Socket filter White List hosts list limit

Document ID:  TEC1386234
Last Modified Date:  06/30/2017
{{active ? 'Hide' : 'Show'}} Technical Document Details

Products

  • CA Privileged Access Management

Releases

  • CA Privileged Access Management:Release:2.8
  • CA Privileged Access Management:Release:2.8.1
  • CA Privileged Access Management:Release:2.8.2

Components

  • PRIVILEGED ACCESS MANAGEMENT:CAPAMX
Question:

We are building socket filter lists to allow PAM users access to a limited number of remote hosts after logging on to a target device with a Socket Filter Agent (SFA) installed. The remote hosts are not grouped by IP and we may have to add many specific entries in the hosts list for some socket filter lists. Is there a limit on how many host entries can be added, and if so, what is the limit?

Answer:

There is no limit when defining or importing socket filter lists, and there is no limit for Windows SFAs. However, UNIX/Linux SFAs have a limit of 4096 entries and will drop and not enforce any list exceeding this limit. The limit should be more than sufficient. If access to a very large number of hosts is to be allowed, it should be possible to define netmasks to allow access to ranges of IPs and keep the length of the list much shorter than the number of devices to which access is allowed. This information is accurate as of CA PAM 2.8 and may change in future releases.

Please help us improve!

Will this information enable you to resolve your issue?

Please tell us what we can do better.

{{feedbackText.length ? feedbackText.length : '0'}}/255

{{status}}

Not what you were looking for?

Search Again >

Product Information

Support by Product >

Communities

Join a Community >

Chat with CA

Just give us some brief information and we'll connect you to the right CA ExpertCA sales representative.

Our hours of availability are 8AM - 5PM CST.

All Fields Required

connecting

We're matching your request.

Unfortunately, we can't connect you to an agent. If you are not automatically redirected please click here.

  • {{message.agentProfile.name}} will be helping you today.

    View Profile


  • Transfered to {{message.agentProfile.name}}

    {{message.agentProfile.name}} joined the conversation

    {{message.agentProfile.name}} left the conversation

  • Your chat with {{$storage.chatSession.messages[$index - 1].agentProfile.name}} has ended.
    Thank you for your interest in CA.


    Rate Your Chat Experience.

    {{chat.statusMsg}}

agent is typing