Skip to content

Administrator access to firewall features

Device access profiles use role-based access control to determine which firewall features administrators can view and manage. For each feature, you can assign an access level of None, Read-only, or Read-write, allowing administrators to perform only the tasks required for their role.

Learn about the firewall features you can include in a device access profile.

Monitoring and troubleshooting

For administrators to monitor and troubleshoot the firewall services, assign the required access level for the following features:

  • Control center
  • Logs and reports

    • LogSettings
    • LogViewer
    • Reports
    • Data anonymization
    • Deanonymization
  • Live connections

  • Identity configurations

    • Live users
  • System configurations

    • Diagnostics

System configurations

For administrators to manage system-level settings and maintenance tasks, assign the required access level for the following features:

  • Access profile
  • Default admin password
  • Backup
  • Restore backup
  • Firmware management
  • Licensing
  • Service management
  • Pattern updates
  • Reboot and shutdown
  • High availability
  • Download certificates
  • Certificate management
  • System configurations

Rules, policies, and threat protection

For administrators to manage rules, policies, and threat protection settings, assign the required access level for the following features:

  • Firewall, NAT, and SSL/TLS inspection rules, Active threat response

    • Firewall rules
    • NAT rules
    • SSL/TLS inspection rules
    • Active threat response
  • WAF and web server configurations

    • WAF rules
    • Web servers
  • Intrusion prevention

  • Zero-day protection

Protection modules

For administrators to manage protection modules, assign the required access level for the following features:

  • Wireless protection

    • Wireless client list
    • Wireless settings
    • Wireless networks
    • Access points
    • Mesh networks
  • Web

  • Cloud applications
  • Application policies
  • Email

Routing and connectivity

For administrators to manage routing and connectivity, assign the required access level for the following features:

  • Network and routing

    • Network
    • Routing
  • VPN

    • VPN tunnel management
    • VPN configurations

Identity configurations

For administrators to manage authentication and related configurations, assign the required access level for the following features:

  • Authentication configurations
  • User groups
  • Users
  • Administrators
  • Guest users
  • Guest user settings
  • Access time and Traffic quota

Objects and QoS

For administrators to manage objects, including IP, MAC, and FQDN hosts, services, and QoS policies, assign the required access level for the following features:

  • Address and service objects
  • Traffic shaping policies