Skip to main content
Support
0
Contact us
Nederlands
Deutsch
Español
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareers
Cloud Compute

With Cloud Compute, you have access anytime and anywhere to a portal through which you can configure your entire IT environment from wherever you are in the world.

Cloud Storage

Reliable access to your files, infrastructure, and applications at all times – with no interruptions or delays. At Worldstream, we offer a variety of storage solutions.

Flexible cloud icon
Flexible cloud
Private cloud icon
Private cloud
Bare metal icon
Bare Metal Compute
Hollow cube icon
Object storage
Hollow cube icon
File storage
Block storage icon
Block storage
Backup storage icon
Backup storage
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

All Servers

Choose your Dedicated Server now. Custom or Instant Delivery. Powerhouse servers built for your use case.

Use Cases

Whatever your use case, we’re here to help you find the ideal solution.

Deal servers icon
Deals
AMD servers icon
AMD Processors
AI servers icon
Intel Processors
Hollow cube icon
Virtualisation, Containerisation and Orchestration
Hollow cube icon
Websites and Applications
Hollow cube icon
Gaming and Streaming Infrastructure

24/7/365 support with an average response time of just 7 minutes. Thanks to our own data centers, our engineers can go directly to your server for fast, hands-on assistance. Email or call us anytime.

Smart outsourcing

Some IT creates added value, while other types are supportive. Use that as a starting point for outsourcing.

Cost Efficiency

Complete IT packages may seem like the safe option, but when you consider the costs, other choices often make more sense.

IT flexibility & control

Outsourcing doesn’t mean losing control; it actually provides more flexibility and control.

Cloud repatriation

The cloud is not a final destination: You should continuously evaluate and adjust your cloud environment as needs evolve.

Financial services
Logistics & Transportation
Retail & E-commerce
Media & Entertainment
Tech & Software Development
Security
Managed Service Providers
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

Chat with usContact us
About WorldstreamAbout the technologyCasesKnowledge base
About usMeet the teamJobsBecome a resellerCertificationsOur data centersOur networkDDoS ProtectionAMD EPYC serversTechnology PartnersOperating SystemsAll casesEasyTerraDutch Drone CompanyPerfGridArticlesFAQNews and BlogsProducts and Services
Contact us

Call +31 (0) 174 – 712 117

Industriestraat 53, Naaldwijk

Nederlands
Deutsch
Español
0
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareersAbout WorldstreamAbout the technologyCasesKnowledge baseMy Worldstream
Contact
Support
NederlandsDeutschEspañol
  1. HomeHome
  2. Knowledge Base
  3. Networking
  4. SSH bastion hosts: a single, hardened way into your private servers

SSH bastion hosts: a single, hardened way into your private servers

Applies to General networking concept, SSH accessAudience Server administrators, security-conscious teamsLast reviewed September 2026

Quick answer

A bastion host, also called a jump host, is a single, carefully hardened server that holds SSH access to a private network. You connect to it first, then hop from there to the server you actually want, so individual servers on the private network never need their own public SSH exposure at all. That leaves exactly one server's SSH surface to lock down, watch and patch, instead of every server on the network being independently exposed.

On this page
  • The problem it solves
  • How the hop works
  • Making two hops feel like one
  • Where the bastion sits

The problem it solves

If every server on a private network also has SSH open to the public internet, each one is its own independent target: its own login attempts to watch, its own sshd version to keep patched, its own configuration that can quietly drift out of line with the rest. Multiply that by however many servers you run, and you've multiplied the attack surface by the same number, even though in practice the same handful of people need access to all of them.

A bastion host inverts that. Instead of every server being reachable from the internet, only the bastion is. Every other server on the private network keeps SSH open only to internal traffic, reachable from the bastion but not from outside it. There's still exactly one door with a lock, but now there's only one door.

How the hop works

You connect to the bastion with your usual SSH client and credentials. From a session on the bastion, you then connect onward to the actual target server, which is only reachable from inside the private network the bastion sits on the edge of. Two separate SSH connections happen, one to the bastion and one from the bastion to the target, but the target server only ever sees a connection arriving from the bastion's private address, never directly from the internet.

Because the bastion is the one server with any public exposure at all, it's worth treating it differently to the servers behind it: minimal software installed, aggressive patching, key-only login, and close attention to its logs, along the same lines covered in How to improve your SSH security. A bastion that's neglected defeats the purpose, since it becomes the one weak point that grants access to everything behind it.

Making two hops feel like one

Manually SSHing into the bastion, then SSHing again from there to the target, works but gets tedious fast, and it means your private key (or at least an agent that can use it) needs to be usable from the bastion too. Two common configuration patterns avoid that:

1

ProxyJump

OpenSSH's -J flag, or a ProxyJump line in your SSH config, tells your own client to route the connection through the bastion automatically:

ssh -J user@bastion-ip user@target-private-ip

Or set it once in ~/.ssh/config so a plain ssh target does the same thing without typing it out each time:

Host target
    HostName target-private-ip
    User user
    ProxyJump user@bastion-ip

With ProxyJump, your client opens the connection to the target through the bastion, but the bastion itself never holds your private key. It's still a single command from your side, even though it's technically two hops.

2

SSH agent forwarding

Agent forwarding is the older approach: it lets a session on the bastion make use of the SSH key held by the agent running on your own machine, without ever copying the private key itself to the bastion. It works, but it's worth understanding what it grants: for as long as your forwarded session is open, anything running on the bastion under your account could, in principle, ask your agent to sign a request for another destination. ProxyJump avoids that exposure entirely, since it never involves the bastion in key handling at all, which is why it's generally the preferred pattern for a bastion setup today.

Where the bastion sits

A bastion typically sits at the edge of a private network segment, with one leg reachable from the internet and the other reachable by, or attached to, the private network holding the servers it protects. See Connecting servers over a private VLAN for how that private segment itself is put together; the bastion is what makes it practical to actually manage servers on it without opening the whole segment to the internet.

Related articles

  • How to improve your SSH security
  • Creating an SSH key pair
  • Connecting servers over a private VLAN
Was this article helpful?

Solid IT. No Surprises

Sparring partner for IT maturity
Eliminating barriers so you can run
Predictable and transparant costs

Contact

  • Industriestraat 53, Naaldwijk
  • Payment Methods
  • Abuse
  • Developers Resources
  • Network Operations Center
  • About us
  • Meet the team
  • Jobs
  • Become a reseller
  • Certifications
  • Our data centers
  • Our network
  • DDoS Protection
  • AMD EPYC servers
  • Technology Partners
  • Operating Systems
  • Overview
  • FAQ
  • Cases
  • News & Blogs
  • Use Cases
Nederlands
Deutsch
Español
Nederlands
Deutsch
Español
  • Legal
  • Disclosure