<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Prevent same admin user making configuration change from different places (Web &amp;amp; CLI) at same time in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-same-admin-user-making-configuration-change-from/m-p/183597#M56410</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know is there any way to prevent same admin user (say devAdmin) making configuration change from different places (Web &amp;amp; CLI) at same time?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anthony Cheung&lt;/P&gt;</description>
    <pubDate>Wed, 25 Oct 2017 09:07:17 GMT</pubDate>
    <dc:creator>anthony_cheung</dc:creator>
    <dc:date>2017-10-25T09:07:17Z</dc:date>
    <item>
      <title>Prevent same admin user making configuration change from different places (Web &amp; CLI) at same time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-same-admin-user-making-configuration-change-from/m-p/183597#M56410</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know is there any way to prevent same admin user (say devAdmin) making configuration change from different places (Web &amp;amp; CLI) at same time?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anthony Cheung&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2017 09:07:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-same-admin-user-making-configuration-change-from/m-p/183597#M56410</guid>
      <dc:creator>anthony_cheung</dc:creator>
      <dc:date>2017-10-25T09:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent same admin user making configuration change from different places (Web &amp; CLI) at sam</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-same-admin-user-making-configuration-change-from/m-p/183749#M56438</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Yes the feature is called a commit lock. Its under the Device -&amp;gt; Setup -&amp;gt; Management -&amp;gt; General Settings. Click the sprocket and then check the box for "&lt;EM&gt;Automatically Acquire Commit Lock".&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So once someone makes a setting change it locks the config until that person releases, commits it, or someone else releases it (if you allow for that).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2017 21:57:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-same-admin-user-making-configuration-change-from/m-p/183749#M56438</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-10-25T21:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent same admin user making configuration change from different places (Web &amp; CLI) at sam</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-same-admin-user-making-configuration-change-from/m-p/183752#M56439</link>
      <description>&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/firewall-administration/use-the-web-interface/manage-locks-for-restricting-configuration-changes" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/firewall-administration/use-the-web-interface/manage-locks-for-restricting-configuration-changes&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2017 22:09:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-same-admin-user-making-configuration-change-from/m-p/183752#M56439</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-10-25T22:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent same admin user making configuration change from different places (Web &amp; CLI) at sam</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-same-admin-user-making-configuration-change-from/m-p/183790#M56444</link>
      <description>&lt;P&gt;Thanks for your reply. I have tried commit lock but it seems not work for my case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My case is "same admin user using different methods at the same time". For example, I have an admin user which username is "adminA". I log in Web interface with "adminA" and at the same time "adminA" is logged in CLI. In this situation, if commit lock is acquired on CLI, I cannot acquire the lock in Web interface becuse "adminA" has acquired the lock. Nevertheless, "adminA" on Web interface can commit configuration changes even the changes are made in CLI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any way to resolve this situation?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 02:29:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-same-admin-user-making-configuration-change-from/m-p/183790#M56444</guid>
      <dc:creator>anthony_cheung</dc:creator>
      <dc:date>2017-10-26T02:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent same admin user making configuration change from different places (Web &amp; CLI) at sam</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-same-admin-user-making-configuration-change-from/m-p/184024#M56476</link>
      <description>&lt;P&gt;Hmm, interesting. That may be a TAC case.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 22:12:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-same-admin-user-making-configuration-change-from/m-p/184024#M56476</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-10-26T22:12:59Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent same admin user making configuration change from different places (Web &amp; CLI) at sam</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-same-admin-user-making-configuration-change-from/m-p/184028#M56477</link>
      <description>&lt;P&gt;In this instance, a case would not get a resolution. A feature request is needed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's an odd use case: if the same user is making changes in CLI and different changes in the GUI, that user should know that because it's the same user. I don't understand why you would want to prevent a user from administering the firewall in such a way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75886"&gt;@anthony_cheung&lt;/a&gt;, is your use case something you can expand on here? Why is this a problem?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 22:19:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-same-admin-user-making-configuration-change-from/m-p/184028#M56477</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2017-10-26T22:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent same admin user making configuration change from different places (Web &amp; CLI) at sam</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-same-admin-user-making-configuration-change-from/m-p/184365#M56551</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28203"&gt;@gwesson&lt;/a&gt;, actually, I would like to use CLI and some shell script programming to do automatic password management task (e.g. periodic changing password). Nevertheless,&amp;nbsp;I cannot find a way to block the actual admin user from logging in Web interface to do any other configuration jobs. That's why I raise the question.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 01:18:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-same-admin-user-making-configuration-change-from/m-p/184365#M56551</guid>
      <dc:creator>anthony_cheung</dc:creator>
      <dc:date>2017-10-30T01:18:11Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent same admin user making configuration change from different places (Web &amp; CLI) at sam</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-same-admin-user-making-configuration-change-from/m-p/184519#M56584</link>
      <description>&lt;P&gt;I understand the use case, thanks for that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The simplest thing would be to create an Admin Role that blocks all Web UI sections and allows superuser for CLI.&amp;nbsp;Then create an Administrator and assign the admin role you created to that administrator.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That user would only have access to the CLI, though you may want to make it have access to XML API to take full advantage of it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your existing AdminA user would still have full access to CLI and UI, but because it's a different user name the config lock would work as provided by&amp;nbsp;Otakar.Klier.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 16:25:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-same-admin-user-making-configuration-change-from/m-p/184519#M56584</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2017-10-30T16:25:56Z</dc:date>
    </item>
  </channel>
</rss>

