Access Control Target

Prev Next

Available in VPC

In Access Control Target, you can create and manage server or DB targets to control user access. When a target is created, a relay session for the corresponding resource is established inside the proxy server to control user access and record access history.

Access Control Target interface

The following is a basic description of how to use Access Control Target:

dsac-accesscontroltarget_01_en

Component Description
① Menu name Current menu name.
② Basic features Basic features provided by the DB & Server Access Control service.
  • [Create Server Target]: Create a server target to control user access.
  • [Create DB Target]: Create a DB target to control user access.
  • [Learn more]: View service details.
  • [Refresh]: Update the screen with the latest information.
③ Access Control Target features Features provided on the Access Control Target interface
  • [Target settings]: Change the access port and memos of access control targets.
  • [Logging and Masking settings]: Change the logging scope and privacy masking settings of targets.
  • [Delete target]: Delete targets.
  • [Server Target usage range settings]: Set the server target creation limit (usage range).
④ Search and quantity information Search the target list and check server target quantity information.
  • Search: You can search for a target by entering its name.
  • Target type: Filter the list by All, Server, or DB.
  • Server Target: Display the set server target usage range and current usage quantity.
⑤ Target list Check the list of targets being relayed by the proxy server and their details.
  • Target name: The name specified when the target was created.
  • Target type: The target's type.
    • Server | Cloud DB | DBMS Server
  • Resource type: Resource type linked as the access control target.
    • Server: Operating system information.
    • DB: DB engine version information.
  • Resource server name: Name of the resource linked as the access control target.
  • Access Port: Port number accessible for the access control target resource.
  • Logging scope: Request or Request & Response.
  • Resource status: Access control target resource status.
  • VPC: VPC to which the access control target resource belongs.
  • Subnet: Subnet to which the access control target resource belongs.
  • Private domain (IP): Private domain or private IP of the access control target resource.

Server Target usage range settings

Server targets can be created up to a predefined usage range (quantity), so set the usage range first before creating any server targets. Since usage fees are charged based on the quantity set, you must calculate an appropriate quantity before setting it. To configure the settings, follow these steps:

  1. In the NAVER Cloud Platform console's VPC environment, navigate to Menu > All Services > Security > DB & Server Access Control > Access Control Target.
  2. Click [Server Target usage range settings].
  3. When the Server Target usage range settings popup appears, input the required information.
    • Server Target management name: Enter during initial setup.
    • Current Server Target usage range: Set server target quantity.
    • Server Targets currently in use: The number of server targets currently in use.
    • Server Target usage: Server target usage status.
    • Server Target usage range definition: Server target quantity you want to set.
  4. Click [Configure].
  5. When the pricing information popup appears, check the contents and click [OK].
Caution

Note the following things when setting the server target usage range:

  • Billing for the server target usage range begins from the time the range is set.
  • You cannot change the usage range to be lower than the number of server targets currently in use.

Create a Server Target

You can create a server that is remotely accessed via SSH as an access control target. To create a server target:

  1. In the NAVER Cloud Platform console's VPC environment, navigate to Menu > All Services > Security > DB & Server Access Control > Access Control Target.
  2. Click [Create Server Target].
    • If you have not set the server target usage range, a popup prompting you to do so will appear.
  3. When Server Target settings appears, enter the information and click [Next].
    • Target name: Names may contain Korean characters, lowercase English letters, numbers, and the special character "-", and may be between 3 and 30 characters long.
    • Target type: Server (fixed value).
    • Resource server name: Click to select the Linux server in the VPC environment to set as the access control target.
    • Resource type: Resource server's operating system information.
    • Access Port (SSH only): Enter the accessible port number for the access control target resource between 1 and 65535.
      • For task history logging, only SSH (default value: 22) is supported.
      • If a different port is being used for security reasons, enter the set SSH port number.
    • Memo: Enter a description of the access control target that is less than 1,000 bytes.
  4. When Logging and Masking settings appears, set the logging scope and whether to mask personal information, the click [Next].
    • Logging scope: Select the record scope of the access control history.
      • Request: Log access times, access users, access IP addresses, queries, and commands.
      • Request & Response: Log access times, access users, access IP addresses, queries, commands, and result values.
    • Personal information masking: Select whether to mask personal information when logging result values.
      • Disable personal information masking: Do not mask personal information when logging result values.
      • Enable personal information masking: Mask personal information when logging result values.
        • Personal information masking targets: Select targets for masking.
        • Select user-defined masking: Select a pattern entered directly by the user and click [Add].
  5. Check items regarding personal information masking measures, and click [Next].
  6. When the final confirmation appears, check the details and then click [Create target].
Note

