Select
Device > Access Domain
or
Panorama > Access Domain
to specify
domains for administrator access to the firewall or Panorama. On the firewall, access domains are linked to RADIUS Vendor-Specific Attributes (VSAs) and are supported only if a RADIUS server is used for administrator authentication (see
Device > Server Profiles > RADIUS ). On Panorama, you can manage access domains locally or using RADIUS VSAs (see
Panorama > Access Domains ).
When an administrator attempts to log in to the firewall, the firewall queries the RADIUS server for the administrator’s access domain. If there is an associated domain on the RADIUS server, it is returned and the administrator is restricted to the defined virtual systems inside the named access domain on the firewall or Panorama. If RADIUS is not used, the access domain settings on this page are ignored.