<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Limited Permission Profile in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32876#M88379</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="Bravo" class="image-1 jive-image j-img-original" src="https://i.gifer.com/YEQF.gif" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Mar 2019 09:31:51 GMT</pubDate>
    <dc:creator>Aitor_Carazo</dc:creator>
    <dc:date>2019-03-08T09:31:51Z</dc:date>
    <item>
      <title>Limited Permission Profile</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32868#M88371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can I setup a read only user with a profile that only allows him to read logs and view his policy only?&amp;nbsp; This is on a SMS not an MDM.&amp;nbsp; The purpose is to allow a limited admin the ability to be restricted to just what they control or have a business need to see.&amp;nbsp; They do not see all the policies or logs, just their own at their remote location.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Feb 2019 16:39:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32868#M88371</guid>
      <dc:creator>Julie_Paul</dc:creator>
      <dc:date>2019-02-12T16:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Permission Profile</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32869#M88372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Julie,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's the version do you use? On R80.x you can create a specific profile (SmartConsole &amp;gt; Manage &amp;amp; Settings &amp;gt; Permissions &amp;amp; Administrators &amp;gt; Permission profiles) according to you&amp;nbsp;need and associate with the user, but we can't create a profile read/write for a specific gateway or policy package.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For more details, please see:&amp;nbsp;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R80/CP_R80_SmartDashboard_OLH/html_frameset.htm?topic=documents/R80/CP_R80_SmartDashboard_OLH/H4D85vDH-u2beps-s16BOQ2" title="https://sc1.checkpoint.com/documents/R80/CP_R80_SmartDashboard_OLH/html_frameset.htm?topic=documents/R80/CP_R80_SmartDashboard_OLH/H4D85vDH-u2beps-s16BOQ2"&gt;SmartConsole R80 Help&lt;/A&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alisson Lima&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Feb 2019 22:27:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32869#M88372</guid>
      <dc:creator>Alisson_Lima</dc:creator>
      <dc:date>2019-02-12T22:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Permission Profile</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32870#M88373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;R80.20 That is the problem.&amp;nbsp; I have customers who need the ability to create limited view admin profiles.&amp;nbsp; They are too small to be an MDM shop but still need the flexibility to only allow specific users read access to specific policies and the logs associated to that policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Feb 2019 22:54:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32870#M88373</guid>
      <dc:creator>Julie_Paul</dc:creator>
      <dc:date>2019-02-12T22:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Permission Profile</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32871#M88374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can grant them access to logs in unfiltered but read only mode via smartview:&lt;/P&gt;&lt;P&gt;&lt;A href="https://management"&gt;https://management&lt;/A&gt;_ip/smartview&amp;nbsp;&lt;/P&gt;&lt;P&gt;by restricting their access to the management server to https only:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78402_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2019 05:52:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32871#M88374</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-02-13T05:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Permission Profile</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32872#M88375</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That will not work, they&amp;nbsp; need to only see their gateway logs and the policy also.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2019 13:28:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32872#M88375</guid>
      <dc:creator>Julie_Paul</dc:creator>
      <dc:date>2019-02-13T13:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Permission Profile</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32873#M88376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since you also asked this question internally and got an answer, why not propagate the answer here &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;In general, you can restrict the logs a given user sees in SmartView.&lt;/P&gt;&lt;P&gt;You cannot currently restrict read access to all policies in SmartConsole.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to apply a “hardcoded” filter which the user will not be able to edit (in order to restrict the ability to see logs not relevant), perform the following steps.