Atlas Knowledge Base
Dashboard
Dashboard

Dashboard


The SBN Tunnel dashboard is the browser-based administration console installed alongside the tunnel server. Reach it at https://<server-address>:<dashboard-port> -- the port is chosen during installation (see Installing & Uninstalling). Sign in with the administrator username and password set up at install time; five failed sign-in attempts from the same address lock that address out for ten minutes. Once signed in, the console presents nine tabs across the top, and every tunnel server reachable from the console is administered from the same screens. For the product overview, see SBN Tunnel.

Server

The Server tab is the runtime view, with one card per tunnel server. Each card shows uptime, process memory, active session count, and whether the server is currently accepting connections, along with its SSH, management, and peer ports and its running version. Cards expand to reveal the peer list with each peer's health state, the idle-timeout setting, and a table of active sessions listing session ID, license, customer label, remote address, connection age, and idle time. An administrator can rename a server, adjust its idle timeout, disconnect an individual session, or take a server out of rotation so it stops accepting new connections while existing sessions finish.

Endpoints

Endpoints are the destinations behind the tunnel -- typically database servers that clients reach by name. Each entry has a name, an IP or host, and a port; when a client asks for a destination, the tunnel matches the name first and falls back to matching IP and port. The table shows each endpoint's live connection count and status, with a filter box that narrows the list by name, host, or port (a space between terms matches all of them). Administrators add, edit, and delete endpoints here; which licenses may reach which endpoints is set on the Licenses tab.

Farm Keys

Farm keys are the trust anchors that let a tunnel client confirm it is talking to a genuine server rather than an impostor. Generating a key creates the keypair in the browser, signs the host-key fingerprints of the connected tunnel servers, publishes those signed attestations for clients to check, and downloads the private key for safekeeping -- the private key is never sent to the server. The table lists each key's label, key ID, public key, published attestation count, and the number of licenses bound to it. Keys stack, so adding a new one never cuts off licenses issued against an older one; the separate re-sign panel is used after a server is rebuilt from scratch and its host key changes. Background on how this protects a connection is in Security.

Licenses

A license is what a tunnel client presents to connect, and licenses apply to every connected tunnel server -- creating, editing, or deleting one on any console propagates to all of them. Each license has a name embedded in the key (letters, digits, and underscore), a free-text description, a maximum simultaneous connection count where zero means unlimited, the farm key it binds to, and an optional list of allowed endpoints (leaving the list empty allows all of them). The server generates the key itself, and a copy button places it on the clipboard for sending to the customer. The table shows each license's bound key, connection ceiling, active connection count, and status, with buttons to suspend a license so new connections are refused and to resume it later.

Security

Security holds four sub-tabs. Enforcement shows the automatic lockout settings in force on each server -- failure threshold, measurement window, block duration, and maximum block -- above live tables of currently blocked addresses (with time remaining and repeat-block count) and addresses being tracked for recent failures; an administrator can release a blocked address immediately. Allow and Reject hold IP addresses and CIDR ranges: while the allow list has any entry it becomes the sole gate and the reject list is ignored, and leaving both lists empty applies no address restriction. Geo-fence restricts admission by the client's country once an IP-lookup service token has been saved and verified; locations are picked by continent or individual country as a default, individual licenses can override that default, and a test box resolves any public address to show what the gate would decide without creating a connection. A failed location lookup allows the connection and records a warning rather than disconnecting anyone. Details of the layered protections are in Security.

Audit

The Audit tab is the searchable event history across every connected tunnel server, refreshing every five seconds. Each row records the server, timestamp, action, license, remote address, session ID, and free-text details. Events cover connects and disconnects, denied attempts, license suspensions, resumptions and edits, certificate provisioning, renewal and revocation, idle timeouts, servers entering and leaving rotation, peers joining or leaving, and configuration pushes. Administrators filter by action type and by license, and set how many of the most recent rows to display.

Insights

Insights presents trends over a selected window of the last minute, hour, twenty-four hours, or seven days. A row of large counters shows current call rate per minute, active sessions, blocked address count, new blocks per minute, and tracked address count. Below them, four charts plot tunnel calls per second, active sessions, blocked address count, and new blocks per second across all connected servers. Warning banners appear when the metrics feed falls behind or the recorder starts skipping cycles, which points at load or disk pressure on the machine.

Log

The Log tab streams the tail of the server log file. An administrator chooses how many lines to display -- 100, 200, 500, or 1000 -- refreshes on demand, or turns on automatic refresh every five seconds to watch activity as it happens. It is the fastest place to look when a connection attempt fails and the audit entry alone does not explain why.

Settings

Settings holds four configuration panels. Email (SMTP) sets the from address and display name, host and port, optional username and password, and whether TLS is required, with a button that sends a test message to an address you supply. Log Retention sets how many days of log files to keep on this server only; a new file starts each day and is capped at 25 MB, and older files are removed after the retention period or sooner if the log drive runs low on space. Contact Email shows the current address and changes it, with verification links sent to both the old and new addresses that must both be confirmed within five minutes or the change is discarded. Admin Password sets a new sign-in password, which takes effect only after the confirmation link sent to the contact email is opened within five minutes, at which point all signed-in sessions are ended.



Was this helpful?