- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Possibility to limit User Access via Managemen...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Possibility to limit User Access via Management Server
Hello Guys,
is it possible to limit the access for a user that has access to the management server, only to get view and/or access to dedicated firewalls that are present on the management server?
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Concerning what can be done in Dashboard: No, permissins are not that granular - see here how it can be restricted: https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Cont...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For access to the Security Gateway machine you can set individual Gaia administrators per machine with specific roles.
In Gaia Portal go to - User Management > Users or Roles
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The Multi-Domain Management is the sholution for this:
https://www.checkpoint.com/quantum/multi-domain-security-management/
Akos
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is not the solution - remember how expensive MDM licenses are, so if you need one SMS to manage your gateways, you will not pay x-times its price to get such options. I also do not know if this granular access does not only concern CMAs (as each CMA could have a different admin, a concept that makes sense).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
True, I had such kind of discussion with one of our customer. They didn't buy MDS....
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believe what @Tal_Paz-Fridman said also makes lots of sense to me. See attached.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
NO - the question is about granular admin rights on SMS by Dashboard (user that has access to the management server can only view and/or access dedicated firewalls on the management server), not about GAiA portal access on different gateways.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
thanks for the answers so far ...so it will not be so easy to archive
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Rather impossible - only by using one CMA per GW in MDM, which is very expensive...
Better use admins that are trustable and let them swear on the bible that they will only touch their GW in Dashboard 😉 As all actions are recorded, you can always trace who did what when on which rule or GW...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
:D:D ok that workaround is even better, we will do that 😉
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FWIW, here is what AI Copilot said, though to me, does not seem like it would work for you : - (
Andy
Yes, it is possible to limit the access for a user to only view and/or access dedicated firewalls on the management server. This can be achieved by creating specific permission profiles and assigning them to the user. Here are the steps to do this:
-
Create a Permission Profile:
- Open SmartConsole and go to the "Manage & Settings" tab.
- Under "Permissions & Administrators," select "Permission Profiles."
- Click "New" to create a new permission profile.
- Define the permissions for the profile. You can set the profile to allow only read access or specific access to certain features.
-
Assign the Permission Profile to the User:
- Go to "Manage & Settings" > "Permissions & Administrators" > "Administrators."
- Select the user you want to modify or create a new user.
- Assign the previously created permission profile to the user.
-
Limit Access to Specific Firewalls:
- In the same user settings, you can specify which firewalls (Security Gateways) the user has access to.
- Under the "Permissions" tab, you can define the specific objects (firewalls) the user can access.
By following these steps, you can ensure that the user has limited access to only view and/or manage specific firewalls on the management server.
- R81.10 Quantum Security Management Administration Guide - Managing-User-and-Administrator-Accounts
- R80.40 Security Management Administration Guide - Managing-User-and-Administrator-Accounts
- R77 Security Management Administration Guide - 41613
- R81.20 Quantum Security Management Administration Guide - Managing-User-and-Administrator-Accounts
- R81 Quantum Security Management Administration Guide - Managing-User-and-Administrator-Accounts
- R81.20 Identity Awareness Administration Guide - Acquiring-Identities-for-Active-Directory-Users
- R81.10 Identity Awareness Administration Guide - Acquiring-Identities-for-Active-Directory-Users
- R82 Identity Awareness Administration Guide - Acquiring-Identities-for-Active-Directory-Users
- Quantum Spark R80.20.10 Centrally Managed Administration Guide for 1500 Appliances - Working-User-Aw...
- Quantum Spark R80.20.15 Centrally Managed Administration Guide for 1500 Appliances - Working-User-Aw...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I was thinking maybe with below, but dont see an option for specific gateways though...
Andy
