Chat now with support
Chat with Support

One Identity Safeguard for Privileged Sessions 5.9.0 - Administration Guide

Preface Introduction The concepts of SPS The Welcome Wizard and the first login Basic settings User management and access control Managing SPS
Controlling SPS: reboot, shutdown Managing Safeguard for Privileged Sessions clusters Managing a high availability SPS cluster Upgrading SPS Managing the SPS license Accessing the SPS console Sealed mode Out-of-band management of SPS Managing the certificates used on SPS
General connection settings HTTP-specific settings ICA-specific settings RDP-specific settings SSH-specific settings Telnet-specific settings VMware Horizon View connections VNC-specific settings Indexing audit trails Using the Search (classic) interface Using the Search interface Searching session data on a central node in a cluster Advanced authentication and authorization techniques Reports The SPS RPC API The SPS REST API SPS scenarios Troubleshooting SPS Configuring external devices Using SCP with agent-forwarding Security checklist for configuring SPS Jumplists for in-product help Third-party contributions About us

Preferences

To configure your preferences about the web interface, navigate to User Menu > Preferences.

Figure 36: User Menu > Preferences

  • Show tooltips: Display tooltips for user interface elements to help using the product.

  • Confirmation before deleting policies: Display a pop-up window when you attempt to delete policies to prevent deleting policies accidentally.

  • Confirmation before deleting entries: Display a pop-up window when you attempt to delete entries to prevent deleting entries accidentally.

  • Warn when unsaved changes may be lost: Display a pop-up window to warn when you navigate to another window without committing your changes to prevent losing unsaved changes.

  • Autoclose successful commit messages: General confirmation windows will not appear. (For example, Configuration saved successfully that appears after successfully committing a change). As a result, pop-up windows appear only for failed actions or errors.

  • Mousewheel scrolling of search results: When there are several pages of displayable search results on the Search page, navigate between search result pages with the mousewheel. When turned off, using the mousewheel on the Search page scrolls the whole page.

  • Audit trail filename template:

    To change the filename of the audit trails, navigate to User menu > Preferences and change the Audit trail filename template. The default template is {protocol}-{starttime}-{gw-username}-{remote-username}-{dst-ip}.zat. The template can include anything, the keys (inside {} brackets) are replaced with their actual values. These keys are the following:

    • connection-policy: The connection policy

    • dst-ip: Destination IP address

    • dst-port: Destination port

    • gw-username: Gateway username

    • protocol: Protocol

    • remote-username: Remote username

    • session-id: Session ID

    • src-ip: Source IP address

    • starttime: Start time of the session

Network settings

The Basic Settings > Network tab contains the network interface and naming settings of SPS.

Interfaces:

Figure 37: Basic Settings > Network > Interfaces

Lists all of the logical interfaces (VLAN IDs, IP addresses, netmasks, and names) assigned to the three physical interfaces of SPS. For more information on managing logical interfaces, see Managing logical interfaces.

In addition, it is also possible to set the Maximum Transmission Unit (MTU) for each network interface (VLAN or network interface card) individually. The default value is 1500.

Speed is displayed for every physical interface. To explicitly set the speed of the interface, select the new value from the Speed field. Modifying the speed of an interface is recommended only for advanced users.

You can add interface-specific network routes using the Advanced routing option of each interface. Otherwise, use the Routing table option to manage networking routes.

Routing table:

Figure 38: Basic Settings > Network > Routing table

When sending a packet to a remote network, SPS consults the routing table to determine the path it should be sent. If there is no information in the routing table then the packet is sent to the default gateway. Use the routing table to define static routes to specific hosts or networks. You have to use the routing table if SPS interfaces are connected to multiple subnets.

Click the and icons to add new routes or delete existing ones. A route means that messages sent to the Address/Netmask network should be delivered to Gateway.

For detailed examples, see Configuring the routing table.

IP forwarding:

Figure 39: Basic Settings > Network > IP forwarding

You can enable routing between logical interfaces, which allows you to direct uncontrolled traffic through SPS. For more information, see Routing uncontrolled traffic between logical interfaces.

To mimic the functionality of the deprecated Router mode, configure a logical interface for each physical interface you want to connect, and enable IP forwarding between them.

Naming:

Figure 40: Basic Settings > Network > Naming

  • Hostname: Name of the machine running SPS.

  • Nick name: The nickname of SPS. Use it to distinguish the devices. It is displayed in the core and boot login shells.

  • DNS search domain: Name of the domain used on the network. When resolving the domain names of the audited connections, SPS will use this domain to resolve the target hostname if the appended domain entry of a target address is empty.

