CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-10
Member
 
Join Date: 2007-01-10
Posts: 35
Rep Power: 0
ppnair@gmail.com has an average reputation (10+)
Default How to restrict to Policy Push alone?

Hi Guys,

I would appreciate any inputs on this. I have to provide GUI access to operations folks on Fw-1 NGX R62 firewalls Smart Dashborad.

My question is: How can I restrict a user only allowed to push [Install] the policy. Read-only mode will not allow this, Read-write mode aloows everything which they have access to change rules, delete objects etc.

So from the operations perspective I am looking for a user access with only install policy.

Thanks in advance

Praveen

Last edited by ppnair@gmail.com; 2007-09-10 at 11:02. Reason: Change product R52 to R62
Reply With Quote
  #2 (permalink)  
Old 2007-09-10
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 247
Rep Power: 2
dantro has an average reputation (10+)
Default Re: How to restrict to Policy Push alone?

Create a permission read/write profile that matches your requirements as close as possible. Use this profile for the admin account in question.
Reply With Quote
  #3 (permalink)  
Old 2007-09-10
Junior Member
 
Join Date: 2006-07-26
Posts: 13
Rep Power: 0
dondma has an average reputation (10+)
Default Re: How to restrict to Policy Push alone?

Another possibility is that if the admin(s) have access to the enforcement module console, they can run a command to 'pull' the policy, thereby eliminating the need to access to Smart Dashboard. This is done using the 'fw fetch' command
Reply With Quote
  #4 (permalink)  
Old 2007-09-11
Senior Member
 
Join Date: 2007-07-16
Posts: 603
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: How to restrict to Policy Push alone?

I had a chat with CP Product Managers about this exact same issue at CPX. They are looking into an "Approver" and "Installer" role in the next version, although if they get more people asking for it they may accelerate this. I'd strongly suggest you submit this as an RFE so that they see the need.
Reply With Quote
  #5 (permalink)  
Old 2007-09-11
Member
 
Join Date: 2007-01-10
Posts: 35
Rep Power: 0
ppnair@gmail.com has an average reputation (10+)
Default Re: How to restrict to Policy Push alone?

Hi Dantro, Dondma and Thorpuse,

Appreciate your responses. As Thorpuse explained I should submit a RFE for this specific need. In my understanding there is no way to edit some config files or any other methods to restrict an user only to allow him to simply push the policy. With the read/write he can do everything; read-only he cannot push the policy. So I need something in between for operations.

Any other experts figured this out there? I would appreciate if any..

Thanks and Regards,

Praveen
I silently pray for our 9/11 victims and families. God Bless America !
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:41.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0