08-06-2012 05:58 AM - edited 03-10-2019 07:23 PM
Hi,
Can somebody show how to configure ACS 5.2 for device administration of Checkpoint firewalls and security management servers?
thanks
08-06-2012 08:20 AM
Hi,
I have created a "Authorization Profile" with a new "Shell Profile" policy.
In the policy i manualy entered this attributes:
Nokia-IPSO-SuperUser-Access=1
Nokia-IPSO-User-Role=adminRole
"adminRole" is a Checkpoint default role. You can create your own role and change these in your Shell Profile if needed.
The attribute are set to mandatory for this Shell Profile.
Regards
08-06-2012 08:48 AM
Hi Thomas,
Thanks for the reply, this is for firewall gateway running IPSO, but how about the Security management server for checkpoint?
regards,
Marlon
08-06-2012 10:20 AM
Hi Marlon,
we use TACACS only to authenticate user against our Security Management Server, but for authorization there is a local user configured which refers to the TACACS user.
If you use Provider-1, look at page 54.
In Cisco ACS, you configure an "Authorization Profile" and add only the Shell Profile "Permit Access"
Thomas
09-05-2012 06:22 AM
Hi Thomas,
Thanks for the reply, but i dont have enough privilege to access the link. will u able to share it?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide