Balabit - RDP and SSH channel policies (site 1)
Balabit SCB Solution · Config document · referenced from Connection and channel policies
noteThe SSH policies are titled
PARTNER1-ssh-only, ORG-ssh-only, PARTNER1-scp-sftp-only and ORG-scp-sftp-only here, while the connections reference PARTNER1-SSH-ONLY and ORG-SSH-ONLY. The site 2 configuration spells them PARTNER1-SSH-ONLY, ORG-SSH-ONLY, PARTNER1-SCP-SFTP-ONLY and ORG-SCP-SFTP-only. The CONTENT POLICY of the shell channels is empty here; in site 2 it is no-WINSCP.The channel policies of the site 1 cluster: which channels of a connection may be opened, by whom, when, and whether they are recorded. There are three for RDP and four for SSH; the built-in policies (deny, terminal-only, all for RDP; deny, shell-only, all for SSH) are not documented in the design.
| Item | Value |
|---|---|
| Where | SCB web interface, RDP Control > Channel Policies and SSH Control > Channel Policies |
| Cluster | dc1-s-xblb001 |
| Firmware at the time | 5 LTS (5.0.3) |
| Source | My design document, version 0.5 of 2017-12-01 (draft), chapters 7.5.2 and 7.6.2 |
| Referenced by | RDP connections, SSH connections |
The answers
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapters 7.5.2 and 7.6.2 RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Drawing / FROM = RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Drawing / TARGET = RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Drawing / TIME = 7x24 RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Drawing / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Drawing / GATEWAY GROUPS = RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Drawing / REMOTE GROUPS = SCB_USERS_PARTNER1 RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Drawing / CONTENT POLICY = RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Clipboard / FROM = RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Clipboard / TARGET = RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Clipboard / TIME = 7x24 RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Clipboard / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Clipboard / GATEWAY GROUPS = RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Clipboard / REMOTE GROUPS = SCB_USERS_PARTNER1 RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Drawing / FROM = RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Drawing / TARGET = RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Drawing / TIME = 7x24 RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Drawing / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Drawing / GATEWAY GROUPS = RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Drawing / REMOTE GROUPS = SCB_USERS_ORG RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Drawing / CONTENT POLICY = RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Clipboard / FROM = RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Clipboard / TARGET = RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Clipboard / TIME = 7x24 RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Clipboard / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Clipboard / GATEWAY GROUPS = RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Clipboard / REMOTE GROUPS = SCB_USERS_ORG RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Drawing / FROM = RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Drawing / TARGET = RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Drawing / TIME = 7x24 RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Drawing / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Drawing / GATEWAY GROUPS = RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Drawing / REMOTE GROUPS = SCB_USERS_PARTNER2 RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Drawing / CONTENT POLICY = RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Clipboard / FROM = RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Clipboard / TARGET = RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Clipboard / TIME = 7x24 RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Clipboard / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Clipboard / GATEWAY GROUPS = RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Clipboard / REMOTE GROUPS = SCB_USERS_PARTNER2 SSH Control > Channel Policies > PARTNER1-ssh-only > Session shell / FROM = SSH Control > Channel Policies > PARTNER1-ssh-only > Session shell / TARGET = SSH Control > Channel Policies > PARTNER1-ssh-only > Session shell / TIME = 7x24 SSH Control > Channel Policies > PARTNER1-ssh-only > Session shell / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes SSH Control > Channel Policies > PARTNER1-ssh-only > Session shell / GATEWAY GROUPS = SSH Control > Channel Policies > PARTNER1-ssh-only > Session shell / REMOTE GROUPS = SCB_USERS_PARTNER1 SSH Control > Channel Policies > PARTNER1-ssh-only > Session shell / CONTENT POLICY = SSH Control > Channel Policies > PARTNER1-ssh-only > X11 forward / FROM = SSH Control > Channel Policies > PARTNER1-ssh-only > X11 forward / TARGET = SSH Control > Channel Policies > PARTNER1-ssh-only > X11 forward / TIME = 7x24 SSH Control > Channel Policies > PARTNER1-ssh-only > X11 forward / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes SSH Control > Channel Policies > PARTNER1-ssh-only > X11 forward / GATEWAY GROUPS = SSH Control > Channel Policies > PARTNER1-ssh-only > X11 forward / REMOTE GROUPS = SCB_USERS_PARTNER1 SSH Control > Channel Policies > PARTNER1-ssh-only > X11 forward / ALLOWED CLIENT ADDRESSES = SSH Control > Channel Policies > ORG-ssh-only > Session shell / FROM = SSH Control > Channel Policies > ORG-ssh-only > Session shell / TARGET = SSH Control > Channel Policies > ORG-ssh-only > Session shell / TIME = 7x24 SSH Control > Channel Policies > ORG-ssh-only > Session shell / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes SSH Control > Channel Policies > ORG-ssh-only > Session shell / GATEWAY GROUPS = SSH Control > Channel Policies > ORG-ssh-only > Session shell / REMOTE GROUPS = SCB_USERS_ORG SSH Control > Channel Policies > ORG-ssh-only > Session shell / CONTENT POLICY = SSH Control > Channel Policies > ORG-ssh-only > X11 forward / FROM = SSH Control > Channel Policies > ORG-ssh-only > X11 forward / TARGET = SSH Control > Channel Policies > ORG-ssh-only > X11 forward / TIME = 7x24 SSH Control > Channel Policies > ORG-ssh-only > X11 forward / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes SSH Control > Channel Policies > ORG-ssh-only > X11 forward / GATEWAY GROUPS = SSH Control > Channel Policies > ORG-ssh-only > X11 forward / REMOTE GROUPS = SCB_USERS_ORG SSH Control > Channel Policies > ORG-ssh-only > X11 forward / ALLOWED CLIENT ADDRESSES = SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session exec SCP / FROM = SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session exec SCP / TARGET = SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session exec SCP / TIME = 7x24 SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session exec SCP / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session exec SCP / GATEWAY GROUPS = SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session exec SCP / REMOTE GROUPS = SCB_USERS_PARTNER1 SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session exec SCP / LOGGING / LOG FILE TRANSFERS TO SYSLOG / LOG FILE TRANSFERS TO DATABASE = VALUES / Yes / Yes SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session SFTP / FROM = SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session SFTP / TARGET = SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session SFTP / TIME = 7x24 SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session SFTP / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session SFTP / GATEWAY GROUPS = SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session SFTP / REMOTE GROUPS = SCB_USERS_PARTNER1 SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session SFTP / LOGGING / LOG FILE TRANSFERS TO SYSLOG / LOG FILE TRANSFERS TO DATABASE = VALUES / Yes / Yes SSH Control > Channel Policies > ORG-scp-sftp-only > Session exec SCP / FROM = SSH Control > Channel Policies > ORG-scp-sftp-only > Session exec SCP / TARGET = SSH Control > Channel Policies > ORG-scp-sftp-only > Session exec SCP / TIME = 7x24 SSH Control > Channel Policies > ORG-scp-sftp-only > Session exec SCP / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes SSH Control > Channel Policies > ORG-scp-sftp-only > Session exec SCP / GATEWAY GROUPS = SSH Control > Channel Policies > ORG-scp-sftp-only > Session exec SCP / REMOTE GROUPS = SCB_USERS_ORG SSH Control > Channel Policies > ORG-scp-sftp-only > Session exec SCP / LOGGING / LOG FILE TRANSFERS TO SYSLOG / LOG FILE TRANSFERS TO DATABASE = VALUES / Yes / Yes SSH Control > Channel Policies > ORG-scp-sftp-only > Session SFTP / FROM = SSH Control > Channel Policies > ORG-scp-sftp-only > Session SFTP / TARGET = SSH Control > Channel Policies > ORG-scp-sftp-only > Session SFTP / TIME = 7x24 SSH Control > Channel Policies > ORG-scp-sftp-only > Session SFTP / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes SSH Control > Channel Policies > ORG-scp-sftp-only > Session SFTP / GATEWAY GROUPS = SSH Control > Channel Policies > ORG-scp-sftp-only > Session SFTP / REMOTE GROUPS = SCB_USERS_ORG SSH Control > Channel Policies > ORG-scp-sftp-only > Session SFTP / LOGGING / LOG FILE TRANSFERS TO SYSLOG / LOG FILE TRANSFERS TO DATABASE = VALUES / Yes / Yes
| Field | What it means |
|---|---|
| Drawing, Clipboard | The RDP channels allowed: the screen itself, and the clipboard. Anything else (drive and printer redirection, sound, dynamic channels) is not in the list and therefore refused. The built-in RDP policy terminal-only allows the same two channels, which is presumably where the name *-TERMINAL-ONLY comes from |
| Session shell, X11 forward | The SSH channels of the ssh-only policies: an interactive shell and forwarded X11. Port forwarding, agent forwarding and remote command execution are refused |
| Session exec SCP, Session SFTP | The SSH channels of the scp-sftp-only policies; each file transfer is logged to syslog and to the connection database |
| FROM, TARGET | Address restrictions inside the connection; empty, so the connection's own FROM and targets apply |
| TIME = 7x24 | The built-in time policy: always |
| ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes | No four-eyes authorization; the channel is recorded into the audit trail |
| GATEWAY GROUPS | Empty: gateway authentication is not used |
| REMOTE GROUPS | Only members of this AD group may open the channel. As I understand it, the SCB looks the username up in the LDAP server policy of the connection and checks the group, nested groups included |
| ALLOWED CLIENT ADDRESSES | For X11: which X server addresses the forwarded traffic may come from; empty |
The design lists the RDP channel "Clipboard" without a direction, and it does not say why X11 forwarding was allowed.
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
| Drawing and Clipboard; Session shell and X11; SCP and SFTP with transfer logging | The channel types, the four-eyes option per channel and the time policy per channel are unchanged |
| User lists not used | User lists are announced for removal; AD/LDAP groups are the recommended replacement, which is what these policies already use |
Nothing here needs to change for SPS 9.0.