Access rights for administrators

Description

What are the access rights available for the different administrator and which zone(s) can they login from?

Resolution for SonicOS 7.X

This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.


SonicWall appliance provides a default build-in administrator account (Username: admin; Password: password ). When logging in the firewall with this default account and navigate to Device | Users | Local Users & Groups page,  you can see another four administrators groups (SonicWall Administrators, Limited Administrators, SonicWall Read-Only Admins and Guest Administrators).


Image


These five administrators can be classified into four configuration modes (Full Admin, Read-only Admin, Limited Admin, Guest Admin).

  • Build-in Administrator : Full admin
  • SonicWall Administrator: Full admin
  • Limited Administrator: Limited Admin
  • SonicWall Read-Only Admin: Read-Only Admin
  • Guest Administrators: Guest Admin (Guest management only)


Which zone(s) can these administrators access from?

ZoneFull adminLimited AdminRead-Only AdminGuest Admin
WANX
XX
LANXXXX
DMZXXXX
WLANXXXX
VPNXXXX
SSLVPNXXXX


What are the access rights available for the different administrator?

FunctionFull Admin
in config mode
Full Admin in
non-config mode
Read-only AdminLimited AdminGuest Admin
Import certificatesX



Generate certificate sign-
ing requests
X



Export certificatesX



Export appliance settingsXXX

Download TSRXXX

Use other diagnosticsXX
X
Configure networkX

X
Flush ARP cacheXX
X
Setup DHCP ServerX



Renegotiate VPN tunnelsXX


Log users offXX
X
guest users only
X
guest users only
Unlock locked-out usersXX


Clear logXX
X
Filter logsXXXX
Export logXXXX
Email logXX
X
Configure log categoriesXX
X
Configure log settingsX

X
Generate log reportsXX
X
Browse the full UIXXX

Generate log reportsXX
X
Using CLIXX



NOTE: This table does not include all functions available to limited administrators,Guest admin can only browse and manage guest related functions.

  TIP: Non-configuration mode can be entered when another administrator is already in configuration mode and the new administrator chooses not to preempt the existing  administrator.


Priority for preempting administrators?

  •  The build-in admin and SonicWall global management system (GMS) both have the highest priority and can preempt any users.
  • A user that is a member of the SonicWall administrators (Full admin) can preempt any users except for the build-in admin and SonicWall GMS.
  • A user that is a member of the Limited Administrators can only preempt other members of the Limited Administrators group


Resolution for SonicOS 6.5

This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.


SonicWall appliance provides a default build-in administrator account (Username: admin; Password: password ). When logging in the firewall with this default account and navigate to Manage | Users | Local Users & Groups page,  you can see another four administrators groups (SonicWall Administrators, Limited Administrators, SonicWall Read-Only Admins and Guest Administrators).

Image

These five administrators can be classified into four configuration modes (Full Admin, Read-only Admin, Limited Admin, Guest Admin).

  • Build-in Administrator : Full admin
  • SonicWall Administrator: Full admin
  • Limited Administrator: Limited Admin
  • SonicWall Read-Only Admin: Read-Only Admin
  • Guest Administrators: Guest Admin (Guest management only)


Which zone(s) can these administrators access from?

ZoneFull adminLimited AdminRead-Only AdminGuest Admin
WANX
XX
LANXXXX
DMZXXXX
WLANXXXX
VPNXXXX
SSLVPNXXXX


What are the access rights available for the different administrator? 

FunctionFull Admin
in config mode
Full Admin in
non-config mode
Read-only AdminLimited AdminGuest Admin
Import certificatesX



Generate certificate sign-
ing requests
X



Export certificatesX



Export appliance settingsXXX

Download TSRXXX

Use other diagnosticsXX
X
Configure networkX

X
Flush ARP cacheXX
X
Setup DHCP ServerX



Renegotiate VPN tunnelsXX


Log users offXX
X
guest users only
X
guest users only
Unlock locked-out usersXX


Clear logXX
X
Filter logsXXXX
Export logXXXX
Email logXX
X
Configure log categoriesXX
X
Configure log settingsX

X
Generate log reportsXX
X
Browse the full UIXXX

Generate log reportsXX
X
Using CLIXX



 NOTE: This table does not include all functions available to limited administrators,Guest admin can only browse and manage guest related functions.

 TIP: Non-configuration mode can be entered when another administrator is already in configuration mode and the new administrator chooses not to preempt the existing  administrator.


Priority for preempting administrators? 

  •  The build-in admin and SonicWall global management system (GMS) both have the highest priority and can preempt any users.
  • A user that is a member of the SonicWall administrators (Full admin) can preempt any users except for the build-in admin and SonicWall GMS.
  • A user that is a member of the Limited Administrators can only preempt other members of the Limited Administrators group


Related Articles

  • Firewall logs show frequent probe status changes after upgrade
    Read More
  • SSO Agent 4.0: Installation, Configurations, and troubleshooting
    Read More
  • CFS blocks valid sites due to incorrect 64: Not Rated tag
    Read More
not finding your answers?
was this article helpful?