LINUXOR.SK ... open source notes ...

Balabit - Content, indexer and user list policies (site 1)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Connection and channel policies

note<LANGUAGE_2> and <LANGUAGE_3> are placeholders for the two further OCR languages. The content policy no-WINSCP is defined here but not referenced by any channel policy of the site 1 design; site 2 references it.

The smaller policies of the site 1 cluster: the content policy no-WINSCP, the default indexer policy, the four built-in user lists, and the global options of the three protocols that were switched off (HTTP, Telnet, VNC).

ItemValue
WhereSCB web interface, Policies > Content Policies, Policies > Indexer Policies, Policies > User Lists, HTTP Control, Telnet Control and VNC Control > Global Options
Clusterdc1-s-xblb001
Firmware at the time5 LTS (5.0.3)
SourceMy design document, version 0.5 of 2017-12-01 (draft), chapters 7.4.3, 7.4.4, 7.4.7, 7.7, 7.8 and 7.9
Time policiesNot in the answers: the design documents none, because only the built-in 7x24, 5x8, weekdays, weekend and 5x10 exist and every channel uses 7x24

The answers

ini
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapters 7.4.3 to 7.9

Policies > Content Policies > no-WINSCP > SCREEN CONTENT (IN SSH AND TELNET) / MATCH = WinSCP: this is end-of-file
Policies > Content Policies > no-WINSCP > SCREEN CONTENT (IN SSH AND TELNET) / IGNORE = 
Policies > Content Policies > no-WINSCP > SCREEN CONTENT (IN SSH AND TELNET) / ACTIONS = LOG / TERMINATE / NOTIFY
Policies > Content Policies > no-WINSCP > SCREEN CONTENT (IN SSH AND TELNET) / GATEWAY GROUPS = 
Policies > Content Policies > no-WINSCP > SCREEN CONTENT (IN SSH AND TELNET) / REMOTE GROUPS = 

Policies > Indexer Policies > default / SELECT LANGUAGES MANUALLY FOR CHARACTER RECOGNITION = English / <LANGUAGE_2> / <LANGUAGE_3>

Policies > User Lists > all / DEFAULT POLICY = ACCEPT
Policies > User Lists > all / EXCEPTION = 

Policies > User Lists > none / DEFAULT POLICY = REJECT
Policies > User Lists > none / EXCEPTION = 

Policies > User Lists > no_root / DEFAULT POLICY = ACCEPT
Policies > User Lists > no_root / EXCEPTION = root

Policies > User Lists > root_only / DEFAULT POLICY = REJECT
Policies > User Lists > root_only / EXCEPTION = root

HTTP Control > Global Options > TRAFFIC / SERVICE = disabled
HTTP Control > Global Options > TRAFFIC / VERBOSITY LEVEL = 4
HTTP Control > Global Options > AUDIT / TIMESTAMPING = Local
HTTP Control > Global Options > AUDIT / TIMESTAMPING POLICY = 
HTTP Control > Global Options > AUDIT / SIGNING INTERVAL = 30 (s)
HTTP Control > Global Options > AUDIT / CHANNEL DATABASE CLEANUP = 

Telnet Control > Global Options > TRAFFIC / SERVICE = disabled
Telnet Control > Global Options > TRAFFIC / VERBOSITY LEVEL = 4
Telnet Control > Global Options > AUDIT / TIMESTAMPING = Local
Telnet Control > Global Options > AUDIT / TIMESTAMPING POLICY = 
Telnet Control > Global Options > AUDIT / SIGNING INTERVAL = 30 (s)
Telnet Control > Global Options > AUDIT / CHANNEL DATABASE CLEANUP = 

VNC Control > Global Options > TRAFFIC / SERVICE = disabled
VNC Control > Global Options > TRAFFIC / VERBOSITY LEVEL = 4
VNC Control > Global Options > AUDIT / TIMESTAMPING = Local
VNC Control > Global Options > AUDIT / TIMESTAMPING POLICY = 
VNC Control > Global Options > AUDIT / SIGNING INTERVAL = 30 (s)
VNC Control > Global Options > AUDIT / CHANNEL DATABASE CLEANUP = 
FieldWhat it means
no-WINSCP / MATCHThe text WinSCP leaves in a shell session when it transfers files over the shell channel. The design's reason: WinSCP in "SCP" mode moves files inside a Session Shell channel, so the transfers escape the file operations list and cannot be saved from the trail
no-WINSCP / ACTIONSLog the event, terminate the connection and send a notification
GATEWAY GROUPS, REMOTE GROUPSEmpty: the rule applies to everybody
default / SELECT LANGUAGES MANUALLYThe OCR of graphical trails uses three fixed languages instead of automatic detection
User ListsThe four built-in lists. None is referenced by a channel policy
HTTP, Telnet, VNC / SERVICE = disabledThese protocols are not accepted. The site 2 file shows ICA disabled as well

My notes keep a warning next to the indexer question: content policies slow connections down "approximately 5 times" and can cause performance problems with the indexer.

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
no-WINSCP matching "WinSCP: this is end-of-file"The vendor's text is unchanged, including the advice to make clients use WinSCP with SFTP; the solution is described as tested with WinSCP 5.1.5. WinSCP itself, now at 6.5.7, still runs SCP through shell commands, and even with SFTP it can open a separate shell session for some commands
OCR in English and two further languagesThe OCR engine was replaced in 9.0 and the language list changed; all three languages used here are still in it. Indexer policies should be reviewed after such an upgrade
Built-in user listsAnnounced for removal; AD/LDAP groups are the replacement
Built-in time policiesUnchanged

The content policy would still do its job; the vendor's documentation still names WinSCP 5.1.5 as the version it was tested with.

← solutionz