Updated on 2026-07-30 GMT+08:00

Creating a Command Rule

Scenarios

You can create command rules to control which commands can run on managed Linux servers during operation. This gives you granular control over command execution and helps prevent high-risk command execution.

For Linux servers using SSH or Telnet, the guacd proxy audits and filters commands executed during operation based on the rules configured by the administrator. It then returns the audited commands, filtering results, and command outputs for session operation recording, dynamic authorization, and disconnection.

With command rules, you can:

  • Period of validity: Configure the start and end time of the rule validity period. To make the rule valid permanently, leave this parameter empty.
  • Time Limit: Set the days and time when the rule is valid or invalid.
  • Action: Set the action allowed by the rule.
    • Disconnect: After the rule is triggered, the system rejects to execute the command and disconnects the operation session. The system displays a message indicating that the connection is forcibly disconnected by the administrator.
    • Reject command: After the command rule is triggered, the system rejects executing the command and displays a message indicating that the command has been intercepted.
    • Dynamic approval: After the rule is triggered, the system rejects executing the command. The system displays a message indicating that the command has been intercepted and asking you to submit a command approval ticket. A command approval ticket is automatically generated. The command can be executed only after the ticket is submitted and approved.
    • Permit: When the rule is triggered, the system continues to execute the command. By default, all operations are allowed.

Notes and Constraints

  • Command rules apply only to Linux hosts using the SSH or Telnet protocol for fine-grained permission control.
  • Command approval tickets take precedence over command rules.

Precautions

On the rule list page, policies are sorted by priority. The rule in the upper position has higher priority than those in a lower position. To change the priority of a rule, select the rule and drag and drop it to an upper or lower position.

Prerequisites

Your role has the management permission for the Cmd Rules module. For details about the permissions of each role, see Role.

Method 1: Creating a Command Rule

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Policy > Cmd Rules > Cmd Rules to go to the command rule list page.
  3. On the displayed page, click New in the upper right corner of the page.
  4. Configure the basic rule information.

    Table 1 Parameters for creating a command rule

    Parameter

    Description

    Rule Name

    Enter a name for the command rule. The rule name must be unique in a bastion host.

    Naming rules: The value can contain 1 to 64 characters. Only letters, digits, and hyphens (-) are allowed.

    Action

    Select an action for the command rule.

    • Disconnect: After the rule is triggered, the system rejects to execute the command and disconnects the operation session. The system displays a message indicating that the connection is forcibly disconnected by the administrator.
    • Reject command: After the command rule is triggered, the system rejects executing the command and displays a message indicating that the command has been intercepted.
    • Dynamic approval: After the rule is triggered, the system rejects executing the command. The system displays a message indicating that the command has been intercepted and asking you to submit a command approval ticket. A command approval ticket is automatically generated. The command can be executed only after the ticket is submitted and approved.
    • Permit: When the rule is triggered, the system continues to execute the command. By default, all operations are allowed.

    Period of validity

    Configure the start and end time for the rule validity period. To make the rule valid permanently, leave this parameter empty.

    Time Limit

    Set the days and time when the rule is valid or invalid.

  5. Click Next and start to associate the rule with a command or command set.

    • Associating the rule with a command

      Enter one or more commands in the text box. For details, see Format Description of Associated Custom Commands.

    • Associating the rule with a command set
      • You can associate a rule with multiple command sets at once. For details about how to create a command set, see Creating and Managing Command Sets.
        • Select a command set: On the Relate Command Set tab, select a command set in the Selectable cmdset area and click to move it to the Selected cmdset area.
        • Remove a command set: On the Relate Command Set tab, select a command set in the Selected cmdset area and click to move it to the Selectable cmdset area.
      • After a command set is associated with a rule, commands added to the command set automatically inherit the permissions of that rule.
      • If you skip this step, you can associate commands or command sets with the rule later on the command rule list page or details page.

  6. Click Next and start to relate the command rule to one or more users or user groups.

    Make sure the associated users or users in the associated user groups have the permissions for the Cmd Tickets module. Otherwise, after they log in to the system, the Cmd Tickets module will be unavailable to them. This means they cannot submit tickets to obtain approval during operation. For details about the permissions of each role, see Role.
    • You can associate a rule with multiple users or user groups at once.
      • Select users or user groups: On the Relate User or Relate User Group tab, select users or user groups in the Selectable users or Selectable user groups box, and click to move them to the Selected users or Selected user groups box.
      • Remove users or user groups: On the Relate User or Relate User Group tab, select users or user groups in the Selected users or Selected user groups box, and click to move them back to the Selectable users or Selectable user groups box.
    • After a user group is associated with a rule, users automatically obtain the permissions of the rule the instant they are added to the user group.
    • If you skip this step, you can associate users or user groups with the rule later on the command rule list page or details page.

  7. Click Next and start to associate the rule with one or more accounts or account groups.

    • You can associate a rule with multiple managed resource accounts or account groups at once.
      • Select a resource account or account group: On the Relate Account or Relate Account Group tab, select the target resource account or account group in the Selectable accounts or Selectable account groups box, and click to move it to the Selected accounts or Selected account groups box.
      • Remove a resource account or account group: On the Relate Account or Relate Account Group tab, select the target resource account or account group in the Selected accounts or Selected account groups box, and click to remove it back to the Selectable accounts or Selectable account groups box.
    • After an account group is associated with a rule, accounts automatically obtain the permissions of the rule the instant they are added to the account group.
    • If you skip this step, you can associate resource accounts or account groups with the rule later on the command rule list page or details page.

  8. Click OK.

    You can return to the rule list page and view the new command rule. During operation, when the rule is triggered, the system executes configured actions accordingly.

Method 2: Inserting a Command Rule

You can create a rule and insert it before an existing rule. The inserted rule has a higher priority.

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Policy > Cmd Rules > Cmd Rules to go to the command rule list page.
  3. In the row containing the target rule, click Insert in the Operation column.
  4. Configure the rule by referring to Table 1 and click Next.
  5. Associate the rule with a command or command set by referring to 5 and click Next.
  6. Associate the rule with a user or user group by referring to 6 and click Next.
  7. Associate the rule with a resource account or account group by referring to 7, and click OK.

    On the command rule list page, you can view the inserted rule.

Format Description of Associated Custom Commands

After a custom command is associated with a command rule, the bastion host determines whether to execute the command based on the command rule.

Custom associated commands are case-sensitive. If the command to be executed is inconsistent with the configured one, the command rule will fail to be triggered. The following examples are for your reference:

  • One command in each line (Only letters, digits, hyphens (-), and underscores (_) are allowed for the command.)
  • Single command format

    If you want to configure a rule to deny the ls command, set the associated command for the rule to ls. The rule is triggered when the single command ls is executed.

  • Single command and path format

    If you want to configure a rule to dynamically authorize the log query actions, set the associated command for the rule to ls /var/log/. The rule is triggered when the command ls /var/log/ is executed. If the ls /var/log command is executed, the rule fails to be triggered.

  • Commands that contain the wildcard character (*), which indicates one or more characters

    If you want to configure a rule to deny all deletion commands, set the associated command for the rule to rm *. The rule is triggered when the command rm -rf is executed; while the rule will fail to be triggered if the rm command is executed.

  • Commands that contain the question mark (?), which indicates any single character (The number of entered question marks indicates the number of unknown characters.)

    If you want to configure a rule to deny commands that will delete files or file directories containing two certain characters, set the associated command to rm -rf ??. The rule is triggered when the command rm -rf ts is executed. The rule will fail to be triggered if the rm -rf test command is executed.

  • Commands that contain a string or any characters enclosed in square brackets ([]) or negated ones in square brackets (using a vertical bar (|) or caret (^) to negate)

    If you want to configure a rule to dynamically approve commands that will delete files or file directories containing any characters in the string "abcd", set the associated command of the rule to rm -rf [abcd]. The rule is triggered when the command rm -rf cloud is executed. The rule will fail to be triggered if the rm -rf test or rm -rf ABCD command is executed.