Updated on 2026-09-17 GMT+08:00

Creating an ACL Rule

Scenarios

ACL Rules are used to control users' permissions for accessing resources. You can configure ACL rules and associate them with users and resources to control operation personnel, resources, and operations.

You can create ACL rules in many ways. The basic restrictions and functions are as follows:
  • Period of validity: This function controls when a rule is valid.
  • Logon Time Limit: This function controls when a user can log in to the system.
  • IP Limit: This function allows you to control access to managed resources by an IP address blacklist or whitelist.
    • Blacklist: Configure the IP addresses or IP address range to restrict users from these IP addresses from logging in to the resources.
    • Whitelist: Configure the IP addresses or IP address range to allow users from these IP addresses to log in to the resources.
    • If no IP addresses are specified, there is no IP-based login restriction.
  • File Transmission: This function controls permissions to upload and download files during operation.
  • File Manage: This function allows you to manage file or folder permissions, including the permissions to view, delete, and edit files and folders.
  • Uplink clipboard: This function allows you to copy text through the operation session RDP clipboard.
  • Downlink clipboard: This function allows you to paste text through the operation session RDP clipboard.
  • Watermark: This function displays the user login name watermark in the operation session window.
  • Keyboard Audit: This function records the information entered through the keyboard.
  • Kiosk: This function allows you to disable F12, right-click, and the browser toolbar when managing applications through a browser. You can use F12 instead of Ctrl to implement combined key operations. For example, the original combined key for switching between tabs or windows is Ctrl+Tab. If you select Kiosk, you can use F12+Tab to implement combined key operations.

Notes and Constraints

  • To grant the file upload/download permission, enable File Transmission and File Manage.
  • When you create an ACL rule, it automatically belongs to your department by default. To change its department, modify the ACL rule. For details, see Viewing and Editing an ACL Rule.

Precautions

On the rule list page, policies are sorted by priority. The rule in the upper position has higher priority than those in a lower position. To change the priority of a rule, select the rule and drag and drop it to an upper or lower position.

Prerequisites

Your role has the management permission for the ACL Rules module. For details about how to check the permissions of each role, see Role.

Method 1: Creating a Single ACL Rule

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Policy > ACL Rules to enter the ACL rule list page.
  3. On the displayed page, click New in the upper right corner of the page.
  4. Configure the basic information.

    Table 1 Basic information about an ACL rule

    Parameter

    Description

    Rule Name

    Enter a custom name for the ACL rule. The rule name must be unique in a bastion host.

    Naming rules: The value can contain 1 to 64 characters. Only letters, digits, and hyphens (-) are allowed.

    Period of validity

    Configure the start and end time for the rule validity period. To make the rule valid permanently, leave this parameter empty.

    File Transmission

    Configure the permission to upload and download files during operation. If Upload or Download is selected, File Manage must be selected in Options for the permission to take effect.

    • If Upload and/or Download are selected, files can be uploaded and/or downloaded.
    • If Upload and Download are deselected, files cannot be uploaded or downloaded.

    Options

    Configure the session window functions that can be used during operation. If you select a function, you also need to select the same function for the associated resources to let the selected function work. The function items that can be set depend on resource types. For details, see ACL Rule Functions.

    • File Manage: This function allows you to manage file or folder permissions, including the permissions to view, delete, and edit files and folders.
    • Uplink clipboard: This function allows you to copy text through the operation session RDP clipboard.
    • Downlink clipboard: This function allows you to paste text through the operation session RDP clipboard.
    • Watermark: This function displays the user login name watermark in the operation session window.
    • Keyboard Audit: This function records the information entered through the keyboard.
    • Kiosk: This function allows you to disable F12, right-click, and the browser toolbar when managing applications through a browser. You can use F12 instead of Ctrl to implement combined key operations. For example, the original combined key for switching between tabs or windows is Ctrl+Tab. If you select Kiosk, you can use F12+Tab to implement combined key operations.

    Logon Time Limit

    Configure the days and time when users can log in to the resource. Blue indicates that the login is allowed, and white indicates that the login is forbidden.

    IP Limit

    Configure an IP address blacklist or whitelist to control access to managed resources.

    • Blacklist: Configure the IP addresses or IP address range to restrict users from these IP addresses from logging in to the resources.
    • Whitelist: Configure the IP addresses or IP address range to allow users from these IP addresses to log in to the resources.
    • If no IP addresses are specified, there is no IP-based login restriction.

  5. Click Next and start to associate the rule with one or more users or user groups.

    Make sure the associated users or users in the associated user groups have the permissions for the Host Operations or App Operations module. Otherwise, after they log in to the system, the Operation module will be unavailable to them. This means they cannot log in to any managed resources for operation. For details about the permissions of each role, see Role.
    • You can associate a rule with multiple users or user groups at once.
      • Select users or user groups: On the Relate User or Relate User Group tab, select users or user groups in the Selectable users or Selectable user groups box, and click to move them to the Selected users or Selected user groups box.
      • Remove users or user groups: On the Relate User or Relate User Group tab, select users or user groups in the Selected users or Selected user groups box, and click to move them back to the Selectable users or Selectable user groups box.
    • After a user group is associated with a rule, users automatically obtain the permissions of the rule the instant they are added to the user group.
    • If you skip this step, you can associate users or user groups with the rule later on the ACL rule list page or details page.

