Skip to main content

Install PAM Jump Server

JumpCloud Privileged Access Management (PAM) uses a hybrid model. Part of PAM runs in the JumpCloud cloud. A Jump Server runs on a Linux host in your environment.

The Jump Server is the on-premises proxy for privileged sessions to Servers, Databases, and Privileged Websites with Web Shield. It can record sessions when recording is enabled, and it can support Jump Server backup features configured in PAM Settings.

This article explains what a Jump Server does, what you need before install, how to register a Jump Server in the JumpCloud Admin Portal, how to download and run the install file on the Linux host, and how to verify the connection.

Prerequisites​

  • One Linux host that will run the Jump Server containers. Operating system: Ubuntu Server 24.04.
  • Docker installed and running on that host before you execute the Jump Server install file.
  • Root privileges on the host (sudo su or equivalent). The install must run as root.
  • At least 2 vCPUs.
  • At least 8 GB RAM.
  • At least 80 GB free on /. Provision more than 80 GB total so the OS and system files still leave 80 GB free on /.
  • curl available on the host.
  • Host clock drifts under 300 seconds versus JumpCloud server time.
  • Network rules that allow inbound access to the Jump Server Web Port and Shell Port, and outbound access to JumpCloud PAM Platform endpoints for your data center and to your target resources.

Considerations​

  • Incomplete host, Docker, or network configuration is the most common reason install fails, or the Jump Server reports Online but cannot serve sessions.
  • You need a Jump Server with status Online for Servers, Databases, and Privileged Websites with Web Shield. Privileged Websites without Web Shield use JumpCloud Go in the user's browser and do not use the Jump Server for that session path.
  • Installing or reinstalling a Jump Server can take about 10 to 20 minutes. Privileged access through that Jump Server is unavailable while the install runs.

Understanding Jump Servers and Secure Access​

For sessions that use a Jump Server, think in three communication legs:

  • User endpoint to Jump Server: the user reaches the Jump Server for the session.
  • Jump Server and JumpCloud PAM Platform: authentication, credentials, and session commands.
  • Jump Server to target resource: the Jump Server reaches the Server, Database, or Web Shield website.

The JumpCloud Admin Portal and JumpCloud User Portal orchestrate access. They are not an intermediate hop in the middle of session connections.

Important

You need a Jump Server with status Online for Servers, Databases, and Privileged Websites with Web Shield. Privileged Websites without Web Shield use JumpCloud Go in the user's browser and do not use the Jump Server for that session path.

PAM Topology

Reviewing Host and Software Requirements​

Complete these requirements before you register or install a Jump Server.

Prepare one Linux host that will run the Jump Server containers. Install Docker on that host first. The Jump Server install file expects Docker to already be running.

RequirementDetails
Operating system (OS)Ubuntu Server 24.04
Container runtimeDocker installed and running before you execute the Jump Server install file
PrivilegesRoot on the host (sudo su or equivalent). The install must run as root.
CPUAt least 2 vCPUs
MemoryAt least 8 GB RAM
DiskAt least 80 GB free on /. Provision more than 80 GB total so the OS and system files still leave 80 GB free on /.
Toolscurl available on the host
Clock syncHost clock drift under 300 seconds versus JumpCloud server time
tip

As your environment grows, you can update the hardware of your Jump Server so users get improved session quality based on the amount of concurrent sessions.

Jump Server Scalability

Reviewing Network Requirements​

The Jump Server host needs both inbound access (so users and browsers can reach it) and outbound access (so it can connect to JumpCloud and to your target resources).

Inbound to the Jump Server Host​

Users reach the Jump Server on the ports you configure when you add it in the Admin Portal. Defaults are shown below. Change them in Add Jump Server only if you must avoid conflicts with other services on the same host.

PortDefaultUsed for
Web Port443Browser-based privileged sessions
Shell Port2222Direct Access paths that use the shell port

Your firewall or security group must allow inbound connections to those ports from the networks where users connect (for example office, VPN, or ZTNA).

