Bastion Quickstart en
Bastion Quickstart en
Reference: https://doc.wallix.com/en/bastion/9.0.2/Bastion-quickstart
Copyright © 2021 WALLIX
WALLIX Bastion 9.0.2 – Quick Start Guide
Table of Contents
1. Introduction ............................................................................................................................ 3
1.1. Preamble ..................................................................................................................... 3
1.2. Copyright & Licenses .................................................................................................. 3
1.3. Legend ........................................................................................................................ 3
1.4. About this document ................................................................................................... 3
2. Connection to a physical WALLIX Bastion appliance ............................................................. 5
2.1. Powering on ................................................................................................................ 5
2.2. Physical connection .................................................................................................... 5
2.3. Sizing of the physical appliance .................................................................................. 5
3. Connection to a virtual WALLIX Bastion appliance ................................................................ 6
3.1. Deploying on-premises images ................................................................................... 6
3.1.1. Retrieving the ISO and the on-premises images .............................................. 6
3.1.2. Installing the on-premises images .................................................................... 7
3.2. Deploying Cloud tenant images .................................................................................. 8
3.2.1. Retrieving the Cloud tenant images ................................................................. 8
3.2.2. Installing the Cloud tenant images ................................................................... 8
3.3. Configuring the virtual machine ................................................................................... 9
3.3.1. Setting the CPUs and the memory ................................................................. 10
3.3.2. Setting the number of concurrent sessions .................................................... 11
3.3.3. Extending the disk space capacity ................................................................. 12
3.4. Deploying High-Availability in a virtual environment .................................................. 13
4. Logical connection ............................................................................................................... 17
5. System and network configuration ....................................................................................... 18
5.1. Factory settings ......................................................................................................... 18
5.2. Pre-configuration of TCP/UDP network ports ............................................................ 18
5.2.1. Communication from WALLIX Bastion ............................................................ 18
5.2.2. Communication to WALLIX Bastion ................................................................ 19
5.3. Configuring the appliance from the Web interface ..................................................... 19
5.3.1. Accessing the Web interface .......................................................................... 19
5.3.2. Encryption configuration ................................................................................. 20
5.3.3. Network configuration ..................................................................................... 21
5.3.4. Time service configuration ............................................................................. 22
5.3.5. SMTP server configuration ............................................................................. 23
5.4. Changing self-signed certificates of services ............................................................. 23
5.4.1. Changing the Web interface certificate ........................................................... 23
5.4.2. Changing the RDP proxy certificate ............................................................... 24
5.4.3. Changing the SSH proxy host key ................................................................. 24
6. License key activation .......................................................................................................... 26
7. First steps ............................................................................................................................ 28
8. Contact WALLIX Bastion Support ........................................................................................ 29
2
WALLIX Bastion 9.0.2 – Quick Start Guide
Chapter 1. Introduction
1.1. Preamble
Thank you for choosing WALLIX Bastion.
The WALLIX Bastion solution is marketed in the form of a dedicated, ready-to-use server or as a
virtual device for the following virtual environments:
This product has been engineered with the greatest care by our teams at WALLIX and we trust that
it will deliver complete satisfaction.
WALLIX
Service Support
250 bis, Rue du Faubourg Saint-Honoré
75008 PARIS
FRANCE
1.3. Legend
prompt $ command to input <parameter to replace>
command output
on one or more lines
prompt $
3
WALLIX Bastion 9.0.2 – Quick Start Guide
If your device is a physical appliance, refer to Chapter 2, “Connection to a physical WALLIX Bastion
appliance”, page 5.
If your device is a virtual appliance, refer to Chapter 3, “Connection to a virtual WALLIX Bastion
appliance”, page 6.
4
WALLIX Bastion 9.0.2 – Quick Start Guide
Chapter 2. Connection to a physical
WALLIX Bastion appliance
2.1. Powering on
Remove the appliance from its packaging and connect the two redundant power supplies at the
back of the device to two 220-volt electrical power sockets using the power cords provided.
2.2. Physical connection
Caution:
When adding a network card, the four Ethernet ports eth4 to eth7 at the back of the device
are set from right to left.
• in console mode, by connecting a screen to the VGA output and a keyboard to a USB slot on
either the front or back of the unit
• in network mode, from a workstation running Linux, Windows or Mac OS X that is directly
connected to the device with an RJ45 crossed cable (not provided), or through your network if
the 192.168.10.5 address is available on it. You must use the Ethernet port labelled “1” at the
back of the unit.
5
WALLIX Bastion 9.0.2 – Quick Start Guide
Chapter 3. Connection to a virtual
WALLIX Bastion appliance
WALLIX Bastion can be deployed in the following virtual environments:
WALLIX provides a generic ISO and specific images for the above-mentioned environments.
