Restricting folder administrators' access privileges

SMC can segment the administration of your firewall pool by assigning different administrators to separate firewall groups. To do so, you can restrict an administrator's write access to a firewall group, based on the folder tree available in SMC. By segmenting administration, a perimeter can be defined for each administrator, thereby increasing security on your firewall pool.

EXAMPLE
If your firewall pool extends across several countries or continents, you can choose to assign a different administrator for each country or continent. Individual administrators can then manage only firewalls in the folder corresponding to their zone. They can also look up the configuration of other firewalls and of the SMC server in read-only mode.

Only the super administrator can restrict other administrators' write access privileges to certain folders.

The super administrator can then define two administrator profiles that hold write access privileges:

General administrator
  • Holds write access privileges to the root SMC folder, meaning all sub-folders, and therefore all SNS firewalls.

  • Can change the configuration of all SNS firewalls connected to SMC.

  • Can create and change all configuration items found in SMC (objects, rules, VPN topologies, QoS, certificates, encryption profiles, etc.).

  • Can perform certain maintenance operations on the SMC server.

Folder administrator
  • Write access privileges are restricted to one or several folders, and to the firewalls contained in them.

  • Can change only the configuration on firewalls that they manage.

  • Can create configuration items and use them for firewalls that they manage.

  • Can create VPN topologies only with the firewalls that they manage.

  • Can directly access the interface of firewalls that they manage via SMC in read/write.

  • Can access in read-only mode the configuration of firewalls outside their administration perimeter, all configuration items found in SMC, and the configuration of the SMC server.

  • Can directly access the interface of firewalls outside their administration perimeter via SMC, but in read-only mode.

For more details on administrator profiles, as well as the implications and limitations of restricting access privileges to folders, refer to the section Managing administrators from local and external directories and the sections below.