10.07.2015 Views

Provider-1/SiteManager-1 - Check Point

Provider-1/SiteManager-1 - Check Point

Provider-1/SiteManager-1 - Check Point

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Administrators(administrators) with different access rights. It enables trusted communication bothwithin the <strong>Provider</strong>-1/<strong>SiteManager</strong>-1 network, and with customers’ networkenvironments.AdministratorsIt is important, for security purposes, that there be different types of administrativeauthority. Administrators with authority over the entire system are needed in order tomanage the entire <strong>Provider</strong>-1/<strong>SiteManager</strong>-1 system. But there also must be a level ofadministration authority which only applies to the customer environment and not tothe <strong>Provider</strong>-1/<strong>SiteManager</strong>-1 system.It is not appropriate for an administrator who remotely manages a VPN-1 Pro gatewayin a particular customer network, to be able to have authority over the entire<strong>Provider</strong>-1 system. This could be a serious security breach, as a customer’s internal staffwould have access to other customer networks. For an MSP which handles numerouscustomers, it would not be appropriate for a particular customer administrator who isnot familiar with the entire system to, say, have the authority to shut down an MDSManager and delete all the superusers from the system.In the <strong>Provider</strong>-1/<strong>SiteManager</strong>-1 environment, four types of administrators have beendesignated to handle different levels of responsibility. While there needs to beadministrators who have the authority to create and manage the entire<strong>Provider</strong>-1/<strong>SiteManager</strong>-1 environment, not every administrator in the system has thislevel of complete control.Chapter 1 Introduction 27

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!