Access control to the web management console for the realm is implemented by creating additional realm administrator accounts and assigning them access profiles.
To create additional realm administrator accounts, follow these steps:
Name |
Description |
---|---|
Step 1. Log in to the web management console as the root realm administrator. |
Log in to the management console as the root realm administrator created for this realm by entering the login name as administrator_login/realm_code, e.g., Admin/UG. |
Step 2. Create a realm administrator access profile. |
In the Administrators ➜ Administrator profiles section of the realm management console, click Add and provide the desired settings. |
Step 3. Create an administrator account and assign it one of the administrator profiles created earlier. |
In the Administrators section, click Add and select the desired option.
|
When creating an administrator access profile, specify the following parameters:
Name |
Description |
---|---|
Name |
Profile name. |
Description |
Profile description. |
Realm access permissions |
Set permissions to the settings sections of the realm, such as administrators, auth servers, device templates, template groups, managed devices, and logs and reports. The following access options are available:
|
Template access permissions |
Set the rights to view and/or modify the settings for all or specific existing templates here. The settings are presented as UserGate NGFW console tree objects available for delegation. The following access options are available:
For example, you can allow access to network settings for one administrator group and NGFW policies for another. |