31. General Settings » User Management

In Configuration » General Settings » User Management, you can add, modify and delete Console user accounts and roles.

USER_MANAGEMENT_OVERVIEW

To create a Console user account, click [Add User], then assign the Role. By default, there are Administrator and Operator roles, but you can define new roles with granular permissions (reports/configuration) by clicking [Manage Roles].

To modify an existing account, either double-click it or select it and choose [Modify User].

USER_MANAGEMENT_GUEST

These parameters are mandatory when creating or modifying a user account:

Username – A unique account name
Role – Choose one of the existing roles in Configuration » General Settings » User Management » Manage Roles. For granular, permission-based access, create a new role first, then select it here
Authentication – The following authentication options are available:
Local Password – The user is authenticated with the password entered when clicking the Options button. The database stores only the password hash, so it’s not possible to decrypt the plaintext password
Remote – The user is authenticated by the LDAP or RADIUS servers configured in General Settings » User Authentication
REST API Access – Defines whether the user can access the REST API via their credentials or an API Key (set when clicking the Options button):
Disabled – No API access
Enabled – API access + Console access
Exclusive – API access only (no Console)
Two-factor Authentication – Requires a Time-Based One-Time Password (TOTP) app (e.g. Google Authenticator). TOTP works only if server and mobile device clocks are in sync
Expiry Date – The user cannot log in after this date. Leave blank to disable expiry
Landing Tab – The tab shown immediately after logging in. The list grows as you add sensors, dashboards, IP groups, or other objects
Console Notifications – Controls visual/audio notifications from Responses. May need a page refresh for immediate effect
Console Theme – Changes the overall UI appearance
Console Icon Set – Changes the appearance of icons:
Auto – Selects icons based on the Console Theme (Modern for modern themes, Classic otherwise)
Modern – Monochrome, SVG-based
Classic – Colored, bitmap-based
Reports Region – Adjusts the position of the Reports Region in the interface
Configuration Region – Adjusts the position of the Configuration Region in the interface
Minimum Severity – The lowest severity level of events displayed in the Console
Default Time Range – The default timeframe for dashboards upon opening

31.1. Roles

Each Console user is assigned exactly one role, which defines that user’s access level. Three role classes exist:

Administrator – Unrestricted access to everything, including managing all user accounts and roles (built-in)
Operator – Can view every report and change any configuration, but cannot manage user accounts or roles and has no access to General Settings » License Manager (built-in)
Guest – A customizable class with granular, permission-based access to reports, dashboards, Sensors, IP groups, and configuration objects. Every role you add is a Guest role, shaped by the Reports Access and Configuration Access settings described below

ROLE_MANAGEMENT_OVERVIEW

To create a Guest role, open Configuration » General Settings » User Management » Manage Roles and click [Add Role].

USER_ROLE

A role has the following parameters:

Role Name – A unique name for the role
Description – An optional short description, shown next to the role in the Manage Roles list
Reports Access – The role’s access to the Reports Region:
Full – Full access to every report, but the role cannot create Dashboards
Custom – Activates the [Options] button beside the selector; click it to set granular, per-object permissions (see Custom Reports Access)
Configuration Access – The role’s access to the Configuration Region:
Disabled – The role cannot open the Configuration Region
Custom – Activates the [Options] button beside the selector; click it to set granular, per-object permissions (see Custom Configuration Access)
South Region – Show or hide the South Region
Help Menu – Show or hide the Help menu in the Upper Menus
Comments – Optional free-form notes about the role, in a section that is collapsed by default

31.1.1. Custom Reports Access

USER_ROLE_REPORTS

When a role’s Reports Access is set to Custom, click the adjacent [Options] button to open the Reports Access Options window shown above. The top selectors set which objects the role may reach in reports, the middle section governs its dashboard permissions, and the bottom section chooses which panels appear in the role’s Reports region and what each one contains. Object selectors default to All (or None for Full-access Dashboards); left on All, a selector covers every object of that type, including ones added later.

Allow Device Group(s) – Which Device Groups the role may access under Reports » Devices. Any object defined in Configuration » Components can be assigned to a Device Group
Allow IP Group(s) – Which IP Groups the role may access under Reports » IP Groups and Reports » IP Addresses. The subnets and hosts of an IP Zone are assigned to IP Groups
Allow Server(s) – Which server (from Configuration » Servers) the role may access under Reports » Servers
Read-only Dashboards – The dashboards the role can open but not modify
Dashboard Access Policy – Governs whether the role can change dashboards:
No modification allowed – Dashboards are view-only, and the Full-access Dashboards selector below is disabled
Allow modifications to Full-access Dashboards – The role may edit the dashboards chosen in Full-access Dashboards
Allow modifications to Full-access Dashboards and permit adding new ones – As above, and the role may also create new dashboards
Full-access Dashboards – The dashboards the role can view and modify; enabled only when the Dashboard Access Policy permits modification

Each panel of the role’s Reports region is toggled below with a Show / Hide selector. For every panel except Tools, the field beside it is a read-only preview of what the panel will contain, derived from the access selectors above.

Reports » Tools – Show or hide the Reports » Tools menu. When set to Show, the multiselect on the right selects which individual tools the role may open:
Anomalies, Routing, and Firewall — each paired with an Actions entry that also grants the responses and mitigations the tool performs — plus Flows, Packets, Packets Actions, and Packets Actions & Captures (which additionally covers downloaded packet captures)
Reports » Devices – Show or hide the Devices panel, which lists the Allow Device Group(s) selected above
Reports » Dashboards – Show or hide the Dashboards panel, which lists the role’s read-only and full-access dashboards
Reports » IP Addresses – Show or hide the IP Addresses panel, which lists the prefixes contained in the allowed IP Groups
Reports » IP Groups – Show or hide the IP Groups panel, which lists the Allow IP Group(s) selected above
Reports » Servers – Show or hide the Servers panel, which lists the Allow Server(s) selected above

31.1.2. Custom Configuration Access

USER_ROLE_CONFIG

When a role’s Configuration Access is set to Custom, click the adjacent [Options] button to open the Configuration Access Options window shown above. It grants the role selective, per-object access to the configuration areas under Configuration » Network & Policy and Configuration » Schedulers.

Each area provides an Access Policy selector that sets the level of access, followed by one or more object selectors naming the specific objects the policy applies to. An object selector stays disabled until its Access Policy grants access; left on All, it covers every object of that type, including ones added later.

Configuration » Network & Policy » IP Zones – Access to IP Zone prefixes and their per-subnet settings:
No access – The role cannot open any IP Zone
Allow full access to the allowed IP Group(s) in the selected IP Zone(s) – Full access to the prefixes belonging to the IP Group(s) the role is allowed in Custom Reports Access, limited to the IP Zone(s) selected below
Configuration » Network & Policy » Responses – Access to Responses and the actions they carry out:
No access – The role cannot view or use any Response
Allow using the selected Response(s) when defining thresholds – The role may attach the selected Response(s) to thresholds but cannot view or edit the Responses themselves
Allow full access to the selected Response(s) – The role may view and edit the selected Response(s)
Allow full access to the selected Response(s) and permit adding new ones – As above, and the role may also create new Responses
Response Action(s) – Restricts which action types (BGP announcement, packet-sample capture, command or script, email, Syslog, SNMP trap, Console notification, Flowspec/RTBH, third-party inline device, and so on) the role may add to a Response; enabled only under the two full access policies above
Configuration » Network & Policy » Threshold Templates – Access to Threshold Templates:
No access – The role cannot view any Threshold Template
Allow read-only access to the selected Threshold Template(s) – The role may view but not modify the selected Threshold Template(s)
Allow full access to the selected Threshold Template(s) – The role may view and edit the selected Threshold Template(s)
Allow full access to the selected Threshold Template(s) and permit adding new ones – As above, and the role may also create new Threshold Templates
Configuration » Network & Policy » Profiling Templates – Access to Profiling Templates; this area is shown only when Profiling is installed:
No access – The role cannot view any Profiling Template
Allow read-only access to the selected Profiling Template(s) – The role may view but not modify the selected Profiling Template(s)
Allow full access to the selected Profiling Template(s) – The role may view and edit the selected Profiling Template(s)
Allow full access to the selected Profiling Template(s) and permit adding new ones – As above, and the role may also create new Profiling Templates
Configuration » Network & Policy » Whitelist Templates – Access to Whitelist Templates:
No access – The role cannot view any Whitelist Template
Allow read-only access to the selected Whitelist Template(s) – The role may view but not modify the selected Whitelist Template(s)
Allow limited access to the selected Whitelist Template(s) – The role may modify the selected Whitelist Template(s); this is the highest level offered for whitelists, so there is no separate option to permit creating new ones
Configuration » Schedulers – Access to Scheduled Reports:
No access – The role cannot view any Scheduled Report
Allow full access to the selected Scheduled Report(s) and permit adding new ones – The role may view, edit, and create Scheduled Reports, limited to the selected Scheduled Report(s)