All Products
Search
Document Center

Bastionhost:Perform SSH-based O&M

Last Updated:Mar 31, 2026

Use an SSH client or a third-party SSH tool to log in to your Bastionhost instance and connect to managed host assets for O&M. This topic uses macOS terminal (command-line) and ZOC 8 as examples.

Prerequisites

Before you begin, ensure that you have:

Note

Bastionhost provides a fixed O&M address in domain name format and uses dynamic IP addresses to prevent attacks. Always use the domain name rather than the IP address to avoid O&M failures caused by IP address changes.

Access accounts for hosts:

  • To allow the bastion host to access a host without entering credentials manually, authorize the user to use that host's accounts. For details, see Authorize a user to manage the accounts of one or more assets.

  • If no specific accounts are managed in the bastion host, select Unauthorized Asset Accounts Are Allowed in the Special Asset Accounts section. This lets the user enter the host's username and password manually to connect. For details, see Configure O&M settings.

Connect via command-line tool

The default SSH port for Bastionhost is 60022. To change the port, see Configure the bastion host port number.

Password authentication

  1. Open a terminal.

  2. Run the following command, replacing <username> with your bastion host username and <O&M-address> with the O&M address from the console:

    ssh <username>@<O&M-address> -p 60022
  3. Enter the bastion host user's password when prompted.

    mac登录ssh

  4. If two-factor authentication (2FA) is enabled for the user, enter the verification code. To configure 2FA, see Enable two-factor authentication.

    mfa验证

  5. On the asset management page, use the up and down arrow keys to select the target host, then press Enter to connect. For search tips, see Search for assets.

Token authentication

  1. Open a terminal.

  2. Run the following command, replacing <username> with your bastion host username and <O&M-address> with the O&M address:

    ssh <username>@<O&M-address> -p 60022
  3. Enter your O&M token when prompted. To get a token, see Manage an O&M token.

    mac登录ssh

  4. Perform O&M operations on the host.

Public key authentication

  1. Open a terminal and run the following command, replacing <private-key-path>, <username>, and <O&M-address> with your values:

    ssh -i <private-key-path> <username>@<O&M-address> -p 60022
  2. If two-factor authentication is enabled, enter the verification code. To configure 2FA, see Enable two-factor authentication.

  3. On the asset management page, use the up and down arrow keys to select the target host, then press Enter to connect. For search tips, see Search for assets.

Connect via ZOC 8

The following steps use ZOC 8 as an example client tool. The default SSH port is 60022.

Password authentication

  1. Launch ZOC 8 and click Host Directory.

  2. On the Host tab, enter the O&M address of the bastion host, set the port to 60022, and click OK.

    image

  3. On the Login tab, enter the bastion host username and password, then click OK.

    image

  4. If two-factor authentication is enabled, enter the verification code and click OK. To configure 2FA, see Enable two-factor authentication.

    image

  5. On the asset management page, use the up and down arrow keys to select the target host, then press Enter to connect.

Token authentication

  1. Launch ZOC 8 and click Host Directory.

  2. On the Host tab, enter the O&M address of the bastion host, set the port to 60022, and click OK.

    image

  3. On the Login tab, enter the username and password that are used to access the bastion host, then click OK. To get a token, see Manage an O&M token.

    image

  4. Perform O&M operations on the host.

Search for assets

After logging in, search for a target host in either of the following ways:

  • Quick search: Type /+search content. Matching results are highlighted in the list.

  • Bastionhost Search feature: Click [Search]. On the [Search] page, enter ls <keyword> and press Enter to filter hosts by keyword.

Note