Access Policies ใน Zero Trust Security (ZTNA) ของ Sangfor Athena SASE ใช้ตรวจผู้ใช้และเครื่องตลอดช่วงที่ผู้ใช้ Login อยู่ ตั้งแต่ Log in จนถึง Log out เมื่อเงื่อนไขของ Policy เป็นจริง ระบบจะ Log out ผู้ใช้ หรือบันทึก Log โดยไม่แจ้งผู้ใช้ เหมาะกับกฎเรื่องเครื่องที่ใช้ทั้งองค์กร เช่น อนุญาตให้ Login ได้เฉพาะเครื่องที่ Join Domain ขององค์กร บทความนี้อธิบายโครงสร้างของ Policy เงื่อนไขที่เลือกได้ ตัวอย่างการตั้งค่า และการตรวจผลจาก Log ค่าในภาพเป็นค่าตัวอย่าง ให้เปลี่ยนเป็นค่าขององค์กร
สารบัญ
Access Policy กับ App Protection Policy
ทั้งสองแบบอยู่ที่ Core Features › Zero Trust Security › Policies › Security Policies และมีโครงฟอร์มเดียวกัน คือ Basics, Applicable Scope, Conditions, Exceptions และ Action
| หัวข้อ | Access Policies | App Protection Policies |
|---|---|---|
| ขอบเขต | ผู้ใช้หรือ Department ตลอดช่วงที่ Login | ผู้ใช้กับ App ที่กำหนด |
| Action | Log out หรือ Record log without notifying user | Block Access Only (Block เฉพาะ App นั้น) หรือ Log out |
| เลข Policy | ขึ้นต้นด้วย L (เช่น L000001) | ขึ้นต้นด้วย P (เช่น P000001) |
| เหมาะกับ | กฎเรื่องเครื่องที่ใช้ทั้งองค์กร | กฎที่เข้มกว่าสำหรับระบบสำคัญ โดยกระทบผู้ใช้น้อยกว่า |
Security Policy ทำหน้าที่ควบคุมเพิ่มเติม ส่วนสิทธิ์ในการเข้าถึง App ยังมาจาก App Authorization เสมอ
ตัวอย่าง: Login ได้เฉพาะเครื่องที่ Join Domain
ไปที่
Core Features › Zero Trust Security › Policies › Security Policiesแท็บ Access Policies แล้วกด Add Access Policy (หรือ Add)Basics: กรอก Policy Name และ Description (ไม่บังคับ) ฟอร์มใหม่ตั้ง Status เป็น Enable ไว้แล้ว
-
Applicable Scope: กด New เลือกผู้ใช้รายคน หรือเลือกทั้ง Department จากแผนผัง แล้วกด OK แนะนำให้เริ่มจากผู้ใช้ทดสอบก่อน
Conditions: Type เลือก OS-specific (ตั้งเงื่อนไขแยกตาม OS) หรือ General (เงื่อนไขเดียวสำหรับทุก OS) ฟอร์มใหม่เลือก OS-specific และติ๊ก Windows ไว้ OS ที่ไม่ได้ติ๊กจะเข้าใช้งานได้โดยตรง จึงควรติ๊กทุก OS ที่ต้องการควบคุม
-
กด Add Condition หน้าต่าง Select Trigger Condition มีกลุ่ม Endpoint Info, User Info และ Predefined Variables ค้นหา
domainแล้วเลือก Name of the domain joined by endpoints ตั้งตัวดำเนินการเป็น==และกรอกชื่อ Domain ขององค์กร -
Response Method เลือก Allow login (เมื่อไม่ Match เงื่อนไข ระบบทำตาม Action) ส่วน Take action ใช้กับเงื่อนไขแบบกลับด้าน (เมื่อ Match เงื่อนไข ระบบทำตาม Action)
Action: เลือก Log out (ฟอร์มใหม่เลือกไว้แล้ว) หรือ Record log without notifying user เมื่อเลือก Log out ให้เลือก Endpoint Prompt ซึ่งมี 8 แบบ ได้แก่ Custom, Multi-Condition Login Restriction, Require Login from LAN Only, Require Installation of Specified Software, Require Installation of Specified Antivirus Software, Require Updating Antivirus Database, Require Specified Browser และ Require Login from Endpoint Joined to Domain ข้อความจะเปลี่ยนตาม Template ที่เลือก
-
แก้ข้อความให้ผู้ใช้รู้ว่าต้องทำอะไร และเปลี่ยนเบอร์โทรตัวอย่างในข้อความเป็นช่องทางติดต่อทีม IT ขององค์กร ดูผลที่ Preview ด้านขวา แล้วกด OK
-
ระบบสร้าง Policy หมายเลข L000001 (ลำดับถัดไปตามจำนวน Policy) รายการแสดง Policy Number, Policy Name, Applicable Users, Applicable System, Action และ Status
แนะนำ: ก่อนบังคับใช้จริง ให้ตั้ง Action เป็น Record log without notifying user ก่อน ผู้ใช้จะใช้งานได้ตามปกติ แต่ระบบบันทึกเครื่องที่ไม่ผ่านเงื่อนไขไว้ใน Log ตรวจจนมั่นใจแล้วจึงเปลี่ยนเป็น Log out
