Skip to main content

How to use a jump host on a Mac

By Lucas Russo, developer of SSHive · Updated

One bastion profile, used by every private server behind it: a jump chain of up to 5 hops, built in the profile editor, each hop signing in with its own credentials.

Estimated time: 3 minutes

A bastion, or jump host, is the one SSH server of a network that faces the Internet. Every other machine accepts SSH only from it, so there is a single door to patch, to log and to put behind a second factor, and the private servers never expose port 22 at all. From Terminal you go through it with ssh -J bastion target, or a ProxyJump line in ~/.ssh/config. In SSHive the bastion is an ordinary SSH profile, and each private server names it in the Jump Chain (multi-hop) block of its Advanced options. The chain points at the profile, not at a copy of its address: when the bastion's IP changes, you edit that one profile and every server behind it follows. Jump chains are part of SSHive Pro on the Mac. If your bastions are already in ~/.ssh/config, import it first.

Step-by-step

  1. Create the bastion profile first (it has no jumps itself)

    Sidebar › + › SSH. Fill in the bastion's public hostname or IP, port, user and authentication (a key is the better choice). Leave its Advanced options alone: the bastion itself has no jump chain. Save, and connect once to accept its host key. The order matters because each hop of a chain is picked from a menu of your existing SSH profiles: there is no free-text user@host field, so the bastion has to exist first.
  2. Build the chain on the target profile (Pro)

    Create an SSH profile for the private server, with its private address (as seen from inside the bastion's network) and the authentication that server accepts. Open Advanced options and, in Jump Chain (multi-hop), click Add hop. A menu lists your other SSH profiles as name (host:port): pick the bastion. Under the list the route is drawn, bastion → target, and each hop has up, down and remove buttons. Save. In the free version the block is dimmed, and a click on its PRO badge opens the upgrade window.
  3. Each hop signs in with its own profile

    With OpenSSH's ProxyJump, every hop's login comes from ~/.ssh/config and your agent. In SSHive, each profile in the chain signs in with its own saved settings: password, private key, agent or passphrase. A bastion on an ed25519 key and a target that only accepts the agent is fine. Agent Forwarding, in the same Advanced options, is a separate switch: turn it on for a server only when a program running there needs your local agent, a git push from that server with your Mac's key, for example.
  4. Several bastions: list every hop on the final profile

    For two bastions, A then B: create A, create B, then on the target open Jump Chain and add A, then B, in that order; the route reads A → B → target. SSHive follows the chain of the profile you open and nothing else: B's own chain, if it has one, is not used, so every hop goes on the final profile. A chain holds up to 5 hops, and SFTP and tunnels on the final profile go through every one of them.

Frequently asked questions

Can I use a jump host with SFTP and tunnels?+
Yes, both go through the chain. Drag a file into the target's SFTP panel and it travels encrypted, Mac → bastion → target. Tunnels defined on the target profile work the same way.
Do RDP and VNC profiles have a jump chain?+
No, the chain exists on SSH profiles only. For a Windows or VNC machine behind the bastion, give the bastion profile a local tunnel and point the RDP or VNC profile at localhost, as the RDP guide shows.

Related SSHive features

SSH Terminal

GPU-accelerated terminal

SSH Tunnels

Local, remote & SOCKS5 proxy

Try SSHive Free for macOS

Get the all-in-one SSH, SFTP, RDP and VNC client for Mac. Free download, no signup required.

Download SSHive Free