<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/tutorial-for-setting-up-an-ssh-jump-server-hcnbbv9ng" -->

---
title: Tutorial for setting up an SSH Jump Server | daily.dev
description: A practical guide to setting up an SSH jump server (bastion host) using two approaches: traditional OpenSSH with the ProxyJump option and hardened sshd_config...
canonical: https://daily.dev/posts/tutorial-for-setting-up-an-ssh-jump-server-hcnbbv9ng
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Tutorial for setting up an SSH Jump Server | daily.dev
og:description: A practical guide to setting up an SSH jump server (bastion host) using two approaches: traditional OpenSSH with the ProxyJump option and hardened sshd_config...
og:url: https://daily.dev/posts/tutorial-for-setting-up-an-ssh-jump-server-hcnbbv9ng
og:image: https://api.daily.dev/og/posts/HCnBBV9nG.png
og:image:alt: Tutorial for setting up an SSH Jump Server
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Tutorial for setting up an SSH Jump Server

**[Teleport](https://daily.dev/sources/teleport)** · 6 min read · 0 upvotes · 0 comments

## Summary

A practical guide to setting up an SSH jump server (bastion host) using two approaches: traditional OpenSSH with the ProxyJump option and hardened sshd_config settings, or Teleport, a newer open-source SSH proxy that uses certificates instead of keys and supports web-based access and SSO integration. Includes concrete configuration snippets and guidance on when to choose each option based on team size and infrastructure complexity.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://goteleport.com/blog/ssh-jump-server>

## Questions this post answers

### How do I set up an SSH jump server using OpenSSH's ProxyJump option?

Configure the client's ~/.ssh/config with a Host block matching the target IP range and a ProxyJump directive pointing to the jump server, for example 'Host 10.2.2.*' with 'ProxyJump proxy.example.com'. This lets you run ssh 10.2.2.1 directly, and the client automatically connects through the jump server without manually typing -J each time.

_Developers hardening SSH access can find configuration walkthroughs like this one on daily.dev._

### How do I disable interactive shell access for jump users in sshd_config?

Add a Match User block in /etc/ssh/sshd_config for the jump account (e.g. jumpuser) setting PermitTTY no, X11Forwarding no, PermitTunnel no, GatewayPorts no, and ForceCommand /usr/sbin/nologin. This restricts that account to only forwarding SSH connections, preventing it from logging into the jump server directly or misusing it for other tasks.

_Anyone locking down bastion hosts can track SSH hardening techniques like this via daily.dev._

### What are the advantages of Teleport over OpenSSH for a jump server setup?

Teleport, released in 2016, replaces SSH keys with short-lived SSH certificates, removing key management overhead and making servers stateless. It also offers live server introspection instead of static inventories, a web-based proxy interface, support for Kubernetes and HTTP(S) resources through the same jump host, and single sign-on integration with providers like GitHub, Google, Okta, or Active Directory.

_Teams comparing bastion tools can weigh OpenSSH against Teleport using resources surfaced on daily.dev._

## Similar posts on daily.dev

- [Getting started with SSH: Your complete guide to understanding the secure shell](https://daily.dev/posts/getting-started-with-ssh-your-complete-guide-to-understanding-the-secure-shell-kzltkr6dq) · All Things Open · 2 upvotes · 0 comments
- [SSH Essentials: Working with SSH Servers, Clients, and Keys](https://daily.dev/posts/ssh-essentials-working-with-ssh-servers-clients-and-keys-hkehvz7fe) · DigitalOcean Community · 0 upvotes · 0 comments
- [Hardening SSH: Fail2Ban, Nftables & Cloud Firewalls](https://daily.dev/posts/hardening-ssh-fail2ban-nftables-cloud-firewalls-btns6dfx7) · DigitalOcean Community · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#linux](https://daily.dev/tags/linux), [#ssh](https://daily.dev/tags/ssh)

[View this post on daily.dev](https://daily.dev/posts/tutorial-for-setting-up-an-ssh-jump-server-hcnbbv9ng)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Tutorial for setting up an SSH Jump Server","url":"https://daily.dev/posts/tutorial-for-setting-up-an-ssh-jump-server-hcnbbv9ng","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/tutorial-for-setting-up-an-ssh-jump-server-hcnbbv9ng"},"datePublished":"2026-08-23T12:21:59.990Z","dateModified":"2026-08-23T12:44:05.929Z","description":"A practical guide to setting up an SSH jump server (bastion host) using two approaches: traditional OpenSSH with the ProxyJump option and hardened sshd_config...","image":"https://media.daily.dev/image/upload/s--58gMhC4P--/f_auto/v1722860399/public/Placeholder%2012","thumbnailUrl":"https://media.daily.dev/image/upload/s--58gMhC4P--/f_auto/v1722860399/public/Placeholder%2012","isAccessibleForFree":true,"articleSection":"Teleport","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Teleport","logo":"https://media.daily.dev/image/upload/s--Dw-Bbw6O--/c_limit,w_256/f_auto,q_auto/v1787487494/logos/teleport?_a=BAMAMicg0","url":"https://daily.dev/sources/teleport"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/tutorial-for-setting-up-an-ssh-jump-server-hcnbbv9ng","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,linux,ssh","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Teleport","item":"https://daily.dev/sources/teleport"},{"@type":"ListItem","position":3,"name":"Tutorial for setting up an SSH Jump Server"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/tutorial-for-setting-up-an-ssh-jump-server-hcnbbv9ng#faq","mainEntity":[{"@type":"Question","name":"How do I set up an SSH jump server using OpenSSH's ProxyJump option?","acceptedAnswer":{"@type":"Answer","text":"Configure the client's ~/.ssh/config with a Host block matching the target IP range and a ProxyJump directive pointing to the jump server, for example 'Host 10.2.2.*' with 'ProxyJump proxy.example.com'. This lets you run ssh 10.2.2.1 directly, and the client automatically connects through the jump server without manually typing -J each time. Developers hardening SSH access can find configuration walkthroughs like this one on daily.dev."}},{"@type":"Question","name":"How do I disable interactive shell access for jump users in sshd_config?","acceptedAnswer":{"@type":"Answer","text":"Add a Match User block in /etc/ssh/sshd_config for the jump account (e.g. jumpuser) setting PermitTTY no, X11Forwarding no, PermitTunnel no, GatewayPorts no, and ForceCommand /usr/sbin/nologin. This restricts that account to only forwarding SSH connections, preventing it from logging into the jump server directly or misusing it for other tasks. Anyone locking down bastion hosts can track SSH hardening techniques like this via daily.dev."}},{"@type":"Question","name":"What are the advantages of Teleport over OpenSSH for a jump server setup?","acceptedAnswer":{"@type":"Answer","text":"Teleport, released in 2016, replaces SSH keys with short-lived SSH certificates, removing key management overhead and making servers stateless. It also offers live server introspection instead of static inventories, a web-based proxy interface, support for Kubernetes and HTTP(S) resources through the same jump host, and single sign-on integration with providers like GitHub, Google, Okta, or Active Directory. Teams comparing bastion tools can weigh OpenSSH against Teleport using resources surfaced on daily.dev."}}]}
```