• the ISO
• KVM
• Hyper-V
• OpenStack
• VMware
1. Connect from you Web browser to https://support.wallix.com from you Web browser
and enter your WALLIX Support credentials.
2. Click on the “Downloads” tab and download the desired image and the corresponding integrity
check files for WALLIX Bastion 9.0.2. The available images are as follows:
• the generic image (.iso)
• the Hyper-V image (.vhdx)
• the KVM image (.qcow2)
• the OpenStack image (.qcow2)
• the VMware image (.ova)
6
WALLIX Bastion 9.0.2 – Quick Start Guide
3. Check the integrity of the downloaded image using a platform-dependent tool, such as
HashCheck on a Windows environment (https://github.com/gurnec/HashCheck) or by
running the following command for Linux-based systems:
$ sha256sum -c bastion-$VERSION-PLATFORM.PLATFORM_EXTENSION.sha256sum
where the values for “PLATFORM” and “PLATFORM_EXTENSION” must both match
respectively the image type and the image file extension, such as described in the table below:
PLATFORM PLATFORM_EXTENSION
Hyper-V vhdx
KVM qcow2
OpenStack qcow2
VMware ova
Important:
The WALLIX Bastion .vhdx disk image must be imported to create a generation 1 virtual
machine.
The WALLIX Bastion .iso disk image must be imported to create a generation 2 virtual
machine.
For instructions on how to import the downloaded WALLIX Bastion .vhdx or .iso
disk image into a Hyper-V hypervisor, please refer to the official documentation
at https://docs.microsoft.com/en-us/windows-server/virtualization/hyper-
v/hyper-v-on-windows-server.
3.1.2.2. KVM
The virtual machine can be instantiated and the downloaded WALLIX Bastion .qcow2 disk image
can be attached using the “libvirt” utility. For further information, please refer to https://
wiki.libvirt.org.
3.1.2.3. OpenStack
For instructions on how to import the downloaded WALLIX Bastion .qcow2 disk image into
OpenStack, please refer to the official documentation at https://docs.openstack.org.
Note:
When a raw image is needed for this platform, it is possible to convert the downloaded
WALLIX Bastion .qcow2 disk image using the “qemu-img” utility.
As an example, the downloaded .qcow2 disk image for WALLIX Bastion 8.0.0 (i.e.
“bastion-8.0.0-openstack.qcow2”) can be converted to a raw format (i.e. “bastion-8.0.0-
openstack.img”) by running the following command:
7
WALLIX Bastion 9.0.2 – Quick Start Guide
3.1.2.4. VMware
For instructions on how to import the downloaded WALLIX Bastion .ova image into a VMware
hypervisor, please refer to the official documentation at https://docs.vmware.com.
Note:
Only VMware vSphere versions from ESXi 5.5 inclusive are supported.
• AWS
• GCP
• Microsoft Azure
Note:
When deploying WALLIX Bastion in an AWS infrastructure, the default password
for the factory-set administrator account corresponds to “admin-{instanceID}” where
“instanceID” is the EC2 instance ID.
As an example, if this ID corresponds to “i-04a4e1764e07bd88e” then the default
password will be “admin-i-04a4e1764e07bd88e”.
8
WALLIX Bastion 9.0.2 – Quick Start Guide
For instructions on how to deploy the virtual machine on a Google Cloud environment from
the shared image, please refer to the official documentation at https://cloud.google.com/
compute/docs.
3.2.2.3. Microsoft Azure
In order to access the WALLIX Bastion image from the Azure Marketplace, it is required to:
1. Connect from your Web browser to the Microsoft Azure portal at https://
portal.azure.com.
2. On the home page, click on “Create a resource”.
3. On the “New” page, enter “WALLIX” in the search field then select “WALLIX Bastion”.
4. On the page dedicated to the image for WALLIX Bastion, it is then possible either to create and
configure the virtual machine or start with a pre-set configuration.
For instructions on how to create a virtual machine on Microsoft Azure Cloud environment, please
refer to the official documentation at https://docs.microsoft.com/en-us/azure.
Note:
The virtual machine creation wizard on the Microsoft Azure portal and the programmatic
approaches via Azure CLI or Powershell request the creation of a user and password for
the virtual machine.
Please note that these credentials will be requested to log on to WALLIX Bastion from
the SSH admin channel (port 2242) and will replace the connection with the predefined
“wabadmin” user.
The screenshots describe configuration from Hyper-V hypervisor and are intended for
example purposes only.
The parameters of the virtual machine (CPU, RAM, etc.) require to be adjusted to fit the needs of
your environment.
It is advised, for performance reason, to keep the resources above the following values: 2 CPUs,
4GB of RAM and 30GB HHD.