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Edit a file called users.xml which exists under $RTDIR/smartview/db/domains/XXXXX&lt;/LI&gt;&lt;LI&gt;If you have several domains you can look at the file domain.txt under each domain folder in order to know the name of the domain&lt;/LI&gt;&lt;LI&gt;In the users.xml file you’ll see &amp;lt;user&amp;gt; tags&lt;/LI&gt;&lt;LI&gt;You can add a filter tag to the corresponding user tags which will be added to every query the user will send.&lt;/LI&gt;&lt;LI&gt;An Example of a filter which will display only Application Control logs of a specific user:&lt;/LI&gt;&lt;/UL&gt;&lt;PRE&gt;&lt;PRE style="color: #000000; background-color: white; font-weight: normal; text-indent: -0.25in; font-size: 10pt; margin: 0in 0in 0.0001pt 0.5in;"&gt;&lt;SPAN style="color: black; background-color: #efefef; font-size: 9pt;"&gt;&amp;lt;&lt;/SPAN&gt;&lt;STRONG style="background-color: #efefef; color: navy; font-size: 9pt; "&gt;filter&lt;/STRONG&gt;&lt;SPAN style="color: black; background-color: #efefef; font-size: 9pt;"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-size: 9pt;"&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="background-color: #efefef;"&gt;&amp;lt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG style="background-color: #efefef; color: navy; font-size: 9pt; "&gt;and&lt;/STRONG&gt;&lt;SPAN style="color: black; background-color: #efefef; font-size: 9pt;"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-size: 9pt;"&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="background-color: #efefef;"&gt;&amp;lt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG style="background-color: #efefef; color: navy; font-size: 9pt; "&gt;equals&lt;/STRONG&gt;&lt;SPAN style="color: black; background-color: #efefef; font-size: 9pt;"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-size: 9pt;"&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="background-color: #efefef;"&gt;&amp;lt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG style="background-color: #efefef; color: navy; font-size: 9pt; "&gt;field&lt;/STRONG&gt;&lt;SPAN style="color: black; background-color: #efefef; font-size: 9pt;"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-size: 9pt;"&gt;&amp;lt;![CDATA[product]]&amp;gt;&lt;SPAN style="background-color: #efefef;"&gt;&amp;lt;/&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG style="background-color: #efefef; color: navy; font-size: 9pt; "&gt;field&lt;/STRONG&gt;&lt;SPAN style="color: black; background-color: #efefef; font-size: 9pt;"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-size: 9pt;"&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="background-color: #efefef;"&gt;&amp;lt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG style="background-color: #efefef; color: navy; font-size: 9pt; "&gt;value&lt;/STRONG&gt;&lt;SPAN style="color: black; background-color: #efefef; font-size: 9pt;"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-size: 9pt;"&gt;&amp;lt;![CDATA[Application Control]]&amp;gt;&lt;SPAN style="background-color: #efefef;"&gt;&amp;lt;/&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG style="background-color: #efefef; color: navy; font-size: 9pt; "&gt;value&lt;/STRONG&gt;&lt;SPAN style="color: black; background-color: #efefef; font-size: 9pt;"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-size: 9pt;"&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="background-color: #efefef;"&gt;&amp;lt;/&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG style="background-color: #efefef; color: navy; font-size: 9pt; "&gt;equals&lt;/STRONG&gt;&lt;SPAN style="color: black; background-color: #efefef; font-size: 9pt;"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-size: 9pt;"&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="background-color: #efefef;"&gt;&amp;lt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG style="background-color: #efefef; color: navy; font-size: 9pt; "&gt;equals&lt;/STRONG&gt;&lt;SPAN style="color: black; background-color: #efefef; font-size: 9pt;"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-size: 9pt;"&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="background-color: #efefef;"&gt;&amp;lt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG style="background-color: #efefef; color: navy; font-size: 9pt; "&gt;field&lt;/STRONG&gt;&lt;SPAN style="color: black; background-color: #efefef; font-size: 9pt;"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-size: 9pt;"&gt;&amp;lt;![CDATA[user]]&amp;gt;&lt;SPAN style="background-color: #efefef;"&gt;&amp;lt;/&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG style="background-color: #efefef; color: navy; font-size: 9pt; "&gt;field&lt;/STRONG&gt;&lt;SPAN style="color: black; background-color: #efefef; font-size: 9pt;"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-size: 9pt;"&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="background-color: #efefef;"&gt;&amp;lt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG style="background-color: #efefef; color: navy; font-size: 9pt; "&gt;value&lt;/STRONG&gt;&lt;SPAN style="color: black; background-color: #efefef; font-size: 9pt;"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-size: 9pt;"&gt;&amp;lt;![CDATA[John Smith]]&amp;gt;&lt;SPAN style="background-color: #efefef;"&gt;&amp;lt;/&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG style="background-color: #efefef; color: navy; font-size: 9pt; "&gt;value&lt;/STRONG&gt;&lt;SPAN style="color: black; background-color: #efefef; font-size: 9pt;"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-size: 