Outbound from the Jump Server Host​

Outbound connections have two destinations:

  1. JumpCloud PAM Platform and related cloud services for your data center (tables below). Most entries use port 443. The message queue uses port 5671.
  2. Your target resources, over the protocols you will use (for example SSH, RDP, Telnet, VNC, Kubernetes, and database protocols).
warning

Allowing all outbound connections on port 443 is not sufficient. The AWS MQ broker entry uses port 5671, not 443. If that allow list entry is omitted, the Jump Server may install and report Online while some live Platform commands fail later (for example force disconnect during a Live session).

Outbound Allow List by Data Center​

Allow the Jump Server host to reach every address in the table for your JumpCloud data center region.

US Data Center​

AddressPortPurpose
*.vault.jumpcloud.com443PAM Platform communication
*.api.vault.jumpcloud.com443PAM API
*.app.vault.jumpcloud.com443PAM application endpoints
*.connect.vault.jumpcloud.com443Jump Server connection domain
b-4e73f8f9-5209-4e31-b0e9-b53a88287a70.mq.us-east-1.on.aws5671Live Platform commands (AWS MQ)
public.ecr.aws443Pull Jump Server container images
*.cloudfront.net443Session recording upload (CDN)
*.s3.us-east-1.amazonaws.com443Session recording storage
clients2.google.com443JumpCloud Go install inside Web Shield sessions

EU Data Center​

AddressPortPurpose
*.vault.eu.jumpcloud.com443PAM Platform communication
*.api.vault.eu.jumpcloud.com443PAM API
*.app.vault.eu.jumpcloud.com443PAM application endpoints
*.connect.vault.eu.jumpcloud.com443Jump Server connection domain
b-1b7a56b2-c4ea-4ef3-bfaa-f7a46f806487.mq.eu-central-1.on.aws5671Live Platform commands (AWS MQ)
public.ecr.aws443Pull Jump Server container images
*.cloudfront.net443Session recording upload (CDN)
*.s3.eu-central-1.amazonaws.com443Session recording storage
clients2.google.com443JumpCloud Go install inside Web Shield sessions

India Data Center​

AddressPortPurpose
*.vault.in.jumpcloud.com443PAM Platform communication
*.api.vault.in.jumpcloud.com443PAM API
*.app.vault.in.jumpcloud.com443PAM application endpoints
*.connect.vault.in.jumpcloud.com443Jump Server connection domain
b-3e2a9040-3eeb-46ae-b7c4-918bf4c69efb.mq.ap-south-1.on.aws5671Live Platform commands (AWS MQ)
public.ecr.aws443Pull Jump Server container images
*.cloudfront.net443Session recording upload (CDN)
*.s3.ap-south-1.amazonaws.com443Session recording storage
clients2.google.com443JumpCloud Go install inside Web Shield sessions
note

The clients2.google.com endpoint is used when a Web Shield session installs JumpCloud Go inside the Web Shield browser. Privileged Websites without Web Shield use JumpCloud Go in the user's own browser and do not need this outbound path from the Jump Server.

Registering a Jump Server in the Admin Portal​

Installation has two stages. First register the Jump Server in the JumpCloud Admin Portal. Then install the software on the Linux host using the downloadable install file.

  1. Log in to the JumpCloud Admin Portal.
  2. Go to Access > PAM.
  3. Click the Jump Servers tab.
  4. Click Add Jump Server.
  5. In the Add Jump Server dialog, complete the fields below, then click Save.
FieldWhat to enter
NameA clear name for this Jump Server
IP Address (IPv4 Only)IPv4 address of the Linux host
Web PortBrowser session port. Default is 443.
Shell PortShell / Direct Access port. Default is 2222.

The new Jump Server appears in the list. Until you install it on the host, status is typically Not Installed.

Add Jump Server dialog

Opening Install Jump Server​

  1. On the Jump Servers list, find the Jump Server you registered.
  2. In Actions, click Install Jump Server (install icon / tooltip Install Jump Server).
  3. The Install Jump Server page opens with three steps.
StepLabel on the pageWhat you do
11. Choose a versionSelect the Jump Server version to install. Select the newest version available.
22. Select an installation modeDownload the install file
33. Check jump server connectionTest reachability after install

Install Jump Server page

Choosing a Version and Downloading the Install File​

  1. Under 1. Choose a version, select the Jump Server version to install (for example v26 or v27).
  2. Under 2. Select an installation mode, find Download and execute the install file:
  3. Click Download.

