<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Define user with specific privileges in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Define-user-with-specific-privileges/m-p/49512#M3692</link>
    <description>&lt;P&gt;I was mistaken that Dynamic CLI is required. Instead,&amp;nbsp;you need to use a feature in Gaia called "User Defined (Extended) Commands" as described in the Gaia Admin Guide:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R80.20.M2/WebAdminGuides/EN/CP_R80.20_M2_Gaia_AdminGuide/html_frameset.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.20.M2/WebAdminGuides/EN/CP_R80.20_M2_Gaia_AdminGuide/html_frameset.htm&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Apr 2019 01:58:32 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-04-02T01:58:32Z</dc:date>
    <item>
      <title>Define user with specific privileges</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Define-user-with-specific-privileges/m-p/49213#M3677</link>
      <description>&lt;P&gt;I need to define a user with only the privileges to execute the "pdp control revoke_ip x.x.x.x" command.&lt;BR /&gt;Do you know if is it possible?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 16:48:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Define-user-with-specific-privileges/m-p/49213#M3677</guid>
      <dc:creator>Leonardo_Tessar</dc:creator>
      <dc:date>2019-03-29T16:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: Define user with specific privileges</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Define-user-with-specific-privileges/m-p/49282#M3679</link>
      <description>&lt;P&gt;Yes, using the &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk144112" target="_self"&gt;Dynamic CLI&lt;/A&gt;&amp;nbsp;and &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk94491" target="_self"&gt;Role Based Access&lt;/A&gt;. Create the relevant command via the Dynamic CLI feature, assign the specific command to a specific role in Gaia, and assign the desired user that specific role.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2019 15:59:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Define-user-with-specific-privileges/m-p/49282#M3679</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-30T15:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: Define user with specific privileges</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Define-user-with-specific-privileges/m-p/49479#M3691</link>
      <description>Thank you, I've installed the Dynamic CLI but I can't find an equivalent command to "pdp control".&lt;BR /&gt;Could you explain how to create it via Dynamic CLI ?</description>
      <pubDate>Mon, 01 Apr 2019 16:20:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Define-user-with-specific-privileges/m-p/49479#M3691</guid>
      <dc:creator>Leonardo_Tessar</dc:creator>
      <dc:date>2019-04-01T16:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: Define user with specific privileges</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Define-user-with-specific-privileges/m-p/49512#M3692</link>
      <description>&lt;P&gt;I was mistaken that Dynamic CLI is required. Instead,&amp;nbsp;you need to use a feature in Gaia called "User Defined (Extended) Commands" as described in the Gaia Admin Guide:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R80.20.M2/WebAdminGuides/EN/CP_R80.20_M2_Gaia_AdminGuide/html_frameset.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.20.M2/WebAdminGuides/EN/CP_R80.20_M2_Gaia_AdminGuide/html_frameset.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 01:58:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Define-user-with-specific-privileges/m-p/49512#M3692</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-02T01:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: Define user with specific privileges</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Define-user-with-specific-privileges/m-p/49536#M3693</link>
      <description>&lt;P&gt;I checked the list of available extended commands but I didn't find the "pdp".&lt;/P&gt;&lt;P&gt;I tried anyway to add the new command:&lt;/P&gt;&lt;P&gt;&amp;gt; add command revokeip path /opt/CPsuite-R80.20/fw1/bin/pdp "Revoke session from the given ip"&lt;/P&gt;&lt;P&gt;but I get this error:&lt;/P&gt;&lt;P&gt;CLINFR0329 Invalid command&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 07:16:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Define-user-with-specific-privileges/m-p/49536#M3693</guid>
      <dc:creator>Leonardo_Tessar</dc:creator>
      <dc:date>2019-04-02T07:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: Define user with specific privileges</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Define-user-with-specific-privileges/m-p/49596#M3699</link>
      <description>&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;You missed a parameter in your command:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;gw&amp;gt; &lt;STRONG&gt;add command revokeip path /opt/CPsuite-R80.20/fw1/bin/pdp description "Revoke session from the given IP"&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;Command (revokeip) was added.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;Save the configuration and re sign in for changes to take place.&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;gw&amp;gt; &lt;STRONG&gt;save config&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Once you log out/back in, you can use your revokeip command, which calls the pdp binary.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;gw&amp;gt; &lt;STRONG&gt;revokeip&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;Command: root&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;Available options:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;debug &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;- control debug messages&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;tracker &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;- tracker options&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;connections &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;- pdp connections information&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;network &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;- pdp network information&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;status&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;- pdp status information&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;control &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;- pdp control commands&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;monitor &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;- display monitoring data&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;update&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;- recalculate users and machines group membership (deleted accounts will not be updated)&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;vpn &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;- display connected vpn gateways that send vpn client identity data&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;ad&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;- operations related to AD Query&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;timers&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;- show pdp timers information&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="Apple-converted-space" style="font-family: inherit;"&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-family: inherit;"&gt;nested_groups &lt;/SPAN&gt;&lt;SPAN class="Apple-converted-space" style="font-family: inherit;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-family: inherit;"&gt;- nested groups configuration&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;auth&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;- authentication/authorization options&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;radius&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;- radius accounting options&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;&amp;nbsp; ifmap &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;- monitor/control IFMAP&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;&amp;nbsp; idc &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;- operations related to Identity Collector&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;&amp;nbsp; tasks_manager &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;- the task manager menu&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="Apple-converted-space" style="font-family: inherit;"&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-family: inherit;"&gt;topology_map&lt;/SPAN&gt;&lt;SPAN class="Apple-converted-space" style="font-family: inherit;"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-family: inherit;"&gt;- show topology mapping debug info. usage: topology_map [raw]&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;gw&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;If you want to restrict the pdp binary to specific options, then create a shell scrip that calls the pdp binary with the specific options you're interested in.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 15:38:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Define-user-with-specific-privileges/m-p/49596#M3699</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-02T15:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: Define user with specific privileges</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Define-user-with-specific-privileges/m-p/83207#M6430</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"If you want to restrict the pdp binary to specific options, then create a shell scrip that calls the pdp binary with the specific options you're interested"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Can you please explain how to allow user run only spesific option on command?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have user that access to bin bash shell from phyton and we want to allow him run only: fw hashta and not all fw tree options.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Apr 2020 15:18:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Define-user-with-specific-privileges/m-p/83207#M6430</guid>
      <dc:creator>asher</dc:creator>
      <dc:date>2020-04-26T15:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: Define user with specific privileges</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Define-user-with-specific-privileges/m-p/83209#M6431</link>
      <description>The easiest thing to do is write a script that calls the binary with the specific allowed options.&lt;BR /&gt;Then you can add that script as a command as shown here.</description>
      <pubDate>Sun, 26 Apr 2020 15:55:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Define-user-with-specific-privileges/m-p/83209#M6431</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-26T15:55:03Z</dc:date>
    </item>
  </channel>
</rss>

