LINUXOR.SK ... open source notes ...

Balabit - RDP and SSH channel policies (site 1)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Connection and channel policies

noteThe SSH policies are titled PARTNER1-ssh-only, ORG-ssh-only, PARTNER1-scp-sftp-only and ORG-scp-sftp-only here, while the connections reference PARTNER1-SSH-ONLY and ORG-SSH-ONLY. The site 2 configuration spells them PARTNER1-SSH-ONLY, ORG-SSH-ONLY, PARTNER1-SCP-SFTP-ONLY and ORG-SCP-SFTP-only. The CONTENT POLICY of the shell channels is empty here; in site 2 it is no-WINSCP.

The channel policies of the site 1 cluster: which channels of a connection may be opened, by whom, when, and whether they are recorded. There are three for RDP and four for SSH; the built-in policies (deny, terminal-only, all for RDP; deny, shell-only, all for SSH) are not documented in the design.

ItemValue
WhereSCB web interface, RDP Control > Channel Policies and SSH Control > Channel Policies
Clusterdc1-s-xblb001
Firmware at the time5 LTS (5.0.3)
SourceMy design document, version 0.5 of 2017-12-01 (draft), chapters 7.5.2 and 7.6.2
Referenced byRDP connections, SSH connections

The answers

ini
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapters 7.5.2 and 7.6.2

RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Drawing / FROM = 
RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Drawing / TARGET = 
RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Drawing / TIME = 7x24
RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Drawing / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes
RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Drawing / GATEWAY GROUPS = 
RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Drawing / REMOTE GROUPS = SCB_USERS_PARTNER1
RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Drawing / CONTENT POLICY = 
RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Clipboard / FROM = 
RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Clipboard / TARGET = 
RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Clipboard / TIME = 7x24
RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Clipboard / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes
RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Clipboard / GATEWAY GROUPS = 
RDP Control > Channel Policies > PARTNER1-TERMINAL-ONLY > Clipboard / REMOTE GROUPS = SCB_USERS_PARTNER1

RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Drawing / FROM = 
RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Drawing / TARGET = 
RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Drawing / TIME = 7x24
RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Drawing / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes
RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Drawing / GATEWAY GROUPS = 
RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Drawing / REMOTE GROUPS = SCB_USERS_ORG
RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Drawing / CONTENT POLICY = 
RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Clipboard / FROM = 
RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Clipboard / TARGET = 
RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Clipboard / TIME = 7x24
RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Clipboard / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes
RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Clipboard / GATEWAY GROUPS = 
RDP Control > Channel Policies > ORG-TERMINAL-ONLY > Clipboard / REMOTE GROUPS = SCB_USERS_ORG

RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Drawing / FROM = 
RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Drawing / TARGET = 
RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Drawing / TIME = 7x24
RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Drawing / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes
RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Drawing / GATEWAY GROUPS = 
RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Drawing / REMOTE GROUPS = SCB_USERS_PARTNER2
RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Drawing / CONTENT POLICY = 
RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Clipboard / FROM = 
RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Clipboard / TARGET = 
RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Clipboard / TIME = 7x24
RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Clipboard / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes
RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Clipboard / GATEWAY GROUPS = 
RDP Control > Channel Policies > PARTNER2-TERMINAL-ONLY > Clipboard / REMOTE GROUPS = SCB_USERS_PARTNER2

SSH Control > Channel Policies > PARTNER1-ssh-only > Session shell / FROM = 
SSH Control > Channel Policies > PARTNER1-ssh-only > Session shell / TARGET = 
SSH Control > Channel Policies > PARTNER1-ssh-only > Session shell / TIME = 7x24
SSH Control > Channel Policies > PARTNER1-ssh-only > Session shell / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes
SSH Control > Channel Policies > PARTNER1-ssh-only > Session shell / GATEWAY GROUPS = 
SSH Control > Channel Policies > PARTNER1-ssh-only > Session shell / REMOTE GROUPS = SCB_USERS_PARTNER1
SSH Control > Channel Policies > PARTNER1-ssh-only > Session shell / CONTENT POLICY = 
SSH Control > Channel Policies > PARTNER1-ssh-only > X11 forward / FROM = 
SSH Control > Channel Policies > PARTNER1-ssh-only > X11 forward / TARGET = 
SSH Control > Channel Policies > PARTNER1-ssh-only > X11 forward / TIME = 7x24
SSH Control > Channel Policies > PARTNER1-ssh-only > X11 forward / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes
SSH Control > Channel Policies > PARTNER1-ssh-only > X11 forward / GATEWAY GROUPS = 
SSH Control > Channel Policies > PARTNER1-ssh-only > X11 forward / REMOTE GROUPS = SCB_USERS_PARTNER1
SSH Control > Channel Policies > PARTNER1-ssh-only > X11 forward / ALLOWED CLIENT ADDRESSES = 

