructure. All administrative connections pass through it, which reduces the attack surface and centralises auditing.",{"q":51,"a":52},"What exactly does this template configure?","It hardens the SSH configuration (MaxAuthTries, LoginGraceTime, unnecessary options disabled), installs fail2ban, and enables the auditd system audit and a UFW firewall that allows only SSH.",{"q":54,"a":55},"Is SSH password authentication disabled automatically?","No, to avoid locking yourself out: the template hardens SSH without disabling password authentication. Add your public key first, then disable password authentication manually.",{"q":57,"a":58},"How do I use it as a jump host?","With OpenSSH's ProxyJump option: `ssh -J utilisateur@bastion utilisateur@serveur-prive`. SSH forwarding stays enabled on the bastion for this purpose.",{"ram":60,"cpu":61,"stack":62,"port":67},"1 GB","1 vCPU",[63,64,65,66],"SSH","fail2ban","auditd","UFW","22 (SSH)",[69],"ubuntu-24.04",[71,80],{"name":72,"slug":73,"categorySlug":74,"categoryName":75,"categoryColor":76,"logo":77,"tagline":78,"description":79},"CrowdSec","crowdsec","cybersecurity","Cybersecurity & Bastion","text-red-400 bg-red-500\u002F10","https:\u002F\u002Fcdn.jsdelivr.net\u002Fgh\u002Fselfhst\u002Ficons\u002Fsvg\u002Fcrowdsec.svg","Collaborative protection against attacks — behavioural detection and shared threat intelligence.","Collaborative protection against attacks. Behavioural detection and threat-intelligence sharing with the community.",{"name":81,"slug":82,"categorySlug":74,"categoryName":75,"categoryColor":76,"logo":83,"tagline":84,"description":85},"Fail2Ban Enhanced","fail2ban-enhanced","https:\u002F\u002Fcdn.jsdelivr.net\u002Fgh\u002Fselfhst\u002Ficons\u002Fpng\u002Ffail2ban.png","Automatic intrusion blocking — a hardened, production-ready configuration out of the box.","Automatic blocking of intrusion attempts, with a production-optimised configuration and real-time alerts.",[87],"heberger-bastion-host-vps",{"key":89,"slug":74,"name":75,"objective":90,"icon":89,"color":76},"security","Harden infrastructure security.",1785628467562]