3.5 Policy Management
Policy Management
Defining a Device Realm
- Log in to the Single Connect Web GUI
- Navigate to Device Management > Device Group
- Open the Device Realm tab
- Pick a Device Group name from the “Device Group” list on the right; pick a User Group name from the “User Group” list from the left. Now a new “Device Realm” has been created by matching a device group with a user group
Defining a Policy-Key
- Log in to the Single Connect Web GUI
- Navigate to Policy Control > Session Policy
- Open the Policy Key tab
- Select the Type, Element Type and fill in the Key and Description fields
- Save
Policy Key Types: | Definition |
|---|---|
Black Key | Restricted commands |
White Key | Allowed commands |
XML File | XML file that contains context aware policies |
Radius Attribute | Allowed Radius attributes Ex: cisco-avpair := shell:priv-lvl=1 |
TACACS Attribute | Allowed TACACS attributes Ex: priv-lvl=15 |
User Behavior Rating | Commands to be detected as suspicious behavior to block |
Black/White Key Command Generator
The “Key” parameter of the policy definition contains the allowed or restricted commands in their regex form. The “CommandPatternGenerator” button can be used for the creation of these regex statements.
Input the desired command into the “Commands” tab, denoting the “auto-completion point” with a “ ‘ ” (single quote) character. Click the button to create the regex statement.
Note |
|---|
“auto-completion point” is the point in a command string when hitting TAB would complete the remainder of the command. For example, for “clear”, the auto-completion point is “cl”. Which means hitting TAB after typing “cl” will complete the command to “clear” on the CLI screen. |
Defining Policy Group
- Log in to the Single Connect Web GUI
- Navigate to Policy Control > Session Policy
- Open the Policy tab
- Enter the Policy Name, Description, Operation Mode
- Select and add the policy key(s) defined earlier for this group under “Select Policy Key(s)”
- Save
Operation Mode: | Definition |
|---|---|
Operation | Policy group is available when devices are in operation mode (out of maintenance mode) |
Maintenance | Policy group is available when devices are in maintenance mode. Maintenance mode is set on devices. (See also: Managing Devices – Maintenance Mode Settings) |
Defining Time Restriction Policy
Time-based restrictions are used to regulate the CLI connections to network elements via Single Connect on a timely manner. Time and command-based restrictions can be used together to correspond with security needs. The example below reflects a scenario that a service provider may experience often.
Time Interval | Authorization | Explanation |
|---|---|---|
Weekdays 06:00 - 22:00 | Only monitoring commands | Configuration commands are restricted due to potential service affect. |
Weekdays 22:00 - 02:00 | All the configuration commands may be run but service affecting commands | Operators may run all the configuration commands but commands such as “reboot, restart, BGP shutdown” |
Weekdays 02:00 - 06:00 | All commands | No restriction on command running |
Weekend | Only monitoring commands | Configuration commands are restricted due to potential service affect. |
There must be four time-based policies and three command-based policies covering all of the alternatives from the table above.
Time Based Policies:
TBP 1: 06:00 – 22:00, Mon, Tue, Wed, Thu, Fri
TBP 2: 22:00 – 02:00, Mon, Tue, Wed, Thu, Fri
TBP 3: 02:00 – 06:00, Mon, Tue, Wed, Thu, Fri
TBP 4: Sat, Sun
Command Based Policies
Whitelist 1: .*sh.*
Blacklist 1: .*rebo.* , .*resta.* , .*bgp.*/s.*shut.*
Whitelist 2: .*
The Regular Expression mentioned as “.*” covers all of the command subset. By using command and time-based policies together the scenario above is corresponded as below:
- Weekdays 06:00 – 22:00: TBP 1 & Whitelist 1
- Weekdays 22:00 – 02:00: TBP 2 & Blacklist 1
- Weekdays 02:00 – 06:00: TBP 3 & Whitelist 2
- Weekend TBP 4 & Whitelist 1
Defining Permit Zone Policy
The defined IP address can connect to devices directly, others IP that is not defined cannot connect directly.
- Log in to the Single Connect Web GUI
- Navigate to Policy Control > Session Policy
- Open the “Permit Zone” tab
- Enter in IP and username
- Save
Defining Policy Realm
- Log in to the Single Connect Web GUI
- Navigate to Policy Control > Session Policy
- Go to the “Policy Realm” tab
- On this screen, enter the desired policy realm name with the “PR_” prefix format
- Select “Policy Groups” from the right and “Device Realms” from the left. A “Policy Realm” is created by matching “Policy Groups” with “Device Realms”
Managerial Approval Reservation
For the devices that requires managerial approval for connection, users can make reservation for future dates, in order to get the approvals before the planned activity time. To make reservation:
- Log in to the Single Connect Web GUI
- Navigate to Policy Control > Reservation Management
- Start typing the host info.
- Select the device appearing in search results below the text box.
- Click + button.
- Select Time Start and Time End.
- Save
After these steps are completed, reservation record will appear in Search Results part, and responsible manager will get the approval email. User can connect to the device(s) between the specified start and end times, if the manager approves.