<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius configuration shell privileges in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Radius-configuration-shell-privileges/m-p/201958#M66340</link>
    <description>&lt;P&gt;Unfortunately, all RADIUS users end up resolving to the same local user with the same shell.&lt;BR /&gt;I don't believe it's possible to change this.&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jan 2024 22:54:37 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-01-02T22:54:37Z</dc:date>
    <item>
      <title>Radius configuration shell privileges</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Radius-configuration-shell-privileges/m-p/201869#M66339</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I`m trying to configure different ssh privileges in my R81 environment using Radius.&lt;/P&gt;&lt;P&gt;My purpose is to allow expert mode to a specific group and connect them directly into, while others have permission only for clish.&lt;/P&gt;&lt;P&gt;I only managed to configure all of the groups to login the same shell mode: Expert or Clish (and not separate by permissions)&lt;/P&gt;&lt;P&gt;the situation now is that I configured all for clish mode, and the group with expert permissions can move into expert mode by using local expert password, which i`m trying to bypass - or by login them directly into expert (which means for all other groups as well), or to somehow configure expert mode to authenticate using radius.&lt;/P&gt;&lt;P&gt;Gaia Configuration now: RADIUS Users Default Shell: /etc/cli.sh&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Super User UID: 0&lt;/P&gt;&lt;P&gt;Any ideas of how to achieve this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;Thanks&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 01 Jan 2024 13:14:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Radius-configuration-shell-privileges/m-p/201869#M66339</guid>
      <dc:creator>ItzikK</dc:creator>
      <dc:date>2024-01-01T13:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: Radius configuration shell privileges</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Radius-configuration-shell-privileges/m-p/201958#M66340</link>
      <description>&lt;P&gt;Unfortunately, all RADIUS users end up resolving to the same local user with the same shell.&lt;BR /&gt;I don't believe it's possible to change this.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2024 22:54:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Radius-configuration-shell-privileges/m-p/201958#M66340</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-01-02T22:54:37Z</dc:date>
    </item>
  </channel>
</rss>

