<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Required role to do cli backups in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/348623#M86753</link>
    <description>&lt;P&gt;What about using a tool like CatTools to capture the output of 'show config running' ? The readonly permissions lets the user run this command.&lt;/P&gt;</description>
    <pubDate>Fri, 11 Sep 2020 16:12:11 GMT</pubDate>
    <dc:creator>MikeSangray2019</dc:creator>
    <dc:date>2020-09-11T16:12:11Z</dc:date>
    <item>
      <title>Required role to do cli backups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/348278#M86723</link>
      <description>&lt;P&gt;We have a process to do backups using the cli. I'm going to create a new role restricted to cli for this purpose. What admin role is required to perform backups?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2020 15:17:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/348278#M86723</guid>
      <dc:creator>MikeSangray2019</dc:creator>
      <dc:date>2020-09-10T15:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: Required role to do cli backups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/348445#M86733</link>
      <description>&lt;P&gt;from cli, the admin role would be deviceadmin.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried deviceadmin-readonly.. and naturally the choices are different&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as deviceadmin&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;testadmin@Cantwell-PA-220#&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;check Check configuration status&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;commit Commit current set of changes&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;copy Copy a statement&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;delete Delete a data element&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;edit Edit a sub-element&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;exit Exit from this level&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;find Find CLI commands with keyword&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;load Load configuration from disk&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;move Move a node within an ordered collection&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;override Override a template element&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;quit Quit from this level&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;rename Rename a statement&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;revert Revert changes from configuration&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;run Run an operational-mode command&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;save Save configuration to disk&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The deviceadmin-readonly does not offer the same choice:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;testadminro@Cantwell-PA-220#&lt;BR /&gt;check Check configuration status&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;edit Edit a sub-element&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;exit Exit from this level&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;find Find CLI commands with keyword&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;quit Quit from this level&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;run Run an operational-mode command&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;show Show a parameter&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;top Exit to top level of configuration&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;up Exit one level of configuration&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Just remember a deviceadmin from CLI can make whatever changes they want... they ARE a device admin, with full capabilities.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;There is NO ability to restrict an account to ONLY allow saves/backups individually.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 02:32:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/348445#M86733</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-09-11T02:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Required role to do cli backups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/348623#M86753</link>
      <description>&lt;P&gt;What about using a tool like CatTools to capture the output of 'show config running' ? The readonly permissions lets the user run this command.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 16:12:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/348623#M86753</guid>
      <dc:creator>MikeSangray2019</dc:creator>
      <dc:date>2020-09-11T16:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: Required role to do cli backups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/349056#M86791</link>
      <description>&lt;P&gt;Hi Mike&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From a RO account, there is the command "show config running" and the output is in xml format.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H6&gt;&lt;FONT face="courier new,courier"&gt;testadminro@Cantwell-PA-220&amp;gt; show config running&lt;/FONT&gt;&lt;/H6&gt;
&lt;H6&gt;&lt;FONT face="courier new,courier"&gt;config {&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/H6&gt;
&lt;H6&gt;&lt;FONT face="courier new,courier"&gt; preferences {&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;saved-log-query {&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;traffic {&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;h323 {&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;query "( addr.src in 172.17.13.13 ) and ( app neq dns ) and ( app neq dhcp ) and ( app neq ntp ) and ( receive_time geq '2019/01/14 16:59:32' )";&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;}&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;}&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;}&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;}&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;}&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;expedition {&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;permissions {&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;role-based {&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;superuser yes;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;}&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;}&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;phash ********;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;}&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;fred;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;testadmin {&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;permissions {&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;role-based {&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;custom {&lt;/FONT&gt;&lt;/H6&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;So, to summarize, there does not seem a good ability to load a config in "set" notation, but could export with 1000s of lines as XML.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Any other questions I can answer for you?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 12:45:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/349056#M86791</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-09-14T12:45:12Z</dc:date>
