Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Roadrunner88
Contributor

Possibility to limit User Access via Management Server

Hello Guys,

 

is it possible to limit the access for a user that has access to the management server, only to get view and/or access to dedicated firewalls that are present on the management server?

Thanks

0 Kudos
12 Replies
G_W_Albrecht
Legend Legend
Legend

Concerning what can be done in Dashboard: No, permissins are not that granular - see here how it can be restricted: https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Cont...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Tal_Paz-Fridman
Employee
Employee

For access to the Security Gateway machine you can set individual Gaia administrators per machine with specific roles.

In Gaia Portal go to - User Management > Users or Roles

AkosBakos
Leader Leader
Leader

Hi @Roadrunner88 

The Multi-Domain Management is the sholution for this:

https://www.checkpoint.com/quantum/multi-domain-security-management/

Akos

----------------
\m/_(>_<)_\m/
G_W_Albrecht
Legend Legend
Legend

This is not the solution - remember how expensive MDM licenses are, so if you need one SMS to manage your gateways, you will not pay x-times its price to get such options. I also do not know if this granular access does not only concern CMAs (as each CMA could have a different admin, a concept that makes sense).

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
AkosBakos
Leader Leader
Leader

True, I had such kind of discussion with one of our customer. They didn't buy MDS....

----------------
\m/_(>_<)_\m/
0 Kudos
the_rock
Legend
Legend

I believe what @Tal_Paz-Fridman said also makes lots of sense to me. See attached.

Andy

0 Kudos
G_W_Albrecht
Legend Legend
Legend

NO - the question is about granular admin rights on SMS by Dashboard (user that has access to the management server can only view and/or access dedicated firewalls on the management server), not about GAiA portal access on different gateways.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Roadrunner88
Contributor

thanks for the answers so far ...so it will not be so easy to archive

(1)
G_W_Albrecht
Legend Legend
Legend

Rather impossible - only by using one CMA per GW in MDM, which is very expensive...

Better use admins that are trustable and let them swear on the bible that they will only touch their GW in Dashboard 😉 As all actions are recorded, you can always trace who did what when on which rule or GW...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Roadrunner88
Contributor

:D:D ok that workaround is even better, we will do that 😉

0 Kudos
the_rock
Legend
Legend

@Roadrunner88 

FWIW, here is what AI Copilot said, though to me, does not seem like it would work for you : - (

Andy

 

is it possible to limit the access for a user that has access to the management server, only to get view and/or access to dedicated firewalls that are present on the management server?
09:41 AM

Yes, it is possible to limit the access for a user to only view and/or access dedicated firewalls on the management server. This can be achieved by creating specific permission profiles and assigning them to the user. Here are the steps to do this:

  1. Create a Permission Profile:

    • Open SmartConsole and go to the "Manage & Settings" tab.
    • Under "Permissions & Administrators," select "Permission Profiles."
    • Click "New" to create a new permission profile.
    • Define the permissions for the profile. You can set the profile to allow only read access or specific access to certain features.
  2. Assign the Permission Profile to the User:

    • Go to "Manage & Settings" > "Permissions & Administrators" > "Administrators."
    • Select the user you want to modify or create a new user.
    • Assign the previously created permission profile to the user.
  3. Limit Access to Specific Firewalls:

    • In the same user settings, you can specify which firewalls (Security Gateways) the user has access to.
    • Under the "Permissions" tab, you can define the specific objects (firewalls) the user can access.

By following these steps, you can ensure that the user has limited access to only view and/or manage specific firewalls on the management server.

0 Kudos
the_rock
Legend
Legend

I was thinking maybe with below, but dont see an option for specific gateways though...

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events