Installing the Server
An SBN Tunnel server is the machine clients connect through. Installing one puts the tunnel members and the dashboard on that machine as services, in one folder, in a single guided run. The same script installs a new server and upgrades an existing one, on Windows, Linux and macOS.
The SBN Tunnel client is a separate product with its own installer — see Installing & Uninstalling.
What you get
- One service per tunnel —
sbn-tunnel-1,sbn-tunnel-2, and so on. A server can run several tunnels for redundancy, each with its own ports and display name. - A dashboard service —
sbn-tunnel-dashboard, a secure web page showing tunnel status, connected clients, and the health of the tunnel servers this one is connected to. Licences, routing rules, blocked addresses and logs are all managed there. - Log streaming to the machine's shared Innovative NATS broker, so the server's activity appears alongside every other Innovative product's. The installer offers to put the broker on the machine if it is not there yet.
Installing
The install is the same on every platform: download the package, extract it, and run the installer with administrator rights from the folder you extracted to.
- Download
sbn-tunnel.<version>.<platform>.<ext>from the SBN Tunnel area of your Innovative Releases portal. - Extract it into an empty folder on the server. Run the installer from that folder — do not copy it out on its own.
- Run the installer:
| Platform | Run it with |
|---|---|
| Windows | .\install.ps1 from an elevated PowerShell window (Run as Administrator) |
| Linux and macOS | sudo ./install.sh |
What it asks
The run is interactive and works through six steps. Press Enter to take the value it suggests.
- Public address — the IP address or hostname the outside world uses to reach this server. This is the address advertised to clients and to the other tunnel servers this one connects to. If the server sits behind a VPN, NAT or firewall, enter the public-facing address rather than the network card's, which is what the suggested value comes from. A private address is accepted only after you confirm it, because external clients will not be able to reach it. You are then offered an optional public DNS hostname for the tunnel's control-plane certificate; leave it blank to skip.
- Internal address — the address the dashboard and the tunnels on this machine use to reach each other. Many networks do not let a host reach itself through its own public address, so
127.0.0.1always works and an internal LAN address works within the LAN. - Dashboard — the port the dashboard listens on (internal only) and the admin password. The password protects access from outside the server; access from the server itself is unrestricted. On an upgrade you are asked whether to keep the existing password.
- Primary tunnel — three ports and a name for
sbn-tunnel-1: the client port clients connect on (external, and it must be reachable from the internet), the management port the dashboard reads status from (internal only), and the peer port other tunnel servers connect to (internal, and it must be open between the connected servers). You also choose the display name shown in the dashboard and in the SBN client configuration, and how many days of log files to keep (1 to 365, 7 by default). The service purges sooner if the log drive runs low on free space, so logging can never fill the disk. - Additional tunnels — add further tunnels on the same server for redundancy, each with its own three ports and name. Tunnels that are already there can be changed or removed here.
- Connect to another tunnel — give the address of another tunnel server so the two fail over for each other. Its peer port is shown on each server card in its dashboard; leave the port blank and the installer scans for it. Leave the address blank to skip.
The installer then prints the complete plan and asks you to confirm before it changes anything. Afterwards it offers to add the firewall rules for the ports you chose and to start the services, and it verifies that each one is running before reporting success. It finishes by printing the dashboard address.
Where things go
Every run appends to install.log beside the installer. Each tunnel also writes its own service logs under tunnels/tunnel<n>/logs inside the install folder.
Platform notes
- Windows — the package is
sbn-tunnel.<version>.windows.zip. The tunnels and the dashboard are registered as the Windows servicessbn-tunnel-1,sbn-tunnel-2, … andsbn-tunnel-dashboard. A fresh install runs from the folder you extracted to; use-InstallRoot <path>to put it somewhere else. Upgrading a server whose install is elsewhere is handled for you: the installer finds it, copies the new files over it, and re-runs itself there. - Linux — the package is
sbn-tunnel.<version>.linux.tar.gz; extract it withtar -xzf. The same names are registered as systemd units —sbn-tunnel-1.serviceandsbn-tunnel-dashboard.service; check one withsystemctl status sbn-tunnel-1or read its output withjournalctl -u sbn-tunnel-1. A fresh install goes to/opt/innovative/sbn-tunnel, with system logs under/var/log/innovative/sbn-tunnel. An install already on the machine in an older location is adopted where it stands: only the service names change, and configuration, keys, certificates and the geo database stay exactly where they are. - macOS — the same script installs the same services under launchd rather than systemd, as
com.innovative.sbn-tunnel-1andcom.innovative.sbn-tunnel-dashboard. A fresh install goes to/Library/Innovative/sbn-tunnel, with logs under/Library/Logs/Innovative/sbn-tunnel, and it needs bash 4 or newer, which macOS does not ship — install it first. macOS filters by application rather than by port, so no firewall rules are added; allow the tunnel and dashboard applications yourself if the application firewall is on. The macOS package is not yet generally available; contact support if you need one.
Upgrading
Run the same installer from a newer package. It finds the existing install, keeps every setting, and puts the new files in place. Before it stops the services it waits for live tunnel sessions to drain; if they will not drain within the time allowed it asks whether to evict the rest and carry on. An upgrade that needs no answers at all is -QuickInstall on Windows or --quick on Linux and macOS: every prompt takes its current value, nothing is asked, and the run still verifies the version afterwards.
Installing without a console
For automation and test rigs, -Unattended (Windows) or --unattended (Linux and macOS) installs a fresh server with no prompts, taking every default and echoing the answer it assumed. Supply the answers yourself with an answer file — -AnswerFile <path> or --answer-file <path> — and give the dashboard password by file rather than on the command line, with -DashboardPasswordFile <path> or --dashboard-password-file <path>, so it never appears in a process listing.
To see exactly what a run would do without changing anything, add -DryRun or --dry-run. -Help or --help lists every option and touches nothing.
Uninstalling
Run the uninstaller with administrator rights from the same folder you installed from:
| Platform | Run it with |
|---|---|
| Windows | .\uninstall.ps1 from an elevated PowerShell window |
| Linux and macOS | sudo ./uninstall.sh |
It finds the tunnel and dashboard services, drains live sessions first, names everything it is about to remove, and asks you to type the name of the target to confirm. Software only: nothing outside the install folder is touched, and firewall rules, scheduled tasks and anything another product shares are left alone and named in the summary so you can decide. The shared Innovative NATS broker is never removed — SBN Tunnel simply stops being registered against it once its last service is gone.
Options both platforms accept, in -PascalCase on Windows and --kebab-case on Linux and macOS: remove one service instead of the whole set (-Service sbn-tunnel-2 / --service sbn-tunnel-2); remove every set found on the machine (-All / --all); name the install folder when it cannot be discovered (-InstallRoot / --install-root); skip the typed confirmation for a target you named explicitly (-Force / --force); change how long sessions are given to drain (-DrainTimeoutSec / --drain-timeout-sec); and show what would be removed without removing it (-DryRun / --dry-run).
Every run appends to uninstall.log beside the uninstaller.
If something goes wrong
Every install and uninstall run writes a log and prints its path when it finishes, whether it succeeded or not. If a step fails, the script says what failed, why, and what to do next before it stops; services it stopped are started again and tunnels it drained are put back into service. Quote that log when you contact support.
Related help
- Dashboard — running and configuring a tunnel server once it is installed.
- Installing & Uninstalling — the SBN Tunnel client.
- SBN Tunnel Security Architecture — how the tunnel secures traffic.