The table below provides the specifications by number of registered resources. It assumes that the
maximum number of concurrent sessions is less than 8% of the number of registered resources:
9
WALLIX Bastion 9.0.2 – Quick Start Guide
(1)
Sizing information assuming that a typical RDP session consumes less than 2MBytes/s network
bandwith.
The display resolution is 1440x850 pixels and recording files are not encrypted.
5. On the same tab, select "Memory" and set the size according to the number of GB in the above
table (see Table 3.1, “Resource specifications”, page 9):
10
WALLIX Bastion 9.0.2 – Quick Start Guide
The reservation operation is necessary to ensure that the resources are available when needed.
11
WALLIX Bastion 9.0.2 – Quick Start Guide
# pvcreate /dev/sdb
7. Extend the logical volume vg00:
12
WALLIX Bastion 9.0.2 – Quick Start Guide
# e2fsck -f /dev/vg00/lvwab
11. Resize the filesystem on the new volume:
# resize2fs /dev/vg00/lvwab
The WALLIX Bastion HA feature is designed to answer hardware issues related to disk,
motherboard, network card, etc and is not supported through virtual appliances.
1. Proceed with the deployment of the OVF template the same way as the StandAlone mode.
2. Select the cluster and click on the "File" menu then select "Deploy OVF Template".
3. On the "Deploy OVF Template" window, click on "Browse" and select the file "wab_esx4.ovf"
in the "wab_esx4" directory:
13
WALLIX Bastion 9.0.2 – Quick Start Guide
4. Click on "Next" until you reach the "Name and Location" section on the left part of window, then
specify a datacenter:
5. Click on "Next" and select the desired ESX host on which you want to import the VM:
14
WALLIX Bastion 9.0.2 – Quick Start Guide
15
WALLIX Bastion 9.0.2 – Quick Start Guide
8. When you start the VM, a recommendation window is displayed if the settings of the DRS are
set to manual: just click on "Power on" at the bottom of the window:
• You now have a hardware resilient WALLIX Bastion using the VMware HA feature.
16
WALLIX Bastion 9.0.2 – Quick Start Guide
Chapter 4. Logical connection
You can now connect to the appliance and log on using the following credentials:
• Login: wabadmin
• Password: SecureWabAdmin
In console mode:
In network mode:
Important:
For security reasons, all system passwords must be immediately changed on first
connection. By default, the "wabadmin" user is configured with minimum privileges. The
"wabsuper" password can be passed to the "super" command to access higher privileges,
including the ability to get access to "root" privileges using the "sudo" command, which
uses the same password.
17
WALLIX Bastion 9.0.2 – Quick Start Guide
wabadmin$super
[sudo] password for wabsuper:
wabsuper$sudo -i
[sudo] password for wabsuper:
#
5.1. Factory settings
The WALLIX Bastion appliance is delivered with the following factory configuration:
If you wish to change temporarily your WALLIX Bastion IP address from the console before
configuring the Web interface, enter the command below with the desired IP address:
• SSH: 22
• RDP: 3389
• HTTP/HTTPS: 80/443
• SMTP: 25
• SMTPS: 465
• SMTP+STARTTLS: 587
• NTP: 123
18
WALLIX Bastion 9.0.2 – Quick Start Guide
• DNS: 53
• Kerberos external authentication: 88
• LDAP external authentication: 389
• LDAP over SSL external authentication: 636
• RADIUS external authentication: 1812
• TACACS+ external authentication: 49
• NFS network storage: 2049
• CIFS network storage: 445
• SMB for password management: 139 | 445
• Syslog: 514
• SNMP: 162 for trap notifications
• SSH/SFTP/TELNET/RLOGIN proxy: 22
• RDP/VNC proxy: 3389
• SNMP: 161 for read/write access to OIDs
• WALLIX Bastion administration command line interface (SSHADMIN console): 2242
• WALLIX Bastion administration Web interface (GUI): 443
https://bastion_ip_address/ui or https://<bastion_name>/ui
Note:
Please refer to the Release Notes to check the list of browsers supported by WALLIX
Bastion 9.0.2.
When using old web browsers, it may be necessary to lower the security settings of
the WALLIX Bastion web server in order to allow connections. To do so, please refer
to Section 15.27, “Cryptographic configuration of services” in the Administration Guide.
However we recommend rather using a modern web browser, such as Firefox or Chrome,
to maintain a satisfactory security level.
You can access the legacy interface by clicking on the “Legacy interface” icon at the top
of the page.
19
WALLIX Bastion 9.0.2 – Quick Start Guide
Warning:
For security reasons, it is required to change the administrator account password on first
login (from the My Preferences page accessible by hovering your mouse over your user
name at the top right of the screen).
