20 - FPolicy - Policies

Information

Access control is a key security concept. Indeed, visibility and the ability to respond to file access and file operations are critical for maintaining your security posture. To provide visibility and access control for files, the ONTAP solution uses the FPolicy feature. FPolicy is an infrastructure component of the ONTAP solution that allows partner applications to monitor and set file access permissions.

File policies can be set based on file type. FPolicy determines how the storage system handles requests from individual client systems for operations such as create, open, rename, and delete. Beginning with ONTAP 9, the FPolicy file access notification framework is enhanced with filtering controls and resiliency against short network outages.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

To leverage the FPolicy feature, the FPolicy policy must first be created with the vserver fpolicy policy create command. In addition, use the -events parameter if FPolicy is used for visibility and the collection of events. The additional granularity provided by ONTAP enables filtering and access down to the user name level of control. To control privileges and access with user names, specify the - privilege-user-name parameter. The following text provides an example of FPolicy creation:

cluster1::> vserver fpolicy policy create -vserver vs1.example.com -policy-name vs1_pol -events cserver_evt,v1e1 -engine native -is-mandatory true -allow-privileged-access no -ispassthrough-read-enabled false

After the FPolicy policy is created, it must be enabled with the vserver fpolicy enable command. This command also sets the priority or sequence of the FPolicy entry. The FPolicy sequence is important because, if multiple policies have subscribed to the same file access event, the sequence dictates the order in which access is granted or denied. The following text provides a sample configuration for enabling the FPolicy policy and validating the configuration with the vserver fpolicy show command:

cluster1::> vserver fpolicy enable -vserver vs2.example.com -policy-name vs2_pol -sequence-number 5
cluster1::> vserver fpolicy show
Vserver Policy Name Sequence Status Engine
----------------------- ------------------------------ -------- ------- -------
vs1.example.com vs1_pol
vs2.example.com vs2_pol
external
2 entries were displayed.

See Also

https://www.netapp.com/us/media/tr-4569.pdf