SSH Control > Channel Policies > ORG-ssh-only > Session shell / FROM = 
SSH Control > Channel Policies > ORG-ssh-only > Session shell / TARGET = 
SSH Control > Channel Policies > ORG-ssh-only > Session shell / TIME = 7x24
SSH Control > Channel Policies > ORG-ssh-only > Session shell / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes
SSH Control > Channel Policies > ORG-ssh-only > Session shell / GATEWAY GROUPS = 
SSH Control > Channel Policies > ORG-ssh-only > Session shell / REMOTE GROUPS = SCB_USERS_ORG
SSH Control > Channel Policies > ORG-ssh-only > Session shell / CONTENT POLICY = 
SSH Control > Channel Policies > ORG-ssh-only > X11 forward / FROM = 
SSH Control > Channel Policies > ORG-ssh-only > X11 forward / TARGET = 
SSH Control > Channel Policies > ORG-ssh-only > X11 forward / TIME = 7x24
SSH Control > Channel Policies > ORG-ssh-only > X11 forward / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes
SSH Control > Channel Policies > ORG-ssh-only > X11 forward / GATEWAY GROUPS = 
SSH Control > Channel Policies > ORG-ssh-only > X11 forward / REMOTE GROUPS = SCB_USERS_ORG
SSH Control > Channel Policies > ORG-ssh-only > X11 forward / ALLOWED CLIENT ADDRESSES = 

SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session exec SCP / FROM = 
SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session exec SCP / TARGET = 
SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session exec SCP / TIME = 7x24
SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session exec SCP / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes
SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session exec SCP / GATEWAY GROUPS = 
SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session exec SCP / REMOTE GROUPS = SCB_USERS_PARTNER1
SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session exec SCP / LOGGING / LOG FILE TRANSFERS TO SYSLOG / LOG FILE TRANSFERS TO DATABASE = VALUES / Yes / Yes
SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session SFTP / FROM = 
SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session SFTP / TARGET = 
SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session SFTP / TIME = 7x24
SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session SFTP / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes
SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session SFTP / GATEWAY GROUPS = 
SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session SFTP / REMOTE GROUPS = SCB_USERS_PARTNER1
SSH Control > Channel Policies > PARTNER1-scp-sftp-only > Session SFTP / LOGGING / LOG FILE TRANSFERS TO SYSLOG / LOG FILE TRANSFERS TO DATABASE = VALUES / Yes / Yes

SSH Control > Channel Policies > ORG-scp-sftp-only > Session exec SCP / FROM = 
SSH Control > Channel Policies > ORG-scp-sftp-only > Session exec SCP / TARGET = 
SSH Control > Channel Policies > ORG-scp-sftp-only > Session exec SCP / TIME = 7x24
SSH Control > Channel Policies > ORG-scp-sftp-only > Session exec SCP / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes
SSH Control > Channel Policies > ORG-scp-sftp-only > Session exec SCP / GATEWAY GROUPS = 
SSH Control > Channel Policies > ORG-scp-sftp-only > Session exec SCP / REMOTE GROUPS = SCB_USERS_ORG
SSH Control > Channel Policies > ORG-scp-sftp-only > Session exec SCP / LOGGING / LOG FILE TRANSFERS TO SYSLOG / LOG FILE TRANSFERS TO DATABASE = VALUES / Yes / Yes
SSH Control > Channel Policies > ORG-scp-sftp-only > Session SFTP / FROM = 
SSH Control > Channel Policies > ORG-scp-sftp-only > Session SFTP / TARGET = 
SSH Control > Channel Policies > ORG-scp-sftp-only > Session SFTP / TIME = 7x24
SSH Control > Channel Policies > ORG-scp-sftp-only > Session SFTP / ACTIONS / FOUR-EYES / AUDIT = VALUES / No / Yes
SSH Control > Channel Policies > ORG-scp-sftp-only > Session SFTP / GATEWAY GROUPS = 
SSH Control > Channel Policies > ORG-scp-sftp-only > Session SFTP / REMOTE GROUPS = SCB_USERS_ORG
SSH Control > Channel Policies > ORG-scp-sftp-only > Session SFTP / LOGGING / LOG FILE TRANSFERS TO SYSLOG / LOG FILE TRANSFERS TO DATABASE = VALUES / Yes / Yes
FieldWhat it means
Drawing, ClipboardThe RDP channels allowed: the screen itself, and the clipboard. Anything else (drive and printer redirection, sound, dynamic channels) is not in the list and therefore refused. The built-in RDP policy terminal-only allows the same two channels, which is presumably where the name *-TERMINAL-ONLY comes from
Session shell, X11 forwardThe SSH channels of the ssh-only policies: an interactive shell and forwarded X11. Port forwarding, agent forwarding and remote command execution are refused
Session exec SCP, Session SFTPThe SSH channels of the scp-sftp-only policies; each file transfer is logged to syslog and to the connection database
FROM, TARGETAddress restrictions inside the connection; empty, so the connection's own FROM and targets apply
TIME = 7x24The built-in time policy: always
ACTIONS / FOUR-EYES / AUDIT = VALUES / No / YesNo four-eyes authorization; the channel is recorded into the audit trail
GATEWAY GROUPSEmpty: gateway authentication is not used
REMOTE GROUPSOnly members of this AD group may open the channel. As I understand it, the SCB looks the username up in the LDAP server policy of the connection and checks the group, nested groups included
ALLOWED CLIENT ADDRESSESFor X11: which X server addresses the forwarded traffic may come from; empty

The design lists the RDP channel "Clipboard" without a direction, and it does not say why X11 forwarding was allowed.

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
Drawing and Clipboard; Session shell and X11; SCP and SFTP with transfer loggingThe channel types, the four-eyes option per channel and the time policy per channel are unchanged
User lists not usedUser lists are announced for removal; AD/LDAP groups are the recommended replacement, which is what these policies already use

Nothing here needs to change for SPS 9.0.

← solutionz