A private server may be reachable only through a bastion host. Add a second network boundary, and the route becomes easy to mix up: which username belongs to which machine, where does each key live, and which hop is failing?
This guide starts with an OpenSSH example on a Mac, then describes how the same connection layout maps to a mobile SSH client. All addresses, usernames, and key paths below are illustrative; replace them with your own authorized hosts.
Disclosure: I develop JTerm, an SSH client for iPhone, iPad, and Mac. The OpenSSH examples work independently of JTerm.
1. Write down the route
Suppose the connection path is:






