<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama - Restrict Firewall Log Access in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-restrict-firewall-log-access/m-p/4026#M2974</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If by subdomains, do you mean how to restrict access for the admins to see logs on&amp;nbsp; the firewalls in a specific device groups? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer the below document, that explains how to restrict manageable firewall access to admins&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-3106"&gt;https://live.paloaltonetworks.com/docs/DOC-3106&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can restrict access to a device groups or to individual firewalls themselves. The doc shows device groups. The below snapshot shows restricting the admin to firewalls.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="panorama access.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7659_panorama access.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can then select an admin role profile, and limit the access to only the logs as shown below:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="panorama access-2.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7660_panorama access-2.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And use this admin role profile under the admin.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 Aug 2013 12:39:39 GMT</pubDate>
    <dc:creator>kprakash</dc:creator>
    <dc:date>2013-08-13T12:39:39Z</dc:date>
    <item>
      <title>Panorama - Restrict Firewall Log Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-restrict-firewall-log-access/m-p/4025#M2973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anyone know if there is a way to create admins in Panorama for specific subdomains AND restrict their access to only the logs for the firewalls in that subdomain? I want to give access to users for only their FW logs and not let them see all of the other FW logs. So far my testing has resulted in this not being possible, but wanted to see if anyone figured out a way that i just missed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Aug 2013 12:14:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-restrict-firewall-log-access/m-p/4025#M2973</guid>
      <dc:creator>chrisp</dc:creator>
      <dc:date>2013-08-13T12:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama - Restrict Firewall Log Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-restrict-firewall-log-access/m-p/4026#M2974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If by subdomains, do you mean how to restrict access for the admins to see logs on&amp;nbsp; the firewalls in a specific device groups? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer the below document, that explains how to restrict manageable firewall access to admins&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-3106"&gt;https://live.paloaltonetworks.com/docs/DOC-3106&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can restrict access to a device groups or to individual firewalls themselves. The doc shows device groups. The below snapshot shows restricting the admin to firewalls.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="panorama access.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7659_panorama access.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can then select an admin role profile, and limit the access to only the logs as shown below:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="panorama access-2.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7660_panorama access-2.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And use this admin role profile under the admin.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Aug 2013 12:39:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-restrict-firewall-log-access/m-p/4026#M2974</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-13T12:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama - Restrict Firewall Log Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-restrict-firewall-log-access/m-p/4027#M2975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This will work if you want to restrict log access when context switch occurs while the admin is logged in locally to a device though Panorama.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other request to restrict access without a context switch while inside the Panorama Monitor tab is a current feature request. We are tracking this request as we move forward to plan future releases. Please follow up with your SE to add to the FR if you have not already.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Aug 2013 15:08:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-restrict-firewall-log-access/m-p/4027#M2975</guid>
      <dc:creator>mschuricht</dc:creator>
      <dc:date>2013-08-13T15:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama - Restrict Firewall Log Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-restrict-firewall-log-access/m-p/4028#M2976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your last comments regarding Panorama Monitor tab (not contect switching) are exactly where i was going with my question. I don't believe we have submitted that request, but I will now. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; Thanks for the reply.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Aug 2013 15:14:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-restrict-firewall-log-access/m-p/4028#M2976</guid>
      <dc:creator>chrisp</dc:creator>
      <dc:date>2013-08-13T15:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama - Restrict Firewall Log Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-restrict-firewall-log-access/m-p/4029#M2977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If for you sub domain is device group, previous answer are ok but if per device you can have many domain, you have to go through custom report. With query, if users are authenticated or maybe per subnet, you can create the right report for the right person &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Aug 2013 15:35:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-restrict-firewall-log-access/m-p/4029#M2977</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-08-13T15:35:07Z</dc:date>
    </item>
  </channel>
</rss>

