cancel
Showing results for 
Search instead for 
Did you mean: 
Post a Question

True RBAC for management of policies and logs

Hello,

I am looking at how best to deploy RBAC to limit access to different parts of the security polices. It appears that the current CheckPoint implementation I have a good granularity controlling what an Admin Role can edit / update / create.

Is there a way to restrict access to read / view some information?

Ideally with RBAC I would like to be able to restrict what administrators can view. Our structure is to have a policy package for site site with security gateways.  The Central / Global IT team will have access to all policy packages and logs. Ideally the Local IT should have an admin role that only allows them to see policy package related to their site. At the moment it appears I cannot prevent them from seeing the policy packages for all sites.

In the ideal, ideal world the Local IT would only be able to access logs, events and reports for security gateways related to theirs site.

Is there any possibility of doing this within the RBAC offered by Checkpoint. Currently we are running R80.10. I do not know if there are nay changes within R80.20.

Many thanks,

Michael

Tags (1)
1 Reply
Admin
Admin

Re: True RBAC for management of policies and logs

The way you would accomplish this today is with Multi-Domain, with each site having their own domain.

Local admins could access their rules, objects, logs, etc, but not others.

Global admins would be able to access everything across domains.

Within a domain, you cannot currently restrict read permission.