  6. Click Next and start to associate the rule with one or more accounts or account groups.

    • You can associate a rule with multiple managed resource accounts or account groups at once.
      • Select a resource account or account group: On the Relate Account or Relate Account Group tab, select the target resource account or account group in the Selectable accounts or Selectable account groups box, and click to move it to the Selected accounts or Selected account groups box.
      • Remove a resource account or account group: On the Relate Account or Relate Account Group tab, select the target resource account or account group in the Selected accounts or Selected account groups box, and click to remove it back to the Selectable accounts or Selectable account groups box.
    • After an account group is associated with a rule, accounts automatically obtain the permissions of the rule the instant they are added to the account group.
    • If you skip this step, you can associate resource accounts or account groups with the rule later on the ACL rule list page or details page.

  7. Click OK.

    On the ACL rule list page, you can view the new rule.

Method 2: Batch Importing ACL Rules

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Policy > ACL Rules to enter the ACL rule list page.
  3. Click in the upper right corner.
  4. In the displayed dialog box, click Download template and download the import template.
  5. Prepare ACL rules according to the template.
  6. In the displayed dialog box, click Upload and upload the completed ACL rule form.

    • Only .xls, .xlsx, and .csv files can be uploaded.
    • To overwrite the existing rules, select Override existing opsStrategy.

  7. Click OK to complete the upload.

    On the ACL rule list page, you can view the imported rules.

Method 3: Inserting an ACL Rule

You can create a rule and insert it before an existing rule. The inserted rule has a higher priority.

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Policy > ACL Rules to enter the ACL rule list page.
  3. In the Operation column of the target rule, click More > Insert.
  4. Configure the rule by referring to Table 1 and click Next.
  5. Associate the rule with a user or user group by referring to 5 and click Next.
  6. Associate the rule with a resource account or account group by referring to 6, and click OK.

    On the ACL rule list page, you can view the inserted rule.

Method 4: Copying an ACL Rule

You can copy a rule and modify its validity period, department, and functions as needed to create a new rule quickly. The new rule is bound to the same users and resources as the original rule.

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Policy > ACL Rules to enter the ACL rule list page.
  3. In the Operation column of the target rule, click More > Clone.
  4. Set the rule name and department, configure other parameters by referring to Table 1, and click OK.

    On the ACL rule list page, you can view the rule you copy.

ACL Rule Functions

The supported functions vary depending on the operation method and resource types.

Task Type

Period of Validity

File Transfer

Options

Logon Time Limit

IP Limit

Two-person Authorization

-

Effective/Expiration Time

Upload/Download

File Management

Uplink/Downlink clipboard

Watermarking

Keyboard Audit

Kiosk

Permit

Forbid

Blacklist

Whitelist

-

SSH HTML5 operation

√

√

√

√

√

×

×

√

√

√

√

√

SSH client operation

√

×

×

×

×

×

×

√

√

√

√

×

RDP HTML5 operation

√

√

√

√

√

√

×

√

√

√

√

√

RDP client operation

√

×

×

×

×

√

×

√

√

√

√

×

Telnet HTML5 operation

√

√

√

√

√

×

×

√

√

√

√

√

Telnet client operation

√

×

×

×

×

×

×

√

√

√

√

×

VNC

√

×

×

×

√

√

×

√

√

√

√

√

FTP

√

√

√

×

×

×

×

√

√

√

√

√

SFTP

√

√

√

×

×

×

×

√

√

√

√

√

SCP

√

×

×

×

×

×

×

√

√

√

√

√

PostgreSQL

√

×

×

×

×

×

×

√

√

√

√

√

GaussDB

√

×

×

×

×

×

×

√

√

√

√

√

DB2

√

×

×

×

×

×

×

√

√

√

√

√

MySQL

√

×

×

×

×

×

×

√

√

√

√

√

SQL Server

√

×

×

×

×

×

×

√

√

√

√

√

Oracle

√

×

×

×

×

×

×

√

√

√

√

√

Redis

√

×

×

×

×

×

×

√

√

√

√

√

DM

√

×

×

×

×

×

×

√

√

√

√

√

MongoDB

√

×

×

×

×

×

×

√

√

√

√

√

Rlogin HTML5 operation

√

√

√

√

√

×

×

√

√

√

√

√

Rlogin client operation

√

×

×

×

×

×

×

√

√

√

√

×

Windows application operation

√

√

√

√

√

√

√

√

√

√

√

√

Linux application operation

√

√ (supported in V3.3.40.0 and later versions)

√

√ (supported in V3.3.40.0 and later versions)

√

√

√

√

√

√

√

√