Figure 5.1. Login screen
5.3.2. Encryption configuration
The encryption of WALLIX Bastion secures sensitive data (such as target accounts' credentials,
local users' passwords, Web interface connections, SSH and RDP proxy connections, etc.) by using
a strong cryptographic algorithm. This algorithm uses an encryption key which is secret and unique
to your WALLIX Bastion.
When you first log on to WALLIX Bastion, it is recommended to secure this encryption key by
defining a passphrase with a minimum length of 12 characters. This creates an additional protection
to prevent a malicious user from decrypting your data. Make sure you remember the passphrase
as it must be entered at each reboot of WALLIX Bastion and when changing the passphrase.
20
WALLIX Bastion 9.0.2 – Quick Start Guide
You can go back at any time to the “Encryption” page on the “Configuration” menu either to check
that your WALLIX Bastion is ready and secured or to change the passphrase.
5.3.3. Network configuration
From System/Network on the left menu, you access the "Network" page to enter all the parameters
required for correct WALLIX Bastion operation.
21
WALLIX Bastion 9.0.2 – Quick Start Guide
22
WALLIX Bastion 9.0.2 – Quick Start Guide
23
WALLIX Bastion 9.0.2 – Quick Start Guide
Note:
The new certificate generated as a .pem file must be converted into a .crt file prior to
be replaced in the directory.
Once the files have been replaced, it may be necessary to restart the Apache service by entering
the following command:
Note:
These files are also modified by applying the X509 authentication configuration
procedure. For further information, refer to Section 9.7, “X509 certificate authentication
configuration” in the Administration Guide.
If High-Availability is set, the directory into which the certificates are gathered is shared
between both nodes. The procedure is to be applied on the active node only.
You could later generate back a self-signed certificate with the following command:
# WABGuiCertificate selfsign -f
Once the files have been replaced, restart RDP proxy by entering the following command:
Note:
You could later generate back a self-signed certificate with the following command:
24
WALLIX Bastion 9.0.2 – Quick Start Guide
The host key must use RSA algorithm and a minimum 4,096-bit length is recommended.
To install your host key using ED25519 format, copy it on WALLIX Bastion in the directory /var/
wab/etc/ssh/server_ed25519.key location.
Note:
You can generate an SSH proxy host key on WALLIX Bastion by deleting the current host
keys and executing the generator script with the following command:
# rm /var/wab/etc/ssh/server_rsa.key
# rm /var/wab/etc/ssh/server_ed25519.key
# WABSshServerGenRsaKey.sh
25
WALLIX Bastion 9.0.2 – Quick Start Guide
• the license type for a perpetual license agreement (“Legacy Bastion license”)
• the pack for a subscription license agreement (“WALLIX license”)
• the add-ons for a subscription license agreement (“WALLIX license”)
• the license expiration date
• the number of concurrent connections to the Bastion (i.e. primary connections)
Note:
Connections of the administrator account with the "product_administrator" profile are
not counted.
Note:
Each target is only counted once, regardless of the number of groups into which it is
included.
Target accounts which can be used as scenario accounts are not counted.
• when WALLIX Password Manager is associated with the license key, the number of targets
included in groups which can be declared to check out the accounts' credentials
Note:
Each target is only counted once, regardless of the number of groups into which it is
included.
• when WALLIX Password Manager is associated with the license key, the number of
clients using WALLIX Application-to-Application Password Manager (also called “WAAPM”).
Documentation related to WAAPM can be downloaded from WALLIX Support portal (https://
support.wallix.com [https://support.wallix.com/]).
To obtain a license, a context file must be created and sent to WALLIX Support (https://
support.wallix.com/). To do so, click on the “Download context file” button to generate and
26
WALLIX Bastion 9.0.2 – Quick Start Guide
download a context file and send it to the WALLIX Support Team which will provide you with a
license key update.
Once you have received the license update file, upload or drag-and-drop it in the “License update”
section and click on the “Apply” button.
Once you have installed a license on WALLIX Bastion, it will be possible to revoke it by clicking on
the “Revoke” button. The legacy licences (“Legacy Bastion license”) will be revoked immediately.
The current licenses (“WALLIX license”) will become invalid 15 days after performing the revocation.
27
WALLIX Bastion 9.0.2 – Quick Start Guide
Chapter 7. First steps
Follow the steps below to start using WALLIX Bastion. For more advanced features, please refer
to the Administration Guide or the User Guide.
Refer to Section 3.3, ““My Authorizations” menu - Session authorizations” and Section 3.4, ““My
Authorizations” menu - Password authorizations” in the User Guide.
See also the various sub-headings of Chapter 4, “Logging on to target devices” in the User
Guide.
28
WALLIX Bastion 9.0.2 – Quick Start Guide
Web: https://support.wallix.com/
Telephone: (+33) (0)1 70 36 37 50 for Europe, Middle East and Africa and (+1) 438-777-9439 for
the Americas
29