<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkfailover with Readonly User in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Checkfailover-with-Readonly-User/m-p/139261#M27161</link>
    <description>&lt;P&gt;Thanks.. i got certain things to work here.. created a role and added few view commands to it such as ntp, configuration, dns , aaa servers. However , 2 things i cudnt work out.&lt;/P&gt;&lt;P&gt;1) Virtual system access&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) show cluster state in this custom monitor role&lt;/P&gt;&lt;P&gt;regarding virtual system access i am able to run set virtual-system 2 .. but post that i cannot run any command it keeps throwing this error :&amp;nbsp;supsh0361 failure setting current vrf id&lt;/P&gt;&lt;P&gt;as for the &amp;gt; show cluster state i get this error :&amp;nbsp;&lt;SPAN&gt;/bin/cphaprob_start line 6 permission denied&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;if i can somehow get these things to work it will be very helpful.&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jan 2022 13:24:30 GMT</pubDate>
    <dc:creator>LostBoY</dc:creator>
    <dc:date>2022-01-24T13:24:30Z</dc:date>
    <item>
      <title>Re: Checkfailover with Readonly User</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Checkfailover-with-Readonly-User/m-p/139227#M27158</link>
      <description>&lt;P&gt;you can create a new role based on MonitorOnly and add additional commands you want those users to run&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 07:34:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Checkfailover-with-Readonly-User/m-p/139227#M27158</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-01-24T07:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: Checkfailover with Readonly User</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Checkfailover-with-Readonly-User/m-p/139254#M27159</link>
      <description>&lt;P&gt;is it possible to clone monitorOnly and add additonal features ? i was looking at monitorOnly rba role and it mentions access to cluster info but when i run it i get an error /bin/cphaprob_start line 6 permission denied&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 12:14:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Checkfailover-with-Readonly-User/m-p/139254#M27159</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2022-01-24T12:14:46Z</dc:date>
    </item>
    <item>
      <title>Re: Checkfailover with Readonly User</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Checkfailover-with-Readonly-User/m-p/139259#M27160</link>
      <description>&lt;P&gt;Role management is described in the &lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Gaia_AdminGuide/Topics-GAG/Roles.htm?tocpath=User%20Management%7CRoles%7C_____0" target="_self"&gt;Gaia Admin guide&lt;/A&gt;. You can create custom roles with certain additional commands for your needs&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 12:34:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Checkfailover-with-Readonly-User/m-p/139259#M27160</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-01-24T12:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: Checkfailover with Readonly User</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Checkfailover-with-Readonly-User/m-p/139261#M27161</link>
      <description>&lt;P&gt;Thanks.. i got certain things to work here.. created a role and added few view commands to it such as ntp, configuration, dns , aaa servers. However , 2 things i cudnt work out.&lt;/P&gt;&lt;P&gt;1) Virtual system access&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) show cluster state in this custom monitor role&lt;/P&gt;&lt;P&gt;regarding virtual system access i am able to run set virtual-system 2 .. but post that i cannot run any command it keeps throwing this error :&amp;nbsp;supsh0361 failure setting current vrf id&lt;/P&gt;&lt;P&gt;as for the &amp;gt; show cluster state i get this error :&amp;nbsp;&lt;SPAN&gt;/bin/cphaprob_start line 6 permission denied&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;if i can somehow get these things to work it will be very helpful.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 13:24:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Checkfailover-with-Readonly-User/m-p/139261#M27161</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2022-01-24T13:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: Checkfailover with Readonly User</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Checkfailover-with-Readonly-User/m-p/139297#M27162</link>
      <description>&lt;P&gt;Check default shell for that account. Some commands will not work from clish and require bash&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 16:29:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Checkfailover-with-Readonly-User/m-p/139297#M27162</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-01-24T16:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: Checkfailover with Readonly User</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Checkfailover-with-Readonly-User/m-p/139298#M27163</link>
      <description>&lt;P&gt;But from adminRole users i can run show cluster state fron GAIA shell itself.. however its not working with custom roles&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 16:35:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Checkfailover-with-Readonly-User/m-p/139298#M27163</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2022-01-24T16:35:26Z</dc:date>
    </item>
  </channel>
</rss>

