Managing Command Control Rules
Scenarios
You can modify, enable, disable, or delete a command rule you configure, or associate a command rule with a command, command set, user, user group, resource account, or account group.
Prerequisites
Your role has the management permission for the Cmd Rules module. For details about the permissions of each role, see Role.
Viewing and Editing a Command Rule
This topic describes how to view and edit a command rule. You can view and edit the rule configurations, including the basic settings, associated commands, and associated command sets.
- A modified database rule takes effect the instant its status changes to Enabled.
- If associated users have logged in to resources before the modification, those users need to log out and log in again for the modified rule to take effect.
- Log in to your bastion host system.
- In the navigation pane on the left, choose Policy > Cmd Rules > Cmd Rules to go to the command rule list page.
- View the rule list.
Table 1 Parameters for the command rule list Parameter
Description
Rule Name
Name of a command rule.
Status
Status of a command rule.
- Enabled: The rule has been enabled.
- Disabled: The rule has been disabled. To enable it, see Enabling or Disabling a Command Rule.
- Ineffective: The rule has not taken effect because the current time is earlier than the effective time configured for the rule. You can change its Period of validity to make it take effect.
- Expired: The rule has expired. You can change its Period of validity to make it take effect.
- Incomplete: The rule has not been associated with any command, command set, user, user group, resource account, or account group. For details, see Associating a Command Rule with a Command or Command Set, Associating a Command Rule with a User or User Group and Associating a Command Rule with a Resource Account or Account Group.
Action
Action of a rule.
- Disconnect: After the rule is triggered, the system rejects to execute the command and disconnects the operation session. The system displays a message indicating that the connection is forcibly disconnected by the administrator.
- Reject command: After the command rule is triggered, the system rejects executing the command and displays a message indicating that the command has been intercepted.
- Dynamic approval: After the rule is triggered, the system rejects executing the command. The system displays a message indicating that the command has been intercepted and asking you to submit a command approval ticket. A command approval ticket is automatically generated. The command can be executed only after the ticket is submitted and approved.
- Permit: When the rule is triggered, the system continues to execute the command. By default, all operations are allowed.
Command
Commands or command sets associated with the rule.
User
Users and user groups associated with the rule.
Account
Resource accounts and account groups associated with the rule.
Operation
Operations you can perform for the rule.
- Locate the row that contains the target rule, and click the rule name or Manage in the Operation column to go to the details page.
- View and edit basic rule information.
- In the Basic Info area, view basic rule information, such as the department and status.
- In the Basic Info area, click Edit on the right. In the displayed dialog box, modify the Rule Name, Action, Period of validity, and Time Limit settings of the rule. For details about the parameters, see Table 1.
- View and edit commands or command sets associated with the rule.
- In the Command and Command Set areas, view the commands or command sets associated with the rule.
- In the Command or Command Set area, click Edit on the right. In the displayed dialog box, add a command or command set to be associated with the rule.
- In the row containing the target command or command set, click Remove to delete the associated command or command set.
- View and edit users or user groups associated with the rule.
- In the User and UserGroup areas, view the users or user groups associated with the rule.
- In the User or User Group area, click Edit on the right. In the displayed dialog box, associate users or user groups with the rule.
- In the list, locate the row that contains the target user or user group, and click Remove to delete the associated user or user group and cancel the authorization.
- View and edit resource accounts and account groups associated with the rule.
- In the Account and AccountGroup areas, view the resource accounts or account groups associated with the rule.
- In the Account or Account Group area, click Edit on the right. In the displayed configuration window, add a resource account or account group to be associated.
- To remove a resource account or account group, click Remove in the row of the resource account or account group.
Associating a Command Rule with a Command or Command Set
- Log in to your bastion host system.
- In the navigation pane on the left, choose Policy > Cmd Rules > Cmd Rules to go to the command rule list page.
- In the Operation column of the target rule, click Relate and select Command or CmdSet.
- In the displayed dialog box, associate the rule with a command or command set.
- Associating the rule with a command
Enter one or more commands in the text box. For details, see Format Description of Associated Custom Commands.
