How to use a jump host on a Mac
By Lucas Russo, developer of SSHive · Updated
One bastion profile, used by every private server behind it: a jump chain of up to 5 hops, built in the profile editor, each hop signing in with its own credentials.
A bastion, or jump host, is the one SSH server of a network that faces the Internet. Every other machine accepts SSH only from it, so there is a single door to patch, to log and to put behind a second factor, and the private servers never expose port 22 at all. From Terminal you go through it with ssh -J bastion target, or a ProxyJump line in ~/.ssh/config. In SSHive the bastion is an ordinary SSH profile, and each private server names it in the Jump Chain (multi-hop) block of its Advanced options. The chain points at the profile, not at a copy of its address: when the bastion's IP changes, you edit that one profile and every server behind it follows. Jump chains are part of SSHive Pro on the Mac. If your bastions are already in ~/.ssh/config, import it first.
Step-by-step
Create the bastion profile first (it has no jumps itself)
Sidebar › + › SSH. Fill in the bastion's public hostname or IP, port, user and authentication (a key is the better choice). Leave its Advanced options alone: the bastion itself has no jump chain. Save, and connect once to accept its host key. The order matters because each hop of a chain is picked from a menu of your existing SSH profiles: there is no free-textuser@hostfield, so the bastion has to exist first.Build the chain on the target profile (Pro)
Create an SSH profile for the private server, with its private address (as seen from inside the bastion's network) and the authentication that server accepts. Open Advanced options and, in Jump Chain (multi-hop), click Add hop. A menu lists your other SSH profiles as name (host:port): pick the bastion. Under the list the route is drawn,bastion → target, and each hop has up, down and remove buttons. Save. In the free version the block is dimmed, and a click on its PRO badge opens the upgrade window.Each hop signs in with its own profile
With OpenSSH'sProxyJump, every hop's login comes from~/.ssh/configand your agent. In SSHive, each profile in the chain signs in with its own saved settings: password, private key, agent or passphrase. A bastion on an ed25519 key and a target that only accepts the agent is fine. Agent Forwarding, in the same Advanced options, is a separate switch: turn it on for a server only when a program running there needs your local agent, agit pushfrom that server with your Mac's key, for example.Several bastions: list every hop on the final profile
For two bastions, A then B: create A, create B, then on the target open Jump Chain and add A, then B, in that order; the route readsA → B → target. SSHive follows the chain of the profile you open and nothing else: B's own chain, if it has one, is not used, so every hop goes on the final profile. A chain holds up to 5 hops, and SFTP and tunnels on the final profile go through every one of them.
Frequently asked questions
Can I use a jump host with SFTP and tunnels?+
Do RDP and VNC profiles have a jump chain?+
localhost, as the RDP guide shows.Related SSHive features
SSH Terminal
GPU-accelerated terminal
SSH Tunnels
Local, remote & SOCKS5 proxy
Try SSHive Free for macOS
Get the all-in-one SSH, SFTP, RDP and VNC client for Mac. Free download, no signup required.
Download SSHive Free