Balabit - Content, indexer and user list policies (site 1)
Balabit SCB Solution · Config document · referenced from Connection and channel policies
note
<LANGUAGE_2> and <LANGUAGE_3> are placeholders for the two further OCR languages. The content policy no-WINSCP is defined here but not referenced by any channel policy of the site 1 design; site 2 references it.The smaller policies of the site 1 cluster: the content policy no-WINSCP, the default indexer policy, the four built-in user lists, and the global options of the three protocols that were switched off (HTTP, Telnet, VNC).
| Item | Value |
|---|---|
| Where | SCB web interface, Policies > Content Policies, Policies > Indexer Policies, Policies > User Lists, HTTP Control, Telnet Control and VNC Control > Global Options |
| Cluster | dc1-s-xblb001 |
| Firmware at the time | 5 LTS (5.0.3) |
| Source | My design document, version 0.5 of 2017-12-01 (draft), chapters 7.4.3, 7.4.4, 7.4.7, 7.7, 7.8 and 7.9 |
| Time policies | Not in the answers: the design documents none, because only the built-in 7x24, 5x8, weekdays, weekend and 5x10 exist and every channel uses 7x24 |
The answers
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapters 7.4.3 to 7.9 Policies > Content Policies > no-WINSCP > SCREEN CONTENT (IN SSH AND TELNET) / MATCH = WinSCP: this is end-of-file Policies > Content Policies > no-WINSCP > SCREEN CONTENT (IN SSH AND TELNET) / IGNORE = Policies > Content Policies > no-WINSCP > SCREEN CONTENT (IN SSH AND TELNET) / ACTIONS = LOG / TERMINATE / NOTIFY Policies > Content Policies > no-WINSCP > SCREEN CONTENT (IN SSH AND TELNET) / GATEWAY GROUPS = Policies > Content Policies > no-WINSCP > SCREEN CONTENT (IN SSH AND TELNET) / REMOTE GROUPS = Policies > Indexer Policies > default / SELECT LANGUAGES MANUALLY FOR CHARACTER RECOGNITION = English / <LANGUAGE_2> / <LANGUAGE_3> Policies > User Lists > all / DEFAULT POLICY = ACCEPT Policies > User Lists > all / EXCEPTION = Policies > User Lists > none / DEFAULT POLICY = REJECT Policies > User Lists > none / EXCEPTION = Policies > User Lists > no_root / DEFAULT POLICY = ACCEPT Policies > User Lists > no_root / EXCEPTION = root Policies > User Lists > root_only / DEFAULT POLICY = REJECT Policies > User Lists > root_only / EXCEPTION = root HTTP Control > Global Options > TRAFFIC / SERVICE = disabled HTTP Control > Global Options > TRAFFIC / VERBOSITY LEVEL = 4 HTTP Control > Global Options > AUDIT / TIMESTAMPING = Local HTTP Control > Global Options > AUDIT / TIMESTAMPING POLICY = HTTP Control > Global Options > AUDIT / SIGNING INTERVAL = 30 (s) HTTP Control > Global Options > AUDIT / CHANNEL DATABASE CLEANUP = Telnet Control > Global Options > TRAFFIC / SERVICE = disabled Telnet Control > Global Options > TRAFFIC / VERBOSITY LEVEL = 4 Telnet Control > Global Options > AUDIT / TIMESTAMPING = Local Telnet Control > Global Options > AUDIT / TIMESTAMPING POLICY = Telnet Control > Global Options > AUDIT / SIGNING INTERVAL = 30 (s) Telnet Control > Global Options > AUDIT / CHANNEL DATABASE CLEANUP = VNC Control > Global Options > TRAFFIC / SERVICE = disabled VNC Control > Global Options > TRAFFIC / VERBOSITY LEVEL = 4 VNC Control > Global Options > AUDIT / TIMESTAMPING = Local VNC Control > Global Options > AUDIT / TIMESTAMPING POLICY = VNC Control > Global Options > AUDIT / SIGNING INTERVAL = 30 (s) VNC Control > Global Options > AUDIT / CHANNEL DATABASE CLEANUP =
| Field | What it means |
|---|---|
| no-WINSCP / MATCH | The text WinSCP leaves in a shell session when it transfers files over the shell channel. The design's reason: WinSCP in "SCP" mode moves files inside a Session Shell channel, so the transfers escape the file operations list and cannot be saved from the trail |
| no-WINSCP / ACTIONS | Log the event, terminate the connection and send a notification |
| GATEWAY GROUPS, REMOTE GROUPS | Empty: the rule applies to everybody |
| default / SELECT LANGUAGES MANUALLY | The OCR of graphical trails uses three fixed languages instead of automatic detection |
| User Lists | The four built-in lists. None is referenced by a channel policy |
| HTTP, Telnet, VNC / SERVICE = disabled | These protocols are not accepted. The site 2 file shows ICA disabled as well |
My notes keep a warning next to the indexer question: content policies slow connections down "approximately 5 times" and can cause performance problems with the indexer.
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
no-WINSCP matching "WinSCP: this is end-of-file" | The vendor's text is unchanged, including the advice to make clients use WinSCP with SFTP; the solution is described as tested with WinSCP 5.1.5. WinSCP itself, now at 6.5.7, still runs SCP through shell commands, and even with SFTP it can open a separate shell session for some commands |
| OCR in English and two further languages | The OCR engine was replaced in 9.0 and the language list changed; all three languages used here are still in it. Indexer policies should be reviewed after such an upgrade |
| Built-in user lists | Announced for removal; AD/LDAP groups are the replacement |
| Built-in time policies | Unchanged |
The content policy would still do its job; the vendor's documentation still names WinSCP 5.1.5 as the version it was tested with.