Enable Role Based Access for Advanced IP Defense on Panorama
Focus
Focus
Advanced IP Defense

Enable Role Based Access for Advanced IP Defense on Panorama

Table of Contents


Enable Role Based Access for Advanced IP Defense on Panorama

Configure an admin role on Panorama® management server to control access to Advanced IP Defense features pushed to managed devices.
Role-based access on Panorama® management server operates at two levels: the Panorama admin role controls access to Advanced IP Defense configuration pushed to managed devices, and the NGFW admin role controls access directly on each managed NGFW web interface.
  1. Log in to the Panorama web interface.
  2. Configure the Panorama admin role.
    This controls the Panorama administrator access privileges to the Advanced IP Defense profile configuration pushed to managed devices.
    1. Select PanoramaAdmin Roles.
    2. Add a new admin role or select an existing role to modify.
    3. In the Web UIObjectsSecurity Profiles admin role privileges, configure the Advanced IP Defense access privileges.
      The Advanced IP Defense permissions control access to profile configuration, zone attachment, and threat log visibility. Set each permission to Enable, Read Only, or Disable based on the level of access required for the administrator.
    4. Click OK to save the admin role.
  3. Select PanoramaAdministrators and assign the admin role to the appropriate administrator accounts.
  4. Configure the NGFW admin role.
    This controls the access privileges to the Advanced IP Defense profile configuration an administrator has directly on the NGFW web interface.
    1. Select DeviceAdmin Roles and select the Template that your managed devices using Advanced IP Defense belong to.
    2. Add a new admin role or select an existing role to modify.
    3. In the Web UIObjectsSecurity Profiles admin role privileges, configure the Advanced IP Defense access privileges.
      The Advanced IP Defense permissions control access to profile configuration, zone attachment, and threat log visibility. Set each permission to Enable, Read Only, or Disable based on the level of access required for the administrator.
    4. Click OK to save the admin role.
  5. Select DeviceAdministrators and select the Template that your managed devices using Advanced IP Defense belong to, then assign the admin role to the appropriate administrator accounts.
  6. Select CommitCommit and Push to commit changes to Panorama and push them to managed devices.