Connections that do not go through a proxy server do not remain in the access records. Therefore, configure the ACG rules of the server registered as the target to disallow remote connections other than the proxy server ACG.

Create a DB Target

You can create a database (DBMS Server) configured as a server image, either by installing it directly on a Cloud DB or a standard server, as an access control target. You can create up to 30 targets; if you need to create more, you must make a separate request through a service inquiry. To create a DB target:

  1. In the NAVER Cloud Platform console's VPC environment, navigate to Menu > All Services > Security > DB & Server Access Control > Access Control Target.
  2. Click [Create DB Target].
  3. When DB Target settings appears, enter the information and click [Next].
    • Target name: Names may contain Korean characters, lowercase English letters, numbers, and the special character "-", and may be between 3 and 30 characters long.
    • Target type: Choose between Cloud DB and DBMS Server.
    • Resource server name: Click to select the server in the VPC environment to set as the access control target.
      • Cloud DB: Displayed on Cloud DB list.
      • DBMS Server: Displayed on Server list.
    • Resource type: Resource server's information.
      • Cloud DB: Entered automatically.
      • DBMS Server: Select DBMS type.
    • Access Port: Port number accessible for the access control target resource.
      • Cloud DB: Entered automatically.
      • DBMS Server: Enter between 1 and 65535.
    • Memo: Enter a description of the access control target that is less than 1,000 bytes.
  4. When Logging and Masking settings appears, set the logging scope and whether to mask personal information, the click [Next].
    • Logging scope: Select the record scope of the access control history.
      • Request: Log access times, access users, access IP addresses, queries, and commands.
      • Request & Response: Log access times, access users, access IP addresses, queries, commands, and result values.
    • Personal information masking: Select whether to mask personal information when logging result values.
      • Disable personal information masking: Do not mask personal information when logging result values.
      • Enable personal information masking: Mask personal information when logging result values.
        • Personal information masking targets: Select targets for masking.
        • Select user-defined masking: Select a pattern entered directly by the user and click [Add].
  5. Check items regarding personal information masking measures, and click [Next].
  6. When the final confirmation appears, check the details and then click [Create target].
Note

Connections that do not go through a proxy server do not remain in the access records. Therefore, configure the ACG rules of the DB registered as the target to disallow remote connections other than the proxy server ACG.

View Target

To view the details of a created Target:

  1. In the NAVER Cloud Platform console's VPC environment, navigate to Menu > All Services > Security > DB & Server Access Control > Access Control Target.
  2. Check the details.

Change Target

You can change the access port number or memos of access control targets. To change a Target:

  1. In the NAVER Cloud Platform console's VPC environment, navigate to Menu > All Services > Security > DB & Server Access Control > Access Control Target.
  2. Select the Target you want to change and click [Target settings].
  3. When the Target settings popup appears, modify the required information.
  4. Click [Edit].

Change logging and masking

To change the logging and masking settings of access control targets:

  1. In the NAVER Cloud Platform console's VPC environment, navigate to Menu > All Services > Security > DB & Server Access Control > Access Control Target.
  2. Select the Target you want to change and click [Logging and masking settings].
  3. When the Logging and masking settings popup appears, modify the required information.
  4. Click [Edit].

Delete a Target

To delete a Target:

  1. In the NAVER Cloud Platform console's VPC environment, navigate to Menu > All Services > Security > DB & Server Access Control > Access Control Target.
  2. Select the Target you want to delete and click [Delete Target].
  3. When the Delete Target popup appears, check the Target's name and the precautions, select the I have checked check box, and then click [Yes].
Caution

When a target is deleted, all sessions connected to that target are forcibly terminated.