เงื่อนไขที่เลือกได้
เงื่อนไขหลายข้อรวมกันด้วย AND หรือ OR และจัดเป็นกลุ่มได้ด้วย Add Condition Group รายการเงื่อนไขขึ้นกับ OS ที่เลือก ตัวอย่างที่ใช้บ่อย
| กลุ่ม | เงื่อนไข |
|---|---|
| Endpoint Info (ข้อมูลเครื่อง) | Host name, List of endpoint MAC addresses, List of endpoint local IP addresses, Name of the domain joined by endpoints, Version of endpoint OS, CPU architecture, Asset type, Service packs installed on Windows, Existence of specified file, Specify Process (Process ที่ต้องรันอยู่), Run specified antivirus software, Run any antivirus software, Enable system firewall, Latest version of antivirus software, Install specified software และ Omnipoint Secure Client version |
| User Info (ข้อมูลผู้ใช้) | Location where the user is connected, Country where the user is located (ตัวดำเนินการ IN / NOT IN เลือกได้หลายประเทศ) และ Time when the user logs in |
| Predefined Variables (ระบบคำนวณให้) | Login จากสถานที่ครั้งแรก (ระบบเก็บสถานที่ Login ย้อนหลัง 10 แห่ง), Login จากสถานที่ใหม่, Login จากสถานที่ที่ไม่ค่อยใช้ (Login น้อยกว่า 5 วันใน 30 วัน), First-time login, First-time login on one endpoint, Login on trusted endpoint และช่วงเวลา Login ที่ผิดปกติ |
ตัวดำเนินการขึ้นกับเงื่อนไข เช่น Name of the domain joined by endpoints ใช้ได้ทั้ง ==, !=, IN และ NOT IN ส่วนเงื่อนไขแบบจริง/เท็จ เช่น Enable system firewall ใช้ == กับ True หรือ False
Exceptions: การผ่อนผัน
ติ๊ก Exceptions เพื่อผ่อนผันผู้ใช้บางคนให้ผ่านได้ด้วยมาตรการเพิ่มเติมในช่วงเวลาที่กำหนด ฟังก์ชันนี้ใช้กับ Client บน PC
- Time Period: Not specified, Before หรือ Specified
- Applicable Users: All, Specified หรือ Excluded
- Remedial Measure: Enhanced Authentication ด้วย TOTP Token (ผู้ใช้ต้องตั้ง TOTP ไว้แล้ว ดูการตั้งค่า MFA) หรือ Warning ให้ผู้ใช้รับทราบคำเตือนก่อนดำเนินการต่อ (แก้ข้อความได้ที่ Settings)
- Exception Validity: Till the session ends หรือ Specified Period
สิ่งที่ผู้ใช้เห็น
- ผู้ใช้ที่ออนไลน์อยู่ตอนบันทึก Policy จะถูกตรวจทันที หากไม่ผ่านเงื่อนไข ภายในไม่กี่วินาที Client แจ้งว่า Account ถูก Log out เพราะ Match เงื่อนไขของ Security Policy
- เมื่อ Login จากเครื่องที่ไม่ผ่าน ระบบแสดงหน้าข้อความระบุ Violated Policy พร้อมหมายเลข Policy ข้อความตาม Template ที่เลือก และปุ่ม Relogin แล้ว Log out ผู้ใช้
- Action แบบ Record log ผู้ใช้ใช้งานได้ตามปกติ และระบบบันทึกเหตุการณ์ไว้ให้ตรวจสอบ
ตรวจผลจาก Log และการเปิดปิด Policy
-
ไปที่
Logs › Critical Feature Logs › ZTNA Logsแท็บ User Logs กรองด้วย User/Department แล้วดูคอลัมน์ Operation Subtype และ Result- ACL logout – ผู้ใช้ที่ออนไลน์อยู่ถูก Log out ตาม Policy
- User login blocking by ACL – การ Login ถูก Block
- Security event log recorded by ACL – บันทึกเมื่อใช้ Action แบบ Record log
- ACL verification passed – ผ่านการตรวจ
-
กด Details ของแถว ช่อง Cause บอกชื่อ Policy ที่ทำให้เกิดบันทึกนั้น
ประวัติ Login/Logout ดูได้ที่
Logs › User Access › Login/Logoutแท็บ Client Users คอลัมน์ Operation แสดง ACL Logout สำหรับการ Log out จาก Access Policyเปิดหรือปิด Policy ได้จากคอลัมน์ Status ในรายการ (Enabled / Disabled) หรือใช้ปุ่ม Enable / Disable เมื่อเลือกหลาย Policy
ข้อคิดเห็น
0 ข้อคิดเห็น
โปรด ลงชื่อเข้าใช้ เพื่อแสดงข้อคิดเห็น