Glossary · OT security engineering
Bastion host
Also known as: Bastion server
German: Bastion Host
In network security, a bastion host is a specially hardened computer placed at a network boundary, typically in a DMZ, that is deliberately exposed to a less trusted network and serves as a controlled point through which access to a protected network is granted.
- Security engineering
- OT security
In one sentence
A bastion host is a specially hardened computer at a network boundary that serves as the controlled access point into a protected network.
Example
External service partners can reach only the bastion host in the plant DMZ; from there, authorized sessions are forwarded to specific machines in the production network.
How it applies
- Engineering: A bastion host runs as few services as possible, is fully hardened and patched, has strong authentication and logs all activity. It sits between firewalls so that the protected network is never directly reachable from outside.
- Operation: Because it is exposed, the bastion host is expected to be attacked. Monitoring its logs and integrity is a priority for the Security operations center (SOC).
- Maintenance: Only administrators with separate privileged accounts manage it, ideally through Privileged access management (PAM).
- Documentation: Network and security documentation should record the bastion host's purpose, allowed connections, accounts and hardening baseline. Service documentation for remote maintenance should tell partners how to connect through it and what they can reach.
Bastion host vs. jump server
The terms overlap. "Bastion host" emphasizes the hardened, exposed position at the network edge; a Jump server is a bastion host used specifically as a stepping stone for administrative or engineering sessions into a protected zone.