<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom Admin Template Examples for GP Admin and Network Engineer? in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/custom-admin-template-examples-for-gp-admin-and-network-engineer/m-p/441571#M484</link>
    <description>&lt;P&gt;Thank you for posting question&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/2857"&gt;@PeterT&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe that Access Domain together with Custom Admin Roles can give you that level of granularity you are looking for.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would suggest to go to: Panorama &amp;gt; Access Domain &amp;gt; Add new Access Domain&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then select Template where all Global Protest is configured, limit Device Context to Firewalls where Global Protect configuration is pushed. Below is an example:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1634559483749.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37058i37C3B2784D5B26AD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_0-1634559483749.png" alt="PavelK_0-1634559483749.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then navigate to Panorama &amp;gt; Admin Roles &amp;gt; Add new Admin Role and limit Device Group &amp;amp; Template only to Global Protect configuration. Below is an example:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_6-1634560634099.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37064i9895E76A6D7D7B4E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_6-1634560634099.png" alt="PavelK_6-1634560634099.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then link Global Protest Access Domain and Admin Role together in the account. Below is an example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_5-1634560592759.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37063iD405A0BCB722CD08/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_5-1634560592759.png" alt="PavelK_5-1634560592759.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once the admin assigned to Global Protect role logs is, he will be able to see and manage only corresponding configuration:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_3-1634560105205.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37061i401F8424948027E6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_3-1634560105205.png" alt="PavelK_3-1634560105205.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Exactly the same configuration can be replicated for Network Administrator role by changing setting in Access Domain and under Admin Role.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
    <pubDate>Mon, 18 Oct 2021 12:39:44 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2021-10-18T12:39:44Z</dc:date>
    <item>
      <title>Custom Admin Template Examples for GP Admin and Network Engineer?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/custom-admin-template-examples-for-gp-admin-and-network-engineer/m-p/440668#M478</link>
      <description>&lt;P&gt;So recently we (as in voluntold lol) decided to get rid of our dedicated Cisco L3 devices and move the L1 (VMWire) only FW's into L3 as a "cost saving measure".&amp;nbsp; Won't get into how much I hate this but the decision has been made. Also this entire thing is managed via Panorama so don't need "do local FW overrides of templates".&amp;nbsp; Also virtual systems not an option in many cases as the majority are low end small site models (i.e. 800's and down) hence don't need to get into "spin up a virtual system and control it that way" discussions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyways anybody have a config snippet they want to share for setting up the following two custom admin roles?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) GP Admin - Needs access to the FW running GP (not all of them, just one), the ability to configure it all, maintain it, etc (via Panorama templates) but NOT anything else in Panorama or the FW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) Ditto but Network Engineer - I.e. needs access to the virtual routers, L2/L3 configs, interface configs, routing tables, etc but not stuff like admin database, authentication setup, security policy or objects, etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The built-in rolls are ill equipped for this and I know how do do via effective superuser via Device Templates/Admin a per FW / virtual system level but I'm looking for more fine tuned than that i.e. "Just every function GP needs and nothing more" or "Every function a network engineer would need to treat the PA like a L3 device but nothing more"&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 23:31:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/custom-admin-template-examples-for-gp-admin-and-network-engineer/m-p/440668#M478</guid>
      <dc:creator>PeterT</dc:creator>
      <dc:date>2021-10-13T23:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Admin Template Examples for GP Admin and Network Engineer?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/custom-admin-template-examples-for-gp-admin-and-network-engineer/m-p/441571#M484</link>
      <description>&lt;P&gt;Thank you for posting question&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/2857"&gt;@PeterT&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe that Access Domain together with Custom Admin Roles can give you that level of granularity you are looking for.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would suggest to go to: Panorama &amp;gt; Access Domain &amp;gt; Add new Access Domain&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then select Template where all Global Protest is configured, limit Device Context to Firewalls where Global Protect configuration is pushed. Below is an example:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1634559483749.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37058i37C3B2784D5B26AD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_0-1634559483749.png" alt="PavelK_0-1634559483749.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then navigate to Panorama &amp;gt; Admin Roles &amp;gt; Add new Admin Role and limit Device Group &amp;amp; Template only to Global Protect configuration. Below is an example:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_6-1634560634099.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37064i9895E76A6D7D7B4E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_6-1634560634099.png" alt="PavelK_6-1634560634099.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then link Global Protest Access Domain and Admin Role together in the account. Below is an example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_5-1634560592759.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37063iD405A0BCB722CD08/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_5-1634560592759.png" alt="PavelK_5-1634560592759.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once the admin assigned to Global Protect role logs is, he will be able to see and manage only corresponding configuration:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_3-1634560105205.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37061i401F8424948027E6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_3-1634560105205.png" alt="PavelK_3-1634560105205.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Exactly the same configuration can be replicated for Network Administrator role by changing setting in Access Domain and under Admin Role.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2021 12:39:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/custom-admin-template-examples-for-gp-admin-and-network-engineer/m-p/441571#M484</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-10-18T12:39:44Z</dc:date>
    </item>
  </channel>
</rss>