9pt;"&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="background-color: #efefef;"&gt;&amp;lt;/&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG style="background-color: #efefef; color: navy; font-size: 9pt; "&gt;equals&lt;/STRONG&gt;&lt;SPAN style="color: black; background-color: #efefef; font-size: 9pt;"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-size: 9pt;"&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="background-color: #efefef;"&gt;&amp;lt;/&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG style="background-color: #efefef; color: navy; font-size: 9pt; "&gt;and&lt;/STRONG&gt;&lt;SPAN style="color: black; background-color: #efefef; font-size: 9pt;"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-size: 9pt;"&gt;&lt;BR /&gt;&lt;SPAN style="background-color: #efefef;"&gt;&amp;lt;/&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG style="background-color: #efefef; color: navy; font-size: 9pt; "&gt;filter&lt;/STRONG&gt;&lt;SPAN style="color: black; background-color: #efefef; font-size: 9pt;"&gt;&amp;gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Restart SmartView by running the commands:&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;$RTDIR/scripts/stopSmartView&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;$RTDIR/scripts/startSmartView&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Feb 2019 00:42:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32873#M88376</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-16T00:42:53Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Permission Profile</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32874#M88377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried to perform this changes on one user and when i tried to connect via web Smartview i get an error after log-in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 90px;"&gt;&lt;SPAN style="font-size: 22px;"&gt;Initialization failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 90px;"&gt;&lt;SPAN style="font-size: 22px;"&gt;error ref id:6380036B&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I also have tried with the exact example of APPCTL and Jhon Smith and also fails&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;STRONG style="font-size: 13px; "&gt; &amp;nbsp;&amp;nbsp;........................&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG style="font-size: 13px; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;tabs&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG style="font-size: 13px; "&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;active&amp;gt;&amp;lt;![CDATA[{769F9EF8-606A-4956-A357-675E311C632A}]]&amp;gt;&amp;lt;/active&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG style="font-size: 13px; "&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;uid&amp;gt;&amp;lt;![CDATA[{769F9EF8-606A-4956-A357-675E311C632A}]]&amp;gt;&amp;lt;/uid&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG style="font-size: 13px; "&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;/tabs&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG style="font-size: 13px; "&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;emailServer/&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG style="font-size: 13px; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;_timestamp_&amp;gt;&amp;lt;![CDATA[2019-03-06T15:36:12+01:00]]&amp;gt;&amp;lt;/_timestamp_&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG style=": ; color: #3366ff; font-size: 13px; "&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;filter&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG style=": ; color: #3366ff; font-size: 13px; "&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;field&amp;gt;&amp;lt;![CDATA[origin]]&amp;gt;&amp;lt;/field&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG style=": ; color: #3366ff; font-size: 13px; "&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;value&amp;gt;&amp;lt;![CDATA[BranchFW]]&amp;gt;&amp;lt;/value&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG style=": ; color: #3366ff; font-size: 13px; "&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;/filter&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG style="font-size: 13px; "&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;/user&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG style="font-size: 13px; "&gt;&amp;lt;/users&amp;gt;&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt;I tried to find the syntax but there is no info.&amp;nbsp;&lt;/P&gt;&lt;P&gt;How could i get this working?&lt;/P&gt;&lt;P&gt;Where is the error?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2019 15:18:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32874#M88377</guid>
      <dc:creator>Aitor_Carazo</dc:creator>
      <dc:date>2019-03-06T15:18:47Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Permission Profile</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32875#M88378</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;filter&amp;gt;origin:BranchFW&amp;lt;/filter&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Mar 2019 02:40:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32875#M88378</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-07T02:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Permission Profile</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32876#M88379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="Bravo" class="image-1 jive-image j-img-original" src="https://i.gifer.com/YEQF.gif" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Mar 2019 09:31:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32876#M88379</guid>