The Admin Portal downloads an install file to your local machine. That file is a script of install commands. You must place it on the Linux host where the Jump Server will run, then execute it there as root.

Important

Installing or reinstalling a Jump Server can take about 10 to 20 minutes. Privileged access through that Jump Server is unavailable while the install runs.

Putting the Install File on the Jump Server Host​

The install file starts on your workstation after Download. The Linux host must have a copy of that file before you can run it. Use any secure method that works in your environment.

OptionWhen to use itHow
A. File transferYou can copy files from your workstation to the host (SCP, SFTP, or another approved tool)Transfer the downloaded install file to a directory on the Linux host, then continue in that directory.
B. Copy and pasteFile transfer is unavailable, or you prefer to recreate the script on the hostOpen the downloaded file in a text editor on your workstation, copy all content, then on the host create the file with an editor such as nano, paste, and save.

Option A: Transfer the Downloaded File​

  1. Copy the downloaded install file from your workstation to the Linux host.
  2. On the Linux host, go to the directory where you placed the file.

Option B: Copy and Paste with a Text Editor (for example nano)​

Because the install file is text, you can recreate it on the host without a binary transfer:

  1. On your workstation, open the downloaded install file in a text editor.
  2. Select all content and copy it.
  3. On the Linux host, open an editor, for example:
nano <install-file>
  1. Paste the full script, save, and exit the editor.

Running the Install File as Root​

Run these commands on the Linux host. Replace <install-file> with the real filename you downloaded or created.

  1. Switch to root:
sudo su
  1. Make the install file executable:
chmod +x <install-file>
  1. Run the install file:
./<install-file>

Stay on the host until the installer finishes. The installer pulls container images, creates the Jump Server containers, and registers the host with JumpCloud PAM.

warning

Do not manually remove Docker volumes as part of a normal install or update. That can destroy local session recordings that are not yet uploaded, SSH keys used by the Jump Server, and certificates. Use the install file from the Admin Portal for install and reinstall. Manual volume removal is for troubleshooting only when other options fail.

Checking Jump Server Connection​

After the install finishes on the host, return to the Install Jump Server page in the JumpCloud Admin Portal and complete 3. Check jump server connection.

  1. Review the on-screen steps under 3. Check jump server connection.
  2. Click Check Connection.
  3. A new browser tab opens to run the test.
  4. Compare the result to the outcomes below.
ResultWhat you seeWhat to do
SuccessA message such as This server can only be accessed from the application.You can close the new tab and continue to verification.
FailureThe page does not load, or the browser shows an error such as This site can't be reachedCorrect network, DNS, TLS, or firewall issues for the Jump Server Web Port path, then click Check Connection again.

Check jump server connection

Verifying the Installation​

Confirm success in the Admin Portal and on the Linux host.

In the JumpCloud Admin Portal​

  1. Go to Access > PAM > Jump Servers.
  2. Confirm the Jump Server shows an installed version and status Online.
  3. (Optional) Open Health Check from Actions if you need metrics and status detail.

On the Linux Host​

Run:

docker ps -a

Confirm the Jump Server containers are present and show Up.

ContainerRole
vo-coreSession engine and recording for many session types
vo-webWeb entry point for browser sessions
vo-syncSync, backups, and Platform commands
vo-bastionDirect Access / shell port path
vo-databaseDatabase session path

Docker container status

Quick Reminder​

StepWhereWhat you do
RegisterJump Servers > Add Jump ServerName, IPv4, Web Port, Shell Port
DownloadInstall Jump ServerChoose version, select Download
Transfer or pasteYour workstation to Linux hostFile transfer, or copy into nano (or similar)
ExecuteLinux host as rootchmod +x then run the install file
VerifyAdmin Portal and hostCheck Connection, status Online, docker ps -a

Was this information helpful?