Installing & Uninstalling
The SBN Tunnel Client is a small background service that runs on a device and publishes the endpoints your tunnel license authorizes as ordinary local ports. An application on that device connects to 127.0.0.1 and a port number; the traffic travels to the endpoint over the encrypted tunnel. No VPN, and no SBN product needs to be installed.
Use it when the software that needs the endpoint is not SBN, Concentrator, or BackupHostImport. Those three carry their own tunnel support and do not need this -- see SBN Tunnel. Anything else that can be pointed at a host and a port can use the tunnel through this service: a device sending to a receiver, a reporting tool, a third-party application, a Linux machine.
What you need
- A v2 tunnel license key, from SRM > Check License
- The endpoint names your license authorizes, shown beside each farm on that same screen
- Administrator (Windows) or root (Linux) on the device
- Outbound access from the device to your tunnel servers
How it works
The service holds one license key and opens a single encrypted connection to whichever tunnel server is reachable and fastest at the moment. Each endpoint you configure gets its own fixed local port. When an application opens that port, the service carries the connection through to the endpoint and returns the response the same way.
Because the local ports are fixed, you configure the application once and it keeps working across restarts, reconnects, and server failover. If the tunnel server being used goes offline or is taken down for maintenance, the service moves to another server your license allows and the local ports stay where they are.
Traffic is TCP. The service does not read or change what passes through it.
Installing
On Windows
- Copy
sbn-tunnel-client.<version>.windows.zipto the device and extract it. - Open PowerShell as Administrator in the extracted folder.
- Run:
The installer asks for the install folder, your license key, the address and port for the browser interface, and one or more endpoint-to-local-port mappings. It then registers the SBN Tunnel Client service, starts it, and confirms the running version matches the package before reporting success.
On Linux
- Copy
sbn-tunnel-client.<version>.linux.tar.gzto the device and extract it. - Run:
The installer creates a dedicated service account, registers sbn-tunnel-client.service with systemd, starts it, and verifies the running version.
Configuration
Everything is managed from the browser interface the installer sets up. Open the address it printed at the end of the install, on the device itself. The certificate is generated locally, so your browser shows a warning the first time; continue past it.
The page has three parts:
- Status -- whether the tunnel is connected, which server it is using, when the credential expires, and the most recent error
- Forwards -- each mapping, with its local port, its endpoint, the number of connections open right now, and the traffic carried
- Configuration -- the license key and the list of forwards
To add an endpoint, enter a local port and the endpoint in host:port form, then save. The service applies the change immediately. The endpoint must be one your license authorizes; if it is not, the connection is refused and the status area says so.
The browser interface port
The port is chosen during installation and can be anything free on the device. Your choice is remembered and survives upgrades, so an upgrade never moves the page out from under you.
By default the interface listens only on the device itself, which is the safest setting: the page shows and edits your license key, so anyone who can reach it can use your license. If you choose an address that other machines can reach, the installer generates an access token and prints it once -- store it, because the page cannot be opened without it. The license key is never displayed once saved.
Checking it is working
- The Status area shows
connectedand names the server in use. - Each forward shows a rising connection or byte count once an application starts using it.
- On the device, the configured local ports accept connections.
- Windows service logs are in the
logsfolder under the install directory. On Linux usejournalctl -u sbn-tunnel-client.service.
Your tunnel administrator can also confirm the device from the tunnel dashboard, which lists the live session under your license.
When it cannot connect
Status shows an error naming an endpoint. The endpoint is not on your license. Open SRM > Check License to see the authorized names and use one of them exactly as shown, or contact your administrator to have it added.
Status stays on reconnecting. The device cannot reach any tunnel server. Confirm the device has outbound access, then check with your administrator that the servers are up.
The credential expired and did not renew. The service renews automatically well before expiry, so this points at a licensing change. Contact your administrator -- a license can be withdrawn centrally, which stops renewal.
An application cannot open the local port. Another program on the device is already using that port. Change the local port in the browser interface and point the application at the new one.
Updating
Run the installer from a newer package. It detects the existing install and upgrades it; your configuration, license key and browser-interface port are preserved.
Uninstalling
From the extracted package folder:
On Windows
On Linux
The service and program files are removed. Your configuration and license key are kept so a later re-install resumes where you left off; add -RemoveConfig (Windows) or --remove-config (Linux) to delete those as well.
Related
- SBN Tunnel -- what the tunnel is, licensing, and diagnostics
- SBN Tunnel Security Architecture -- how connections are authenticated and protected
- SBN Tunnel with SBN, with the Concentrator, with BackupHostImport