      <dc:creator>Aitor_Carazo</dc:creator>
      <dc:date>2019-03-08T09:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Permission Profile</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32877#M88380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume that worked, then? &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Mar 2019 15:03:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/32877#M88380</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-08T15:03:15Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Permission Profile</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/47928#M88381</link>
      <description>&lt;P&gt;It Works Perfectly!!!&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 10:20:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/47928#M88381</guid>
      <dc:creator>Aitor_Carazo</dc:creator>
      <dc:date>2019-03-20T10:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Permission Profile</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/69968#M88382</link>
      <description>I have been searching for this solution months now.&lt;BR /&gt;&lt;BR /&gt;I would love a sample config of the users.xml file to restrict a user to only be able to view logs generated from a specific gateway.</description>
      <pubDate>Wed, 11 Dec 2019 01:14:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/69968#M88382</guid>
      <dc:creator>steve_warren</dc:creator>
      <dc:date>2019-12-11T01:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Permission Profile</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/70511#M88383</link>
      <description>&lt;P&gt;Insert the &lt;U&gt;filter line&lt;/U&gt; to the right &lt;STRONG&gt;users.xml&lt;/STRONG&gt; file like this:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;in $RTDIR/smartview/db/domains/&lt;STRONG&gt;&amp;lt;relevant_domain_id&amp;gt;&lt;/STRONG&gt;/users.xml&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;lt;owner&amp;gt;&amp;lt;![CDATA[admin]]&amp;gt;&amp;lt;/owner&amp;gt;&lt;BR /&gt;&amp;lt;isNewlyCreated&amp;gt;&amp;lt;![CDATA[true]]&amp;gt;&amp;lt;/isNewlyCreated&amp;gt;&lt;BR /&gt;&amp;lt;username&amp;gt;&amp;lt;![CDATA[admin]]&amp;gt;&amp;lt;/username&amp;gt;&lt;BR /&gt;&amp;lt;locale&amp;gt;&amp;lt;![CDATA[en-US]]&amp;gt;&amp;lt;/locale&amp;gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;lt;filter&amp;gt;&amp;lt;![CDATA[orig:&amp;lt;GW_Name/IP&amp;gt;]]&amp;gt;&amp;lt;/filter&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;&amp;lt;firstDayOfWeek&amp;gt;&amp;lt;![CDATA[2]]&amp;gt;&amp;lt;/firstDayOfWeek&amp;gt;&lt;BR /&gt;&amp;lt;theme&amp;gt;&amp;lt;![CDATA[default]]&amp;gt;&amp;lt;/theme&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Restart Smartview:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;$RTDIR/scripts/stopSmartView; $RTDIR/scripts/startSmartView&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Dec 2019 14:49:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/70511#M88383</guid>
      <dc:creator>Dror_Aharony</dc:creator>
      <dc:date>2019-12-15T14:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Permission Profile</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/73430#M88384</link>
      <description>&lt;P&gt;And if I need to add more than one gateway for the user?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2020 10:35:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/73430#M88384</guid>
      <dc:creator>AntonMakarychev</dc:creator>
      <dc:date>2020-01-27T10:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Permission Profile</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/73431#M88385</link>
      <description>&lt;P&gt;Simply add an OR.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;lt;filter&amp;gt;&amp;lt;![CDATA[orig:&lt;/STRONG&gt;&amp;lt;GW_Name/IP&amp;gt;&lt;STRONG&gt; OR &lt;/STRONG&gt;orig:&amp;lt;GW2&amp;gt;&lt;STRONG&gt;]]&amp;gt;&amp;lt;/filter&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2020 10:38:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/73431#M88385</guid>
      <dc:creator>Dror_Aharony</dc:creator>
      <dc:date>2020-01-27T10:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Permission Profile</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/73433#M88386</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2020 10:45:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/73433#M88386</guid>
      <dc:creator>AntonMakarychev</dc:creator>
      <dc:date>2020-01-27T10:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Permission Profile</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/75671#M88387</link>
