Appliance Configuration
Check Point 1400 Appliances Centrally Managed Administration Guide R77.20.85 | 97
To edit a user or group:
1.
Select the user or group from the list.
2.
Click
Edit
.
3.
Make the relevant changes and click
Apply
.
To delete a user or group:
1.
Select the user or group from the list.
2.
Click
Delete
.
3.
Click
OK
in the confirmation message.
The user or group is deleted.
Identity Awareness
In the
Users & Objects
>
User Awareness
page, you can turn on User Awareness if your centrally
managed Security Management Server is configured to work with User Awareness.
User Awareness lets you configure the Firewall to enforce access control individual users and
groups. You can use Identity Sources to get information about users and groups to create
flexibility and additional security for the Rule Base. Identity Awareness lets you create rules that
are for the specified users for these Rule Bases:
•
Firewall
•
URL Filtering and Application Control
•
Anti-Bot
Configuring Local and Remote System Administrators
The
Device
>
Administrators
page lists the Check Point Appliance administrators and lets you:
•
Create new local administrators
•
Configure the session timeout
•
Limit login failure attempts
Administrators can also be defined in a remote RADIUS server and you can configure the
appliance to allow them access. Authentication of those remotely defined administrators is done
by the same RADIUS server.
Administrator Roles:
•
Super Administrator
- All permissions. Super Administrators can create new locally defined
administrators and change permissions for others.
•
Read Only Administrator
- Limited permissions. Read Only Administrators cannot update
appliance configuration but can change their own passwords or run a traffic monitoring report
from the Tools page.
•
Networking Administrator
- Limited permissions. Networking Administrators can update or
modify operating system settings. They can select a service or network object but cannot
create or modify it.
Two administrators with write permissions cannot log in at the same time. If an administrator is
already logged in, a message shows. You can choose to log in with Read-Only permission or to
continue. If you continue the login process, the first administrator session ends automatically.
Содержание L-71
Страница 122: ......