74
•
Panorama
6.1
Administrator’s
Guide
©
Palo
Alto
Networks,
Inc.
Set
Up
Administrative
Access
to
Panorama
Set
Up
Panorama
Create
an
Administrative
Account:
Local
Account/Authentication
Step
1
Create
an
Admin
Role
profile.
This
step
is
only
required
if
using
custom
roles
instead
of
using
the
built
‐
in
Dynamic
Roles
available
on
Panorama.
Complete
the
following
steps
for
each
role
you
want
to
create:
1.
Select
Panorama > Admin Roles
and
then
click
Add
.
2.
Select
Panorama
or
Device Group and Template
to
define
the
scope
of
administrative
privileges
to
assign.
The
access
privileges
defined
for
Panorama
are
enforced
when
the
administrator
logs
in
to
Panorama;
the
Device
Group
and
Template
role
enforces
read
‐
only
access
to
the
Managed
Devices,
Templates,
and
Device
Groups
nodes
on
the
Panorama
tab.
Access
to
all
other
tabs
can
be
modified
as
required.
Read
‐
only
access
to
the
Device
Groups
and/or
Templates
node(s)
must
be
provided
for
a
role
‐
based
administrator
to
commit
device
groups
and/or
template
changes
to
the
managed
firewalls.
3.
For
the
Web UI
and
/or
XML API
tabs,
set
the
access
levels
for
each
functional
area
of
the
interface
by
clicking
the
adjacent
icon
to
toggle
it
to
the
desired
setting
(Enable,
Read
Only,
or
Disable):
•
For
Panorama
access,
define
access
to
the
Web UI
,
XML
API
,
and
Command Line
.
The
Command Line
tab
does
not
allow
granular
access.
You
must
select
a
predefined
option:
superuser, superreader, Panorama-admin
or
None
.
•
For
access
to
firewalls
(Device
Group
and
Template),
only
one
tab
is
available:
Web UI.
From
Panorama,
you
cannot
enable
access
to
the
CLI
or
XML
API
on
a
firewall
because
no
predefined
roles
restrict
access.
Therefore,
to
prevent
privilege
‐
level
escalation,
the
ability
to
manage
access
to
the
CLI
and
XML
API
is
not
available
from
Panorama.
4.
Enter
a
Name
for
the
profile
and
then
click
OK
to
save
it.
Step
2
(Optional)
Set
requirements
for
local
user
‐
defined
passwords.
•
Create
Password
Profiles
—Define
how
often
administrators
must
change
their
passwords.
Create
multiple
password
profiles
and
apply
them
to
administrator
accounts
as
required
to
enforce
security.
To
create
a
password
profile,
select
Panorama >
Password Profiles
and
then
click
Add
.
•
Configure
minimum
password
complexity
settings
—Define
rules
that
govern
password
complexity,
which
forces
administrators
to
create
passwords
that
are
harder
to
guess,
crack,
or
compromise.
Unlike
password
profiles,
which
can
be
applied
to
individual
accounts,
these
rules
are
firewall
‐
wide
and
apply
to
all
passwords.
To
configure
the
settings,
select
Panorama > Setup
and
edit
the
Minimum
Password
Complexity.