Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
JP_Rex
Collaborator
Collaborator
Jump to solution

R81.20 SmartView Web Application no SSO?

Hello,

if you open

https://<Management Server IP address>/smartconsole

you can use the configured IdP for the Admin access.

for 

https://<IP Address of Management Server>/smartview/

 

it you can not.

 

Any thoughts on why?

 

Regards

 

Peter

 

2 Solutions

Accepted Solutions
PhoneBoy
Admin
Admin

That is expected behavior last I checked.
Also, I believe the Web SmartConsole effectively includes SmartView functionality.

View solution in original post

0 Kudos
Tomer_Noy
Employee
Employee

We've embedded the SmartView functionality into the Web SmartConsole, and we encourage customers to use it. It contains a lot of additional functionality on top of the /smartview web application, and this is where we direct a lot of our investment.

We do not currently plan to add SSO login to the /smartview app.

View solution in original post

0 Kudos
11 Replies
PhoneBoy
Admin
Admin

That is expected behavior last I checked.
Also, I believe the Web SmartConsole effectively includes SmartView functionality.

0 Kudos
JP_Rex
Collaborator
Collaborator

Have you heard any rumors if it will be implemented, Or will the SmartView Web Application be ditched for web SmartConsole?

Regards

 

Peter

0 Kudos
the_rock
Legend
Legend
0 Kudos
JP_Rex
Collaborator
Collaborator

I will check myself in 2 weeks. Someone will be over from Israel to get our EA running.

Regards

Peter

0 Kudos
the_rock
Legend
Legend

Sounds good, they would know for sure 🙂

Andy

0 Kudos
PhoneBoy
Admin
Admin

@Tomer_Noy any plan to implement SAML auth for SmartView?

0 Kudos
Tomer_Noy
Employee
Employee

We've embedded the SmartView functionality into the Web SmartConsole, and we encourage customers to use it. It contains a lot of additional functionality on top of the /smartview web application, and this is where we direct a lot of our investment.

We do not currently plan to add SSO login to the /smartview app.

0 Kudos
Tobi
Participant
Participant

Are there any plans to restrict the appereance  of specific menus in the web smartconsole? We have users that only need access to the firewall logs for which smartview is perfect. If we want use SAML they need to use the web smartconsole, but even if they have permissions only for the log view, they can see all gateways, policies and objects. It would be great if SSO login would be implemented to the smartview app or if there are a possibility to restrict the web smartconsole appereance that they only see the Logs & Monitor menu. 

Is this something that is on the roadmap?

PhoneBoy
Admin
Admin

What's available via Web SmartConsole is a function of the permissions profile you assign to the user.
I created a "Logs only" user with an appropriate permission profile and this is the extent of what I can see in the policy (at least in R82 EA):

image.png

Note that you cannot disable access to the Objects, but they are Read Only and, arguably, necessary to review the logs.

0 Kudos
Tobi
Participant
Participant

If I click on the plus I can also see all the available policies which is not necessary in my opinion. In addition if you go to Gateways & Servers I can see all gateways and have read access to the information which I also don't need for a logs only user. So the best thing would be to grey out Gateway & Servers and Security Policies. In my opinion a logs only user just need access to the Logs & Event section. We use R81.20.

0 Kudos
PhoneBoy
Admin
Admin

The idea of a pre-defined "logs only" admin user would likely require some additional efforts beyond how it displays in Web SmartConsole.
This is very likely an RFE.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events