A private server may be reachable only through a bastion host. Add a second network boundary, and the route becomes easy to mix up: which username belongs to which machine, where does each key live, and which hop is failing?

This guide starts with an OpenSSH example on a Mac, then describes how the same connection layout maps to a mobile SSH client. All addresses, usernames, and key paths below are illustrative; replace them with your own authorized hosts.

Disclosure: I develop JTerm, an SSH client for iPhone, iPad, and Mac. The OpenSSH examples work independently of JTerm.

1. Write down the route

Suppose the connection path is: