Open Frames Download Complete PDF Send Feedback Print This Page

Previous

Next

Configuring SmartWorkflow

In This Section:

Assigning Permissions

Enabling the SmartWorkflow Blade

Configuring SmartWorkflow Properties

Before you can use SmartWorkflow, you set it up. You assign administrators and managers, decide on deployment mode, enable it as a Software Blade, and configure its properties for your environment.

Assigning Permissions

In a full change management scenario with Role Segregation, only managers are authorized to:

  • approve sessions
  • enable or disable SmartWorkflow
  • configure SmartWorkflow properties

In Multi-Domain Security Management, only Multi-Domain Security Management and Domain Superusers have these permissions.

Define users and assign their permissions before you enable SmartWorkflow. This is necessary to prevent SmartWorkflow from enforcing Role Segregation before you assign manager permissions.

Defining Permissions for Security Management Server

When you configure permissions, make sure to give Manager permissions to people who should actually have auditing authority. It is best if Managers are not Administrators.

To configure permission profiles in a Security Management Server environment:

  1. In SmartDashboard, select Manage > Permissions Profiles.
  2. Select an existing profile or click New to create a new profile.
  3. Enter a name for the permission profile.
  4. Select the Allow access via as required for your environment.
  5. Select Read/Write All for managers and administrators.
  6. For Managers only, select Manage Administrators.

Defining Permissions for Multi-Domain Security Management

To configure manager permissions for Multi-Domain Security Management:

  1. In the SmartDomain Manager, click Administrators on the Selection Bar.
  2. In the Domains per Administrator pane, double-click an existing user or right-click the Multi-Domain Security Management icon and choose New Administrator.
  3. In the Edit Administrator window, select Domain Superuser or Multi-Domain Security Management Superuser for managers.
  4. Define other user properties as required.

Enabling the SmartWorkflow Blade

You must enable SmartWorkflow in SmartDashboard for each Security Management server or Domain Management Server before you can begin to work with it. After SmartWorkflow is enabled, SmartWorkflow is available when you re-open SmartDashboard.

After you enable SmartWorkflow, you have a 45-day trial license.

To enable SmartWorkflow:

  1. In SmartDashboard, double-click an active Security Management server or Domain Management Server object and select General Properties. The Security Management server can be primary or secondary but it must have an IP address identical to the server you are connected to.
  2. In the Software Blades section, select the Management tab and then select Workflow.
    The SmartWorkflow Configuration Wizard opens.
  3. Select a mode of working with SmartWorkflow.
    • Use SmartWorkflow for visual change tracking - Lets you track changes to the policy without sessions. You can install the policy without an approval process.
    • Use SmartWorkflow to track, review and require approval for changes - Lets you track changes to the policy with sessions. This enforces policy installation only with approval by a manager. Without approval, the policy cannot be installed.
  4. Save the configuration.

To disable SmartWorkflow:

  1. In SmartDashboard, double-click a Security Management server or Domain Management Server object and select General Properties.
  2. In the Software Blades section, select the Management tab and clear Workflow.
  3. Save the configuration.

Configuring SmartWorkflow Properties

Configure SmartWorkflow properties in SmartDashboard. In a Multi-Domain Security Management environment, do these configuration steps for each Domain Management Server.

To configure SmartWorkflow properties:

  1. In SmartDashboard, click Edit Global Properties.
  2. In the Global Properties window, open SmartWorkflow.

    • To disable highlighting changes made in sessions, clear Highlight changes.
    • To work without sessions, clear Work with sessions.
    • To work without role segregation, clear Require session approval.
  3. Select Administrators can only view their submitted sessions to let administrators view only their own sessions. Managers can view all sessions.
  4. If you enable role segregation:
    1. To make sure managers cannot approve their own sessions, select Managers cannot approve their submitted sessions.
    2. To let administrators install policy if the manager is not available and it must be done, select Administrators can install unapproved policies using a password in an emergency. Enter the emergency password.

    The session remains unapproved after the policy installation. Enter and confirm the emergency password in the designated fields.

 
Top of Page ©2014 Check Point Software Technologies Ltd. All rights reserved. Download Complete PDF Send Feedback Print