Command Limiting Policies Overview
You can use Command Limiting Policies to prevent specific IP addresses or users from executing certain commands on an SFTP or FTP server. This is useful in situations where you want to prevent read/write access to your FTP/SFTP servers.
-
Which protocol the policy applies to: FTP or SFTP
-
IP addresses or users to be denied access to the specified commands
-
Commands to be blocked
-
Whether the policy applies to all instances of the adapter (protocol level) or only to adapter instances that you choose (instance level)
When planning command limiting policies, remember that all instances of the protocol (SFTP/FTP) are affected by the policy.
Define a Command Limiting Policy
To define a command limiting policy:
- From the Administration Menu, select Deployment > Adapter Utilities > Policy Configuration.
- Next to New Policy, click Go!
- Select Command Limiting Policy and click Next.
- Enter the Policy Name.
- Enter Description.
- Select the Policy Mode: IP Address or Range or User Based.
- Select the Protocol: FTP or SFTP.
- Select the Level at which this policy is applied: Protocol or Instance.
- Click Next.
- The next screen displayed depends on the Policy Mode you selected.
- If you selected User Based, select the users affected by this policy and click Next.
- If you selected IP Address or Range, enter the IP address or range and click Next.
-
Select the commands that users or IP addresses will NOT be able to execute on the specified servers and click Next. The commands displayed are dependant on the protocol you selected.
- Review the policy configuration.
- Click Finish to create the policy.
Disable a Command Limiting Policy
To disable a command limiting policy:
- From the Administration Menu, select Deployment > Adapter Utilities > Policy Configuration.
-
In the List panel, in By Policy Type, select Command Limiting Policy and click Go! A list of the command limiting policies are displayed.
- Clear the Enabled checkbox for the policy you want to disable.
Enable a Command Limiting Policy
To enable a command limiting policy that has been disabled:
- From the Administration Menu, select Deployment > Adapter Utilities > Policy Configuration.
-
In the List panel, in By Policy Type, select Command Limiting Policy and click Go! A list of the command limiting policies are displayed.
- Check Enabled for the policy you want to enable.
Edit a Command Limiting Policy
To edit a command limiting policy:
- From the Administration Menu, select Deployment > Adapter Utilities > Policy Configuration.
-
In the List panel, in By Policy Type, select Command Limiting Policy and click Go! A list of the command limiting policies are displayed.
- Select Edit for the command limiting policy you want to enable.
- Review and update as required.
- Review the updates.
- Click Finish to update the policy.
Delete a Command Limiting Policy
Before you can delete a command limiting policy, you must disable it.
To delete a command limiting policy:
- From the Administration Menu, select Deployment > Adapter Utilities > Policy Configuration.
-
In the List panel, in By Policy Type, select Command Limiting Policy and click Go! A list of the command limiting policies are displayed.
- If the policy you want to delete is enabled, clear the Enabled checkbox.
- Select Delete for the policy you want to delete.
- Review and confirm that you want to delete the policy, as the action can not be reversed.
- Click Delete.