<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Admin access to only specific gateway in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/246554#M48057</link>
    <description>&lt;P&gt;So, with Multi-Domain, I can restrict a user or group of users (by associating a profile with them) from seeing only one specific policy, right? If there are, for example, three policies, they can only see and modify one of those three in this scenario.&lt;/P&gt;</description>
    <pubDate>Tue, 15 Apr 2025 16:17:55 GMT</pubDate>
    <dc:creator>jennyado</dc:creator>
    <dc:date>2025-04-15T16:17:55Z</dc:date>
    <item>
      <title>Admin access to only specific gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/160042#M28163</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I have two user in smart console and both having read/write access.Also i have 2 gateways as A and B so is it possible to configure admin 1 can change policies of only gateway A and admin 2 can change only policies of gateway B.If yes please let me know.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 09:51:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/160042#M28163</guid>
      <dc:creator>shenaitejas</dc:creator>
      <dc:date>2022-10-20T09:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: Admin access to only specific gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/160073#M28173</link>
      <description>&lt;P&gt;You'll need to to assign a Permission Profile for each administrator, then attach that Profile to the relevant Policy Layer (part of the overall Policy). Here are the general steps:&lt;/P&gt;
&lt;P&gt;1| For each Administrator define a different Read/Write Permission Profile (even if the actual settings are identical).&lt;/P&gt;
&lt;P&gt;2| Define two Policy Packages - one for each Security Gateway&lt;/P&gt;
&lt;P&gt;3| The Policy Package is made of the specific Policy Layers, so assign each one with the relevant Permission Profile:&lt;/P&gt;
&lt;P&gt;Menu &amp;gt; Manage policies and layers &amp;gt; layers &amp;gt; Access Control &amp;gt; Select the Layer name belonging to the Policy &amp;gt; Edit &amp;gt; Permissions&lt;/P&gt;
&lt;P&gt;4| Add the relevant Permission Profiles&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The end result is two policies that can be changed only by the relevant administrator.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-10-20 18_20_28-Layer Editor.png" style="width: 624px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18182iCFF165174720AA5A/image-size/large?v=v2&amp;amp;px=999" role="button" title="2022-10-20 18_20_28-Layer Editor.png" alt="2022-10-20 18_20_28-Layer Editor.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 15:22:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/160073#M28173</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2022-10-20T15:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Admin access to only specific gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/160080#M28178</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/585"&gt;@Tal_Paz-Fridman&lt;/a&gt;&amp;nbsp;gave you perfect response.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 16:40:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/160080#M28178</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-10-20T16:40:57Z</dc:date>
    </item>
    <item>
      <title>Re: Admin access to only specific gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/160083#M28179</link>
      <description>&lt;P&gt;One caveat with this approach: both administrators will have access to edit the underlying objects, which can affect policies on both gateways.&lt;BR /&gt;For true separation of duties where each gateway has its own set of objects modifiable only by the relevant administrator, you need Multi-Domain.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 19:11:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/160083#M28179</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-20T19:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: Admin access to only specific gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/160128#M28198</link>
      <description>&lt;P&gt;Thank you all..I will check it.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2022 14:27:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/160128#M28198</guid>
      <dc:creator>shenaitejas</dc:creator>
      <dc:date>2022-10-21T14:27:47Z</dc:date>
    </item>
    <item>
      <title>Re: Admin access to only specific gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/246452#M48029</link>
      <description>&lt;P&gt;I applied this configuration to create a Permission Profile (Profile1example) and associated it with the Access Control and Threat Prevention Layers of a Policy Package (PP_example). Is it normal for the user with Profile1example permissions to be able to see the other Policy Packages even if they don't have the Profile permission configured in the Layer Editor?&lt;/P&gt;&lt;P&gt;This is my question because I created a user who has Profile1example associated and can still see the other Policy Packages. Expectedly, they would only see PP_example and only be able to configure and edit that policy.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 00:45:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/246452#M48029</guid>
      <dc:creator>jennyado</dc:creator>
      <dc:date>2025-04-15T00:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: Admin access to only specific gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/246477#M48032</link>
      <description>&lt;P&gt;Are they able to edit the policy package or only to view it in detail ?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 09:30:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/246477#M48032</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-04-15T09:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: Admin access to only specific gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/246507#M48039</link>
      <description>&lt;P&gt;As far as I know, yes, this is expected behavior.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 12:16:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/246507#M48039</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-15T12:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: Admin access to only specific gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/246542#M48054</link>
      <description>&lt;P&gt;It doesn't allow me to edit the other policies, just view them. We can see the details of the other policy packages, and I also see that clicking the "Install Policy" button displays the window to proceed with the installation. I didn't continue testing to confirm if it allows me to install the policy, but I assume it would.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 15:37:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/246542#M48054</guid>
      <dc:creator>jennyado</dc:creator>
      <dc:date>2025-04-15T15:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: Admin access to only specific gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/246543#M48055</link>
      <description>&lt;P&gt;Is it normal to be allowed to proceed with the installation of the other policies?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 15:32:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/246543#M48055</guid>
      <dc:creator>jennyado</dc:creator>
      <dc:date>2025-04-15T15:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: Admin access to only specific gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/246550#M48056</link>
      <description>&lt;P&gt;Install Policy is a separate permission:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30239iC1BC9AB916DC2CE2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;While I haven't checked it, I assume if they have this permission, they can install ANY policy.&lt;BR /&gt;If you need that level of separation, you will need to use Multi-Domain.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 16:07:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/246550#M48056</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-15T16:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: Admin access to only specific gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/246554#M48057</link>
      <description>&lt;P&gt;So, with Multi-Domain, I can restrict a user or group of users (by associating a profile with them) from seeing only one specific policy, right? If there are, for example, three policies, they can only see and modify one of those three in this scenario.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 16:17:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/246554#M48057</guid>
      <dc:creator>jennyado</dc:creator>
      <dc:date>2025-04-15T16:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: Admin access to only specific gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/246555#M48058</link>
      <description>&lt;P&gt;Not exactly as the permission profiles work exactly the same in Multi-Domain (i.e. they have the same limitations).&lt;/P&gt;
&lt;P&gt;What you can do in Multi-Domain is put the gateways and policies in separate management domains.&lt;BR /&gt;This "management domain" is similar to a standalone management server, including separate objects, policies, and logs.&amp;nbsp;&lt;BR /&gt;You can grant access to these management domains per admin as required.&lt;BR /&gt;You can create global objects/rules that apply across the management domains also.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 16:32:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Admin-access-to-only-specific-gateway/m-p/246555#M48058</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-15T16:32:31Z</dc:date>
    </item>
  </channel>
</rss>

