Bastions are Oracle-managed services. You use a bastion to create Secure Shell (SSH) sessions that provide access to other private resources. But you can't connect directly to a bastion with SSH and administer or monitor it like a traditional host.
When connecting to a bastion session, we recommend that you follow the SSH best practices described in Securing Bastion.
You can connect to the following types of sessions:
To use Oracle Cloud Infrastructure, you must be granted security access in a policy by an administrator. This access is required whether you're using the Console or the REST API with an SDK, CLI, or other tool. If you get a message that you don't have permission or are unauthorized, verify with your administrator what type of access you have and which compartment to work in.
To use all Bastion features, you must have the following permissions:
Allow group SecurityAdmins to manage bastion-family in tenancy
Allow group SecurityAdmins to manage virtual-network-family in tenancy
Allow group SecurityAdmins to read instance-family in tenancy
Allow group SecurityAdmins to read instance-agent-plugins in tenancy
Allow group SecurityAdmins to inspect work-requests in tenancy
The VCN (virtual cloud network) that the target resource was created in must allow incoming network traffic from the bastion on the target
port.
For example, if you want to use a session to connect to port 8001 on a compute instance from a bastion with the IP address 192.168.0.99, then the subnet used to access the instance needs to allow ingress traffic from 192.168.0.99 on port 8001.
On the Bastions list page, find the bastion that you want to work with. If you need help finding the list page or the bastion, see Listing Bastions.
Select the name of the bastion.
Copy the Private endpoint IP address.
Select the Target subnet.
If the target resource is on a different subnet than the one used by the bastion to access this VCN, edit the target resource's subnet.
From the Subnet Details page, click an existing security list that is assigned to this subnet.
Alternatively, you can create a security list and assign it to this subnet.
Select Add Ingress Rules.
For Source CIDR, enter a CIDR block that includes the Private endpoint IP address of the bastion.
For example, the CIDR block <bastion_private_IP>/32 includes only the bastion's IP address.
For IP Protocol, select TCP.
For Destination Port Range, enter the port number on the target resource.