Configuring Local and Remote System Administrators
Quantum Spark 1500, 1600, and 1800 Appliances R81.10.X Locally Managed Administration Guide|110
Configuring Local and Remote System
Administrators
The Device > Administrators page lists the appliance administrators. Here you can:
n
Create new local administrators.
n
Configure the session timeout.
n
Limit login failure attempts.
n
Generate a QR code to connect the mobile application with the appliance for the first time.
Administrators can also be defined in a remote RADIUS server and you can configure the appliance to allow
them access. Authentication of those remotely defined administrators is done by the same RADIUS server.
Note - This page is available from the Device and Users & Objects tabs.
Administrator Roles:
n
Super Administrator - All permissions. Super Administrators can create new locally defined
administrators and change permissions for others.
n
Read Only Administrator - Limited permissions. Read Only Administrators cannot update appliance
configuration but can change their own passwords or run a traffic monitoring report from the Tools
page.
n
Networking Administrator - Limited permissions. Networking Administrators can update or modify
operating system settings. They can select a service or network object but cannot create or modify it.
n
Mobile Administrator - Mobile administrators are allowed all networking operations on all interfaces.
They can change their own passwords, generate reports, reboot, change events and mobile policy,
active hosts operations and pairing. They cannot login from or access the WebUI.
n
Remote Access Administrator - Limited permissions. Remote access administrators can manage
the VPN remote access configuration. They can add, edit and delete VPN remote access users and
servers.
n
Access Policy Administrator - Limited permissions. Access policy administrators can manage the
Firewall settings; Applications and URL filtering settings; and the Firewall access policy. They can
also create, edit, and delete network objects, services and custom applications.
Two administrators with write permissions cannot log in at the same time. If an administrator is already
logged in, a message shows. You can choose to log in with Read-Only permission or to continue. If you
continue the login process, the first administrator session ends automatically.
The correct Administrator Role must be configured to perform the operations listed below. If not, a
Permission Error message shows.
Local Administrators