Bastion Host Flashcards
Is the bastion host located in a public or private subnet?
In the public subnet
What does a bastion host allow you to do?
allows you to connect to your EC2 instances in a private subnet using RDP or SSH
How is a bastion host used?
Log into the bastion host from your desktop. Then from the bastion host, log into your EC2 instances that reside in the private subnet.
What is a common nickname given to bastion hosts?
jump box
True or False: It’s best practice to allow all IP addresses to reach your bastion host so you can work from anywhere?
False. Lock down the host to only known IP addresses.
What are the two most likely ports that should be open to a bastion host?
22 (SSH), 3389(RDP)
What is the difference between SSH and RDP
- SSH is most common for Linux command line access
- RDP allows for access to an OS user interface in Linux or Windows.
True or False: You connect to a bastion host over the internet?
True: Since the Bastion host lives in a public subnet, it can be reached from the internet. Follow security best practices.
Does a Bastion host allow your private subnet instances outbound access to the internet?
No. Bastion does not enable outgoing requests from instances.