IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Problem bloking SQL Queries when the collector is dow

    Posted 05/23/19 05:37 AM
    Hi,

    We have an issue with Guardium Data Activity Monitor, we set up an policy to block the DELETE sql query issued by a sepcific users, the policy
    works very well when the collector is UP.

    We want this policy to block these queries even when the collector is down, but when we set up the parameter "FIREWALL_FAIL_CLOSE=1" the policy did not
    work (The access to the server is blocked for all queries even authentication) and when we set up the parameter "FIREWALL_FAIL_CLOSE=0" the policy also fail (the DELETE sql request are executed
    from the non authorized users).

    Can you help us to prevent executing DELETE SQL query event when the collector is down?

    Thank's in advance.

    ------------------------------
    [Larbi] [Belmiloud]
    [Cyber Security]
    [Intervalle Technologies]
    [Algers] [Algeria]
    [+213551193200]
    ------------------------------


  • 2.  RE: Problem bloking SQL Queries when the collector is dow

    Posted 05/23/19 10:34 AM
    ​Larbi,

    I am assuming that you have FIREWALL_DEFAULT_STATE=1 based on how you are describing the firewall is reacting. Here is what I understand is happening:

    FIREWALL_FAIL_CLOSE=1 Since your default state is 1, the STAP is attempting to verify with the collector each time anything happens on that server. This means that when the collector is down and cannot give a verdict your STAP will block any activity on that server.

    FIREWALL_FAIL_CLOSE=0 The opposite of what I described in FAIL_CLOSE=1 is happening here. The STAP is trying to verify any activity on the database with the Collector. Since the collector cannot give a verdict the STAP allows all traffic.

    The only way I can think of getting your issue to resolve is to have a failover collector assigned in the STAP configuration. You may want to create an RFE for functionality to have the STAP make standalone verdicts on activity blocking, the Devs would be able to provide you more insight as to whether or not this is possible.

    ------------------------------
    Chase Walkup
    ------------------------------



  • 3.  RE: Problem bloking SQL Queries when the collector is dow

    Posted 05/28/19 04:16 AM
    Hi chase , 
    we asseked to develloper and there is no way to be implimented in this way, the only possibility is by using HA. 
    thanks for your help.

    ------------------------------
    [Larbi] [Belmiloud]
    [Cyber Security]
    [Intervalle Technologies]
    [Algers] [Algeria]
    [+213551193200]
    ------------------------------



  • 4.  RE: Problem bloking SQL Queries when the collector is dow

    Posted 05/24/19 05:05 AM
    Hi Larbi,
    this behavior is by design, there is no caching of the policy on S-TAP level. Since you do implement blocking, you have to provide high availability for the collector (meaning, installing another collector). It will be a good idea to add also a Central Manager if you don't have one.

    ------------------------------
    Sincerely,
    Alexey Saltovski
    Tech Department Manager
    Tangram-Soft LTD
    Israel

    IBM Champion
    ------------------------------