For those environments where different staff members require varied levels of access to the management interface, role-based administration allows any of the device features to be fully enabled, read-only, or disabled (hidden from view). Supported in both the individual device UI and Panorama, role-based administration allows specific individuals to be given appropriate access to the tasks that are pertinent to their job. Examples:
- Operations staff can have access to the device and networking configuration.
- Security administrators are given control over security policy definition, the log viewer and reporting.
- Key individuals are given full CLI access while for others, the CLI may be disabled.
All administrative activities are logged, showing the time of occurrence, the administrator, the management interface used (web UI, CLI, Panorama), the command or action taken along with the result.
|