<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitor user / read user with permissions to execute troubleshooting commands in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Monitor-user-read-user-with-permissions-to-execute/m-p/241055#M40219</link>
    <description>&lt;P&gt;Here are the supported commands you can use in a role:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_AdminGuide/Content/Topics-GAG/Roles-Extended-Commands.htm?tocpath=User%20Management%7CRoles%7C_____4" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_AdminGuide/Content/Topics-GAG/Roles-Extended-Commands.htm?tocpath=User%20Management%7CRoles%7C_____4&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Second you need to create an admin role instead if monitor role. Monitor role is read-only. Admin role you give view access and write access.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_AdminGuide/Content/Topics-GAG/Roles.htm?tocpath=User%20Management%7CRoles%7C_____0" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_AdminGuide/Content/Topics-GAG/Roles.htm?tocpath=User%20Management%7CRoles%7C_____0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Feb 2025 17:44:34 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2025-02-12T17:44:34Z</dc:date>
    <item>
      <title>Monitor user / read user with permissions to execute troubleshooting commands</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Monitor-user-read-user-with-permissions-to-execute/m-p/241046#M40217</link>
      <description>&lt;P&gt;Hello:&lt;/P&gt;&lt;P&gt;I am trying to create a user with monitoring permissions and also that can execute troubleshooting commands:&lt;/P&gt;&lt;P&gt;tcpdump&lt;BR /&gt;fw monitor&lt;BR /&gt;cpview&lt;BR /&gt;etc&lt;/P&gt;&lt;P&gt;For this I have created a role clone of the monitor and I have also allowed expert mode and the commands but it does not allow SSH access, for it to work I have to give it also adminRole roles.&lt;/P&gt;&lt;P&gt;Do you know what I could be missing?&lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 15:25:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Monitor-user-read-user-with-permissions-to-execute/m-p/241046#M40217</guid>
      <dc:creator>intaq</dc:creator>
      <dc:date>2025-02-12T15:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor user / read user with permissions to execute troubleshooting commands</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Monitor-user-read-user-with-permissions-to-execute/m-p/241055#M40219</link>
      <description>&lt;P&gt;Here are the supported commands you can use in a role:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_AdminGuide/Content/Topics-GAG/Roles-Extended-Commands.htm?tocpath=User%20Management%7CRoles%7C_____4" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_AdminGuide/Content/Topics-GAG/Roles-Extended-Commands.htm?tocpath=User%20Management%7CRoles%7C_____4&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Second you need to create an admin role instead if monitor role. Monitor role is read-only. Admin role you give view access and write access.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_AdminGuide/Content/Topics-GAG/Roles.htm?tocpath=User%20Management%7CRoles%7C_____0" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_AdminGuide/Content/Topics-GAG/Roles.htm?tocpath=User%20Management%7CRoles%7C_____0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 17:44:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Monitor-user-read-user-with-permissions-to-execute/m-p/241055#M40219</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-02-12T17:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor user / read user with permissions to execute troubleshooting commands</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Monitor-user-read-user-with-permissions-to-execute/m-p/241099#M40228</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;Thanks for your reply!&lt;/P&gt;&lt;P&gt;The idea is to create a read-only user with troubleshooting capabilities. That is why we clone the Role from MonitorRole and not from adminRole.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 08:43:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Monitor-user-read-user-with-permissions-to-execute/m-p/241099#M40228</guid>
      <dc:creator>intaq</dc:creator>
      <dc:date>2025-02-13T08:43:47Z</dc:date>
    </item>
  </channel>
</rss>