  • Primary DNS server: IP address of the name server used for domain name resolution.

  • Secondary DNS server: IP address of the name server used for domain name resolution if the primary server is unaccessible.

Configuring user and administrator login addresses

Purpose:

You can configure two separate login addresses for accessing the web interface of SPS:

  • Web login for administrators and users: On this address, users can, depending on their access privileges, modify the configuration of SPS, and perform authentication-related activities (gateway authentication, 4-eyes authorization).

  • Web login for users only: The configuration of SPS cannot be viewed or altered from this address. Users (even ones with administrator privileges) can only perform gateway authentication and 4-eyes authorization.

NOTE:

You can find more information about gateway authentication and 4-eyes authorization in Advanced authentication and authorization techniques.

Both login addresses can be configured to restrict connections to a configured set of IP addresses only.

NOTE:

Avoid using the IP address configured for administrator or user login on SPS when configuring HTTP or SSH connections.

The login addresses are, by default, protected against brute-force attacks: after five unsuccessful login attempts, all following attempts are denied for increasing periods of time. You can turn this off by unselecting the Protect against brute-force attacks option for the web login addresses.

Steps:
  1. Navigate to Basic Settings > Local Services > Web login.

    Figure 41: Basic Settings > Local Services > Web login — Configuring web login address

  2. In the Listening addresses field, choose .

  3. Into the Address field, choose the IP address to use for connecting to SPS's user interface.

    The available addresses correspond to the interface addresses configured in Basic Settings > Network > Interfaces. Only IPv4 addresses can be selected.

  4. Into the HTTP field, enter the port number for HTTP connections.

  5. Into the HTTPS field, enter the port number for HTTPS connections.

  6. Optional step: To permit access to the SPS web interface only from selected subnets or IP addresses, select Restrict clients, click and enter the IP address and netmask of the allowed clients. Note that these settings do not affect the SSH access to SPS.

    Caution:

    Permit administrative access to SPS only from trusted networks. If possible, monitored connections and administrative access to the SPS web interface should originate from separate networks.

    After comitting the changes, the web interface will be available only from the configured subnets or IP addresses.

    Use an IPv4 address.

  7. Recommended: configure a separate login address for user connections in Web login (user only). The configuration settings of SPS cannot be viewed or modified from this address.

  8. Click Commit.

Managing logical interfaces

Purpose:

You can assign logical interfaces to a physical interface. Each logical interface must have its own VLAN ID, and can have its own set of (alias) IP addresses and prefixes. The configured name for each logical interface is visible on SPS's user interface only.

You can configure IPv4 and IPv6 addresses as well. IPv6 is intended for configuring monitored connections. Local services (including the web login) require IPv4 addresses. An interface can have multiple IP addresses, including a mix of IPv4 and IPv6 addresses.

NOTE:

SPS does not support scenarios with two hosts using the same IP address on different VLAN groups.

Steps:
  1. Navigate to Basic Settings > Network > Interfaces.

    Figure 42: Basic Settings > Network > Interfaces — Managing the logical interfaces

  2. If necessary, use the label on the SPS hardware to identify the physical interface to which you want to assign a logical interface.

  3. Choose to add a new logical interface. Provide the following:

    • VLAN: The VLAN ID of the logical interface. Optional.

      Caution:

      Do not set the VLAN ID unless your network environment is already configured to use this VLAN. Otherwise, your SPS appliance will be unavailable using this interface.

    • Address: The IP address of the logical interface.

      You can also enter a hostname instead of the IP address, and SPS automatically resolves the hostname to IP address. Note the following limitations:

      • SPS uses the Domain Name Servers set Basic Settings > Network > Naming > Primary DNS server and Secondary DNS server fields to resolve the hostnames.

      • Only IPv4 addresses are supported.

      • If the Domain Name Server returns multiple IP addresses, SPS selects randomly from the list.

      NOTE:

      Do not use IP addresses that fall into the following ranges:

      • 1.2.0.0/16 (reserved for communication between SPS cluster nodes)

      • 127.0.0.0/8 (localhost IP addresses)

    • Prefix: The IP range of the logical interface.

    • Optional: To add additional (alias) IP addresses and prefixes to a logical interface, click . To remove an alias IP address, click the corresponding .

    • MTU: Maximum Transmission Unit (MTU) to set per network interface (VLAN or network interface card). The default value is 1500.

    • Name: The name of the logical interface. This name is visible on SPS's user interface only.

    To remove a logical interface, choose the on the right side.

  4. Click Commit.

Related Documents