<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CLI: create admin role in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cli-create-admin-role/m-p/449456#M100933</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/194079"&gt;@mlanterm&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just creating an admin-role is cli is easy:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;admin@PA-VM# set shared admin-role adminxdr role device webui&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, when you create your admin-role like this, all the roles will be disabled by default as opposed to when you create the admin-role through the GUI.&amp;nbsp; If you create an admin-role through the GUI, all the roles are enabled by default (which is kinda inconsistent ... maybe check with support if this is considered a bug or a feature request &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below is en example of a CLI created admin-role ... all the roles are disabled by default.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_0-1637848335108.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37803i7B0D446B9E23776C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiwi_0-1637848335108.png" alt="kiwi_0-1637848335108.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could create a script and copy/paste the bulk of lines by enabling scripting mode&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;username@hostname&amp;gt; set cli scripting-mode on&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kiwi&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Thu, 25 Nov 2021 14:05:38 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2021-11-25T14:05:38Z</dc:date>
    <item>
      <title>CLI: create admin role</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-create-admin-role/m-p/449090#M100895</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm struggling a bit to find an efficient way to create an admin role using the cli.&lt;/P&gt;&lt;P&gt;Let's say I want to create an admin role and grant it all rights that can be found in the "Web UI" tab when using the web interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a command that basically does this?&lt;/P&gt;&lt;PRE&gt;set shared admin-role webadmin role device webui ALL&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Right now the only way that I can see is a huge list of commands:&lt;/P&gt;&lt;PRE&gt;set shared admin-role webadmin role device webui acc&lt;BR /&gt;set shared admin-role webadmin role device webui dashboard&lt;BR /&gt;set shared admin-role webadmin role device webui monitor&lt;BR /&gt;set shared admin-role webadmin role device webui monitor logs&lt;BR /&gt;set shared admin-role webadmin role device webui monitor logs traffic enable&lt;BR /&gt;(repeat last line for all the items under logs)&lt;BR /&gt;(and for each and every other item in webui, it just keeps going...)&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;Maybe I'm overlooking something?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 15:05:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-create-admin-role/m-p/449090#M100895</guid>
      <dc:creator>mlanterm</dc:creator>
      <dc:date>2021-11-23T15:05:21Z</dc:date>
    </item>
    <item>
      <title>Re: CLI: create admin role</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-create-admin-role/m-p/449456#M100933</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/194079"&gt;@mlanterm&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just creating an admin-role is cli is easy:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;admin@PA-VM# set shared admin-role adminxdr role device webui&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, when you create your admin-role like this, all the roles will be disabled by default as opposed to when you create the admin-role through the GUI.&amp;nbsp; If you create an admin-role through the GUI, all the roles are enabled by default (which is kinda inconsistent ... maybe check with support if this is considered a bug or a feature request &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below is en example of a CLI created admin-role ... all the roles are disabled by default.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_0-1637848335108.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37803i7B0D446B9E23776C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiwi_0-1637848335108.png" alt="kiwi_0-1637848335108.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could create a script and copy/paste the bulk of lines by enabling scripting mode&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;username@hostname&amp;gt; set cli scripting-mode on&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kiwi&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 25 Nov 2021 14:05:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-create-admin-role/m-p/449456#M100933</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2021-11-25T14:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: CLI: create admin role</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-create-admin-role/m-p/449473#M100936</link>
      <description>&lt;P&gt;You can try the below link to get the best practice configuration from GitHub for both FW and Panorama.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/PaloAltoNetworks/iron-skillet/tree/panos_v10.0/loadable_configs/sample-set-commands" target="_blank"&gt;https://github.com/PaloAltoNetworks/iron-skillet/tree/panos_v10.0/loadable_configs/sample-set-commands&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2021 16:14:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-create-admin-role/m-p/449473#M100936</guid>
      <dc:creator>Mudhireddy</dc:creator>
      <dc:date>2021-11-25T16:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: CLI: create admin role</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-create-admin-role/m-p/509252#M106016</link>
      <description>&lt;P&gt;Did you find a way other than scripting 80+ lines to enable all?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2022 06:40:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-create-admin-role/m-p/509252#M106016</guid>
      <dc:creator>Tony.Vichai</dc:creator>
      <dc:date>2022-07-19T06:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: CLI: create admin role</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-create-admin-role/m-p/509254#M106017</link>
      <description>&lt;P&gt;No, I'm afraid not. We sort-of worked around it by using Radius with domain accounts, and gave up on separate types of admins. So we have the local admin account as a break-glass emergency account, and for daily use it's domain accounts where Radius sends the "superuser" attribute along. In this setup there's no need to define custom admin roles.&lt;/P&gt;
&lt;P&gt;Which is okay in our small team, where "yay everyone is a superuser" is "fine"...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I &lt;EM&gt;still&lt;/EM&gt; feel it's very counter-intuitive to script an admin role without wildcards and have it work the opposite way as the GUI.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2022 07:45:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-create-admin-role/m-p/509254#M106017</guid>
      <dc:creator>mlanterm</dc:creator>
      <dc:date>2022-07-19T07:45:12Z</dc:date>
    </item>
  </channel>
</rss>

