Bastion host

From Wikipedia, the free encyclopedia

Icon of a computer

A bastion host is a computer on a network that provides a single entrance and exit point to the Internet from the internal network and vice versa.

Bastion hosts are used to mitigate the security risks of a network by providing a barrier between private and public areas.

Bastion hosts are related to dual-homed hosts and screened hosts. While a dual-homed host often contains a firewall it is used to host other services as well. A screened host is a dual-homed host that is dedicated to running the firewall. To escalate to the bastion host level the screened host is hardened for the firewall purpose. (i.e. non-essential services and ports are shut down and/or closed)

[edit] See also


[edit] External links


In other languages