    </item>
    <item>
      <title>Re: Required role to do cli backups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/349430#M86854</link>
      <description>&lt;P&gt;What are you saying here? Are you saying that if the config is exported as XML that there is no ability to restore it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;So, to summarize, there does not seem a good ability to load a config in "set" notation, but could export with 1000s of lines as XML."&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 16:40:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/349430#M86854</guid>
      <dc:creator>MikeSangray2019</dc:creator>
      <dc:date>2020-09-15T16:40:08Z</dc:date>
    </item>
    <item>
      <title>Re: Required role to do cli backups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/349509#M86865</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124213"&gt;@MikeSangray2019&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I was suggesting is that config management is best done via the GUI vs from CLI.&lt;/P&gt;
&lt;P&gt;You can properly create a customized role to allow export/import of config file, using WebUI.&lt;/P&gt;
&lt;P&gt;But from CLI, you are very/extremely limited in permissions, hence very difficult, almost impossible, for config administration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 20:35:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/349509#M86865</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-09-15T20:35:10Z</dc:date>
    </item>
    <item>
      <title>Re: Required role to do cli backups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/349511#M86866</link>
      <description>&lt;P&gt;Do you know if the&amp;nbsp;&lt;SPAN&gt;output of 'show config running'&amp;nbsp;in an xml file can be used to restore the config?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 20:59:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/349511#M86866</guid>
      <dc:creator>MikeSangray2019</dc:creator>
      <dc:date>2020-09-15T20:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: Required role to do cli backups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/349547#M86868</link>
      <description>&lt;P&gt;Hi Mike.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think I should clarify my comments, as I would not want to mislead information here.&lt;/P&gt;
&lt;P&gt;The original request was that you wanted an admin-role from CLI that could do backups.&lt;/P&gt;
&lt;P&gt;My interpretation was that you ONLY wanted the person to do backups and not have any other access.&lt;/P&gt;
&lt;P&gt;That is not possible feasible to provide a RO account, with ability to export configs (or upload configs), whether that is a single line, or full config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is definitely possible to choose a CLI admin role of "device admin".&amp;nbsp; This will allow the user to do whatever they want from CLI, import/export, look at the config in "set" notation etc.&amp;nbsp; But it also comes with the ability to admin the entire firewall from CLI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, if you created a custom admin-role and remove all GUI privileges, then the person would not be able to log into the FW GUI to make changes.&amp;nbsp; On the flip side... by allowing them to be a device-admin from cli, allows them to manipulate the config to give them back permissions that were taken away from the GUI... well, see, that is not right either.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, as an engineer, what to do.&amp;nbsp; My recommendation is create a GUI role (not from cli) that has access only to the Operations Tab... as such.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SteveCantwell_0-1600209877994.png" style="width: 257px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27764iE1EADB3DA68688B0/image-dimensions/257x195?v=v2" width="257" height="195" role="button" title="SteveCantwell_0-1600209877994.png" alt="SteveCantwell_0-1600209877994.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Everything (like EVERYTHING is disabled, so when a admin logs in.. only choice they have is the menu options under Operations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does this help you out a little more...&amp;nbsp; Don't restrict yourself to CLI only.&amp;nbsp; Learn what the UI can do, and allow UI access.&lt;/P&gt;
&lt;P&gt;Much easier and you will keep your hair.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 22:48:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/349547#M86868</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-09-15T22:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: Required role to do cli backups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/350236#M86941</link>
      <description>&lt;P&gt;The GUI was a limiting factor in this scenario, but thanks for the information. We're after an automated solution, so maybe Panorama or API.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 21:24:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/350236#M86941</guid>
      <dc:creator>MikeSangray2019</dc:creator>
      <dc:date>2020-09-17T21:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: Required role to do cli backups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/350251#M86944</link>
      <description>&lt;P&gt;With API and a small script works perfectly&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 23:06:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/required-role-to-do-cli-backups/m-p/350251#M86944</guid>
      <dc:creator>Abdul-Fattah</dc:creator>
      <dc:date>2020-09-17T23:06:16Z</dc:date>
    </item>
  </channel>
</rss>

