ExtraHop 8.8 ExtraHop Trace Admin UI Guide
35
8. From the Privilege assignment options drop-down list, choose one of the following options:
•
Remote users have full write access
This option grants remote users full write access to the ExtraHop system. In addition, you can
grant additional access for packet downloads, SSL session keys, and detections.
•
Remote users have full read-only access
This option grants remote users read-only access to the ExtraHop system. In addition, you can
grant additional access for packet downloads, SSL session keys, and detections.
9. (Optional) Configure packet and session key access. Select one of the following options to allow
remote users to download packet captures and SSL session keys.
•
No access
•
Packets only
•
Packets and session keys
10. (Optional) Configure detections access. Select one of the following options to allow remote users
to view detections. This setting is visible only when the global privilege policy for detections access
control is set to
Only specified users can view detections
.
•
No access
•
Full access
11. Click
Save and Finish
.
12. Click
Done
.
Configure remote authentication through
The ExtraHop system supports Terminal Access Controller Access-Control System Plus () for
remote authentication and authorization.
Ensure that each user to be remotely authorized has the
ExtraHop service configured on the
before beginning this procedure.
1. Log in to the Administration settings on the ExtraHop system through
https://<extrahop-
hostname-or-IP-address>/admin
.
2. In the Access Settings section, click
Remote Authentication
.
3. From the Remote authentication method drop-down list, select
, and then click
Continue
.
4. On the Add Server page, type the following information:
• Host
:
The hostname or IP address of the server. Make sure that the DNS of the ExtraHop
system is properly configured if you are entering a hostname.
• Secret
:
The shared secret between the ExtraHop system and the server. Contact your
administrator to obtain the shared secret.
Note:
The secret cannot include the number sign (#).
• Timeout
:
The amount of time in seconds that the ExtraHop system waits for a response from the
server before attempting to connect again.
5. Click
Add Server
.
6. (Optional) Add additional servers as needed.
7. Click
Save and Finish
.
8. From the Permission assignment options drop-down list, choose one of the following options:
•
Obtain privileges level from remote server
This option allows remote users to obtain privilege levels from the remote server. You must also
configure permissions on the server.
•
Remote users have full write access
Содержание Trace Admin UI
Страница 1: ...ExtraHop 8 8 ExtraHop Trace Admin UI Guide...