- Products
- Learn
- Local User Groups
- Partners
- More
Check Point WAF TechTalk:
Introduction and New Features
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
CheckMates Go:
CheckMates Fest
We need to restrict the editing of all rules from a certain section tittle for other administrators, and that they can only be edited by admin. Is it possible to do this in Check Point?
Granting permission for a specific section of the rulebase is not feasible. However, you can explore the following alternatives:
Implement Ordered Layers and assign distinct Permission Profiles to each layer.
Transition to Multi-Domain Security Management, which allows you to utilize a Global Domain for a particular policy segment, while the Domain level administrator handles the remaining sections.
If you can send a screenshot and circle what you want to di, I can test it in my lab.
Andy
For example, administrators other than Administator cannot edit 1-13 rules
I have an hour before my next call, so stand by, let me see if this is possible.
Cheers,
Andy
Granting permission for a specific section of the rulebase is not feasible. However, you can explore the following alternatives:
Implement Ordered Layers and assign distinct Permission Profiles to each layer.
Transition to Multi-Domain Security Management, which allows you to utilize a Global Domain for a particular policy segment, while the Domain level administrator handles the remaining sections.
Implement Ordered Layers and assign distinct Permission Profiles to each layer.
Could you describe this process in more detail?
Thank you I have figured out the technology in question.
I think what @Tal_Paz-Fridman said makes sense. I looked for any setting related to being able to possible prevent given admin from modifying regular rule(s), but it does not appear to exist anywhere.
Its definitely good candidate for RFE, in my view.
Andy
Yeah, that's what I thought, too. MDS implementation is quite difficult in terms of time, while layers implementation is simple. We will try this option, thanks
Im fairly sure this is what @Tal_Paz-Fridman was referring to.
Andy
Directly, no.
However, through use of a SmartTask like https://community.checkpoint.com/t5/Management/SmartTask-Custom-Permissions/m-p/77247#M11281, it should be possible.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 11 | |
| 9 | |
| 8 | |
| 7 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Thu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 03:00 PM (EDT)
Maestro Masters Americas: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 03:00 PM (EDT)
Maestro Masters Americas: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementThu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY