You are on page 1of 92

WALLIX CERTIFIED ADMINISTRATOR

WCA

SESSION MANAGER
WALLIX products : WALLIX PAM Bastion features

• Single Sign-On
• Access policies
Session • Session recording
• Pattern detection
Audit-Risk Manager
Compliance

APPLIANCES
PASSWORD WAB
LINUX/UNIX SERVERS
Privileged
Users SESSION Cloud
MANAGER Availability
Access VAULT APPLICATIONS
WINDOWS SERVERS
Manager WEB CONSOLES
Third
parties

SIEM
• Access policies Logs management

Password • Extensible change management


• Generation complexity
Manager • Check-out/check-in workflow
• Password Visualization
© Copyright WALLIX 2
Demo 1-Session
Manager
How does
it work ?
Basic Configuration Gui
Global concepts

Which account can Bastion Target device


be used to connect Primary connection Secondary connection
to the device ?
RDP, SSH,HTTPS RDP, SSH, VNC, RAWTCPIP
TELNET, RLOGIN

User/primary account Secondary/Target account


Accounts

User/primary account
Accounts
mappings

Interactive User/primary
accounts accounts
Interactive
login

© Copyright WALLIX 7
Interactive login

Account mapping Account

© Copyright WALLIX 8
Global concepts

Authorization

Primary accounts group Target target group

Accounts Accounts mappings

SSH, TELNET
Primary Vmware
SSH
accounts client

• Protocols and subprotocols allowed (RDP,


RDP_CLIPBOARD_DOWN, SSH, etc..) Scenario Accounts Interactive login
• Session recording
• Approval workflow SSH, TELNET
RDP

FTP
SSH startup scenario
client

© Copyright WALLIX 9
Global concepts

▪ Steps:
1. Add a user/primary account

2. Add a user/primary account group

3. Add target device

4. Add secondary/target account (Not Mandatory)

5. Add target group

6. Add authorization

© Copyright WALLIX 10
QUESTIONS?
MANAGE USER/PRIMARY ACCOUNT WITH
LOCAL AUTHENTICATION
Global concepts

▪ Steps:
1. Add a user/primary account

2. Add a user/primary account group

3. Add target device

4. Add secondary/target account (Not Mandatory)

5. Add target group

6. Add authorization

© Copyright WALLIX 13
Types of user/primary account group

Primary/user account Group

Local users with external


Local users
authentication
Manager user/primary account group

▪ Add a local account

© Copyright WALLIX 15
Manage a user/primary account group

▪ Add a local account with a local authentication

© Copyright WALLIX 16
Manage a user/primary account group

▪ Add a local account with an external authentication

© Copyright WALLIX 17
Manage a user/primary account group

▪ Delete user/primary accounts

Delete

© Copyright WALLIX 18
QUESTIONS?
MANAGE PRIMARY USER GROUP
Global concepts

▪ Steps:
1. Add a user/primary account

2. Add a user/primary account group

3. Add target device

4. Add secondary/target account (Not Mandatory)

5. Add target group

6. Add authorization

© Copyright WALLIX 21
Manage a user/primary account group

▪ Add a user/primary
account group

© Copyright WALLIX 22
Manage a user/primary account group

▪ Rule examples (regular expressions)

rm\s+.* (detect files deleting)


$filesize:>10m (transfer files bigger that 10M)
$downsize:>100m (download files bigger than 100M)
$acmd:[en:able, sh:ow kerb:eros, access-t:emplate, conf:igure t:erminal] (cisco commands)

© Copyright WALLIX 23
Manage a user/primary account group

Delete a group

© Copyright WALLIX 24
Manage a user/primary account group

Create a time frame


for a user group

© Copyright WALLIX 25
QUESTIONS?
MANAGE DEVICES
Global concepts

▪ Steps:
1. Add a user/primary account

2. Add a user/primary account group

3. Add target device

4. Add secondary/target account (Not Mandatory)

5. Add target group

6. Add authorization

© Copyright WALLIX 28
Manage a device

▪ Add an RDP device

© Copyright WALLIX 29
Manage a device

▪ Add an SSH device

© Copyright WALLIX 30
Manage a device

▪ Delete devices

Delete a
device

© Copyright WALLIX 31
QUESTIONS?
MANAGE SECONDARY/TARGET ACCOUNT :
Global concepts

▪ Steps:
1. Add a user/primary account

2. Add a user/primary account group

3. Add target device

4. Add secondary/target account (Not Mandatory)

5. Add target group

6. Add authorization

© Copyright WALLIX 34
TYPES OF SECONDARY/TARGET ACCOUNT

Device account

• Linked to a device

Application account

• Linked to an Application
Local domains

Device1
Application1

Device1-LocalDomain1
Application1-LocalDomain1

Device1-LocalDomain2
Application1-LocalDomain2

Device1-LocalDomain3

Why ?
• Every local domain can have a different password change policy
© Copyright WALLIX 36
ADD SECONDARY/TARGET ACCOUNT - DEVICE ACCOUNT