- Associating the rule with a command set
- You can associate a rule with multiple command sets at once. For details about how to create a command set, see Creating and Managing Command Sets.
- Select a command set: On the Relate Command Set tab, select a command set in the Selectable cmdset area and click
to move it to the Selected cmdset area. - Remove a command set: On the Relate Command Set tab, select a command set in the Selected cmdset area and click
to move it to the Selectable cmdset area.
- Select a command set: On the Relate Command Set tab, select a command set in the Selectable cmdset area and click
- After a command set is associated with a rule, commands added to the command set automatically inherit the permissions of that rule.
- You can associate a rule with multiple command sets at once. For details about how to create a command set, see Creating and Managing Command Sets.
- Associating the rule with a command
- Click OK.
Associating a Command Rule with a User or User Group
- Log in to your bastion host system.
- In the navigation pane on the left, choose Policy > Cmd Rules > Cmd Rules to go to the command rule list page.
- In the row containing the target rule, click Relate in the Operation column and select User or UserGroup.
- In the displayed dialog box, associate the rule with a user or user group. Make sure the associated users or users in the associated user groups have the permissions for the Cmd Tickets module. Otherwise, after they log in to the system, the Cmd Tickets module will be unavailable to them. This means they cannot submit tickets to obtain approval during operation. For details about the permissions of each role, see Role.
- You can associate a rule with multiple users or user groups at once.
- Select users or user groups: On the Relate User or Relate User Group tab, select users or user groups in the Selectable users or Selectable user groups box, and click
to move them to the Selected users or Selected user groups box. - Remove users or user groups: On the Relate User or Relate User Group tab, select users or user groups in the Selected users or Selected user groups box, and click
to move them back to the Selectable users or Selectable user groups box.
- Select users or user groups: On the Relate User or Relate User Group tab, select users or user groups in the Selectable users or Selectable user groups box, and click
- After a user group is associated with a rule, users automatically obtain the permissions of the rule the instant they are added to the user group.
- You can associate a rule with multiple users or user groups at once.
- Click OK.
Associating a Command Rule with a Resource Account or Account Group
- Log in to your bastion host system.
- In the navigation pane on the left, choose Policy > Cmd Rules > Cmd Rules to go to the command rule list page.
- In the Operation column of the target rule, click Relate and select Account or Account Group.
- In the displayed dialog box, associate the rule with a resource account or account group.
- You can associate a rule with multiple managed resource accounts or account groups at once.
- Select a resource account or account group: On the Relate Account or Relate Account Group tab, select the target resource account or account group in the Selectable accounts or Selectable account groups box, and click
to move it to the Selected accounts or Selected account groups box. - Remove a resource account or account group: On the Relate Account or Relate Account Group tab, select the target resource account or account group in the Selected accounts or Selected account groups box, and click
to remove it back to the Selectable accounts or Selectable account groups box.
- Select a resource account or account group: On the Relate Account or Relate Account Group tab, select the target resource account or account group in the Selectable accounts or Selectable account groups box, and click
- After an account group is associated with a rule, accounts automatically obtain the permissions of the rule the instant they are added to the account group.
- You can associate a rule with multiple managed resource accounts or account groups at once.
- Click OK.
Enabling or Disabling a Command Rule
- Log in to your bastion host system.
- In the navigation pane on the left, choose Policy > Cmd Rules > Cmd Rules to go to the command rule list page.
- Enable or disable a command rule.
- Enabling a rule
- In the rule list, select all the target rules and click Enable in the lower left corner.
- In the displayed dialog box, click OK.
- Disabling a rule
- In the rule list, select all the target rules and click Disable in the lower left corner.
- In the displayed dialog box, click OK.
- Enabling a rule
Deleting a Command Rule
- Log in to your bastion host system.
- In the navigation pane on the left, choose Policy > Cmd Rules > Cmd Rules to go to the command rule list page.
- Delete a command rule.
- Deleting a single rule
- In the row containing the target rule, click Delete in the Operation column.
- In the displayed dialog box, click OK.
- Batch deleting rules
- On the ACL rule list page, select all the target rules.
- Click Delete in the lower left corner.
- In the displayed dialog box, click OK.
- Deleting a single rule
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot