I'm using a user with read only permissions. User can login to GUI but fails to use the REST api via browser.
Is there a problem for such users to use the api?
Is the admin a superuser or a device or vsys admin? As of PAN-OS 4.1, the API only supports superuser admins only.
I think I might be suffering from the same issue the REST API Doc says the following. "The API is available to Superuser and Superuser (readonly) administrators from PAN-OS 4.1.0;" This suggest to me that the superuser (readonly) account should get access to commands exposed via the API.
However if i try to run say https://<firewall>/api/?type=op&cmd=<show><arp>all</arp></show>&key=<keyvalue> i get invalid credentials yet the CLI for PAN OS 4.1 document suggest that the follwing user account types should be able to run this command "superuser, vsysadmin, deviceadmin, superreader, vsysreader"
I would rather not have to use a full admin account to get access to simple show commands for the device anybody have any ideas.
PAN-OS 4.1.3 resolved an issue where a superuser-readonly admin account was not able to run Operational commands with the API.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!