      <description>&lt;P&gt;Hi, I am also trying to limit the visible data to the user. The filter&amp;nbsp;&lt;STRONG&gt;&amp;lt;filter&amp;gt;&amp;lt;![CDATA[orig:&amp;lt;GW_Name/IP&amp;gt;]]&amp;gt;&amp;lt;/filter&amp;gt;&amp;nbsp;&lt;/STRONG&gt;works fine, but I have a different kind of problem.&lt;/P&gt;&lt;P&gt;We are using MDS, and when the user connects to SmartViev he can choose between the global domain (MDS) and a specific domain. If he chooses the specific domain the filter works fine. If he chooses the global domain (MDS) the filter does not apply, he can see all the logs&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":neutral_face:"&gt;😐&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Can I restrict the user access not to be able to connect to the global domain (MDS) thorugh SmartView at all, or to filter the view on MDS?&lt;BR /&gt;In the SmartConsole on the MDS I have restricted the user permission to view the logs only and to be able to see only one domain (the other domains aren't visible), but the option of viewing logs on the global domain (MDS) is always available through SmartView.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 08:35:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/75671#M88387</guid>
      <dc:creator>Hrvoje_Brlek</dc:creator>
      <dc:date>2020-02-19T08:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Permission Profile</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/75678#M88388</link>
      <description>&lt;P&gt;You can try either of the following:&lt;/P&gt;
&lt;P&gt;1, You can remove the global domain from his administrator all together from and he won't be able to connect to MDS level at all.&lt;/P&gt;
&lt;P&gt;2. You can assign him a permission profile to the global domain that doesn't have log permission. Go to&amp;nbsp;&lt;SPAN&gt;Permission profile -&amp;gt; Monitoring and Logging and remove the permission for traffic logs and management logs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3. You can change the admin type to a "Domain Level Only". This kind of profile can't connect to global level.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 08:57:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/75678#M88388</guid>
      <dc:creator>Amir_Senn</dc:creator>
      <dc:date>2020-02-19T08:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Permission Profile</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/75709#M88390</link>
      <description>&lt;P&gt;Hi, I am testing and this is what I get. Just to clarify I am talking about SmartView browser viewing, not the SmartConsole access. The user is local, and we are using R80.30.&lt;/P&gt;&lt;P&gt;3. It was already configured as domain-level only, but can still connect to MDS on SmartView (with all logs visible).&amp;nbsp;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 500px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4517i278C830869A9B7E1/image-dimensions/500x444?v=v2" width="500" height="444" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. The multi-domain permission is obligatory on the user profile. This is how it was set, and it doesn't work. Still all the logs are visible through MDS on SMartView.&lt;/P&gt;&lt;P&gt;Multi-domain:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 466px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4511i7694D35CCB29D655/image-dimensions/466x614?v=v2" width="466" height="614" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Read-only NO access:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 465px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4513i03124A2D602E5334/image-dimensions/465x416?v=v2" width="465" height="416" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Read only Log:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 467px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4514i342C3573F865621A/image-dimensions/467x418?v=v2" width="467" height="418" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;User profile:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 494px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4518iB2F0A901914EC486/image-dimensions/494x436?v=v2" width="494" height="436" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Can you please elaborate this one, or how to set it up?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 10:16:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/75709#M88390</guid>
      <dc:creator>Hrvoje_Brlek</dc:creator>
      <dc:date>2020-02-19T10:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Permission Profile</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/75726#M88391</link>
      <description>&lt;P&gt;1. On the last picture you added, there's a "All Global Domains" item on the domains list. The intention was to remove it by selecting it and clicking on the X above.&lt;/P&gt;
&lt;P&gt;I want to elaborate on something, at least from logs perspective. Everything you see on SmartConsole should be identical to what you see on the SmartView webapp. There should be no difference whatsoever. If there is a difference there's an issue here.&lt;/P&gt;
&lt;P&gt;First thing I suggest you should do is to check if you have some sort of access roles. Perhaps it signs in with an access role and not the CP admin you created for him.&lt;/P&gt;
&lt;P&gt;If it's not related then this is an issue. I would suggest installing latest jumbo hotfix to see if this solves this.&lt;/P&gt;
&lt;P&gt;If the issue continues, I suggest opening ticket for TAC support.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 12:26:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limited-Permission-Profile/m-p/75726#M88391</guid>
      <dc:creator>Amir_Senn</dc:creator>
      <dc:date>2020-02-19T12:26:50Z</dc:date>
    </item>
  </channel>
</rss>

