Glossary · OT security engineering
Jump server
Also known as: Jump host, Jump box
German: Sprungserver
In network security, a jump server is a hardened, monitored system in a controlled network segment through which administrators, engineers or service technicians must connect before accessing systems in a protected zone, so that no direct connections to the protected systems are needed.
- Security engineering
- OT security
In one sentence
A jump server is a hardened, monitored system through which users must connect before reaching systems in a protected zone.
Example
Engineers connect from the office network to a jump server in the IDMZ, which holds the engineering software and is the only system allowed to reach the PLCs of the press line.
How it applies
- Engineering: A jump server is placed in the DMZ or in a management zone. Users authenticate with MFA, sessions are logged and often recorded, and firewall rules allow the protected systems to be reached only from the jump server.
- Operation: Engineering tools installed on the jump server are version-controlled and scanned, so that laptops of unknown state never connect directly to controllers. File transfer through the jump server should be controlled and scanned too.
- Maintenance: Jump servers are high-value targets and must be patched, hardened and monitored with priority. Shared accounts on jump servers undermine their value for accountability.
- Documentation: Service documentation should describe how to connect through the jump server, which tools are available there, and how files are transferred. Keep screenshots and instructions aligned with the current setup.
Jump server vs. remote access server
A Remote access server terminates external connections, for example VPNs. A jump server is the controlled stepping stone from which sessions to target systems start. Many architectures combine both.