- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Re: Allow an Non-Admin to allow VPN user for speci...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Allow an Non-Admin to allow VPN user for specific time range
Hello all,
within an organisation some VPN users are for technicians outside the organisation. They are from
vendors to help in emergencies or to maintain the vendor machines. The requirement is to allow these
users in case of an emergency without to have call an firewall admin to allow the user in the policy.
At the moment I tend to solve this via management API and time objects, it seems for me the best solution.
To have a sub-layer and an admin account with less privileges was another thought. The user properties
looks not so flexible.
This requirement seems not to unusually, so how is this solved by others?
Regards,
Alex
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Within a layer you can allow a defined read-only admin user write access without needing the access to any other layer.
That said, you could build a webpage that would be allowed to update that layer with a single click, for instance telling it to allow the user in for the next hour.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If these are contractors another option may simply be to control this at the Active Directory level depending on the specifics?
- Group membership & Identity Rules
- Account Enabled or Disabled
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
external user directory this would be easy.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
With that the API user will have lower rights than using Time Objects, is that what you mean?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, that was also my thoughts. A webpage with own users and a "backend" wich has the Check Point API user.
At the moment my idea is to have time objects with tags. The tags helps to identify the time objects. The firewall
admin can build the rules needed and give the rules the time objects.
The non firewall user log into a webpage and sees only the time objects he could allow. A click and the time
object will be updated to allow the rule for some hours.
What would be the benefit of layers instead of time objects? At the moment I cannot use layers anyway. But I'm
always happy to hear opinions.
The requirement for such a scenario seems not to specific, perhaps there are other solutions which are I'm
not aware of.
Regards,
Alex
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The next rule will be a drop rule and the layer rule will be the exact allow rule with the proper src-dst and port.