Menus from which secondary/target account can be added

© Copyright WALLIX 37
Manage a secondary account

Add secondary/target account –


Device account

© Copyright WALLIX 38
Manage a secondary account

Manage secondary/target account – Device account

© Copyright WALLIX 39
QUESTIONS?
ADD target GROUP
Global concepts

▪ Steps:
1. Add a user/primary account

2. Add a user/primary account group

3. Add target device

4. Add secondary/target account (Not Mandatory)

5. Add target group

6. Add authorization

© Copyright WALLIX 42
Manage a target group

Add a target group

© Copyright WALLIX 43
Manage a target group

Account

userbastion1 RDP: adminwindows1


SSH: adminlinux1

Account mapping

userbastion1 RDP & SSH: userbastion1

Interactive login

userbastion1
RDP: adminwindows1
SSH: adminlinux1

© Copyright WALLIX 44
QUESTIONS?
MANAGE AN AUTHORIZATION
Global concepts

▪ Steps:
1. Add a user/primary account

2. Add a user/primary account group

3. Add target device

4. Add secondary/target account (Not Mandatory)

5. Add target group

6. Add authorization

© Copyright WALLIX 47
Manage an authorization

Add an authorization

© Copyright WALLIX 48
Manage an authorization

Start/stop session
recording

Authorize/deny password
checkout

Start/stop approval
workflow

© Copyright WALLIX 49
Manage an authorization

Manage authorizations

Delete a group

© Copyright WALLIX 50
Global concepts

▪ Steps:
1. Add a user/primary account

2. Add a user/primary account group

3. Add target device

4. Add secondary/target account (Not Mandatory)

5. Add target group

6. Add authorization

© Copyright WALLIX 51
QUESTIONS?
MANAGE A CHECKOUT POLICY
Demo 2- Check Out Policy
with lock
QUESTIONS?
Global concepts

▪ Check-out Policy on the target account


User/primary Secondary/Target
account account
Primary user 1
Check-out Policy
Without Lock Primary user 2

User/primary Secondary/Target
account account
Primary user 1
Check-out Policy
With Lock
Primary user 2

© Copyright WALLIX 57
Manage a secondary account

Add a check-out Policy

© Copyright WALLIX 58
MANAGE APPLICATION
Global concept

Goals
• Give an access only to an application instead of an
entire session
What's an Application
• A webapp (i.e a browser)
• A think app
QUESTIONS?
Demo 3- Check Application
Manage applications
Bastion Target application
Which account can
Secondary connection
be used to Primary connection

authenticate on the RDP


RDP
application ? Authentication

User/primary account Secondary/Target accounts


Accounts

Accounts mappings User/primary account

Interactive User/primary
Interactive login accounts accounts

© Copyright WALLIX 64
Manage applications
Prerequisites:

Enable RDS (Remote Desktop Services) on


the Windows server

Allow the user who opens the RDP session


on the server accessing to the collection

IF Session Probe is enabled :


Publish only cmd.exe and allow all command-line parameters

ELSE :
Publish the application in the collection

© Copyright WALLIX 65
QUESTIONS?
Global concepts

▪ Steps:

1. Add an Application

2. Add secondary/target application account (Not Mandatory)

3. Add the target on a target group

© Copyright WALLIX 67
Global concepts

▪ Steps:

1. Add an Application

2. Add secondary/target application account (Not Mandatory)

3. Add the target on a target group

© Copyright WALLIX 68
Manage applications

Add an application not requiring an account or with an interactive account.

© Copyright WALLIX 69
Manage applications
Add an application requiring an account

© Copyright WALLIX 70
Global concepts

▪ Steps:

1. Add an Application

2. Add secondary/target application account (Not Mandatory)

3. Add the target on a target group

© Copyright WALLIX 71
Manage applications

Add an application secondary/target account

© Copyright WALLIX 72
Manage applications

Add an application secondary/target account

© Copyright WALLIX 73
Global concepts

▪ Steps:

1. Add an Application

2. Add secondary/target application account (Not Mandatory)

3. Add the target on a target group

© Copyright WALLIX 74
Manage applications

▪ Add an application not requiring an account or with an interactive account

© Copyright WALLIX 75
Manage applications

Add an application
requiring an account

userbastion1 wca_user

userbastion1 userbastion1

© Copyright WALLIX 76
Manage applications

Connection to the application from Bastion GUI

© Copyright WALLIX 77
Global concepts

▪ Steps:

1. Add an Application

2. Add secondary/target application account (Not Mandatory)

3. Add the target on a target group

© Copyright WALLIX 78
QUESTIONS?
Annexes
CONNECTING TO A SERVER USING RDP
Connecting to a server using RDP

▪ Connecting to a server using RDP (Remote Desktop Protocol)

© Copyright WALLIX 81
Connecting to a server using RDP

▪ Connecting to a server using RDP (Remote Desktop Protocol)

© Copyright WALLIX 82
Connecting to a server using RDP

▪ Account

© Copyright WALLIX 83
Connecting to a server using RDP

▪ Account mapping

© Copyright WALLIX 84
Connecting to a server using RDP

▪ Interactive

© Copyright WALLIX 85
Connecting to a server using RDP

Connecting to a server using RDP from Bastion GUI

© Copyright WALLIX 86
Connecting to a server using RDP

Connecting to a server using RDP from Bastion GUI

OTP: One-Time Password

© Copyright WALLIX 87
CONNECTING TO AN SSH SERVER
Connecting to a server using SSH

▪ Connecting to an SSH server using Putty

© Copyright WALLIX 89
Connecting to a server using SSH

Interactive

Account

Account
mapping

© Copyright WALLIX 90
Connecting to a server using SSH

© Copyright WALLIX 91
Connecting to a server using SSH

Download and install WALLIX puTTY

© Copyright WALLIX 92
CONNECTING TO AN APPLICATION
Connecting To Application

▪ Connection to the application from Bastion GUI

© Copyright WALLIX 94
Connecting To Application

▪ Connection to the application using RDP client

© Copyright WALLIX 95

You might also like