The global settings listed in the following article define the restrictions for administrative roles. They are needed when a new administrator is introduced (see: How to Create a New Admin Profile [1] ). Configure Administrative Roles In order to configure the settings for CC Administrative Roles, complete the following steps: 1. 2. 3. 4. 5. Log into the Barracuda NG Control Center [2]. Go to the Config > Multi-Range > Global Settings page. Open the Administrative Roles object by double clicking it. Click Lock. Click + to add a new entry. The checkboxes in this following section define whether the corresponding module can be accessed by the administrator (checkbox selected). When selected the permissions can be set in detail by clicking the Edit or Set buttons. 6. In the Name field, enter a describing sequence number for the administrator s role. 7. Configure the following settings as required: Parameter CC Config Kill Sessions Change Change Events Show Admins Manage Admins Create/Remove Range Create/Remove Cluster Use RCS Create/Remove Boxes Create/Remove Servers Create/Remove Service Create/Remove Repository Manage HA Sync Create PAR File Allow Config View on Box Allow Emergency Override 1 / 5
CC Control Access to CC PKI Service Control Show Map It is recommended that you grant the Show Map permission in the CC Control Module section to every admin role. Admins that do not have this permission will get an error message immediately after they log into the Barracuda NG Control Center. Show Config. Updates Manage Config. Updates Show Box REXEC Manage Box REXEC Show Box Software Updates Manage Box Software Updates Manage Box File Update Start/Stop Server Block Server Start/Stop Service Block Service Delete Wild Route Activate New Configuration Restart Network Subsystem Set or Sync Box Time Restart NGFW Subsystem Reboot System Activate Kernel Update Kill Sessions Import License Remove License View License Data Show Box File Update Users can view the File Updates tab on a Barracuda NG Control Center but are not allowed to manage update tasks. (option available in firmware version 5.2.9 and later) 2 / 5
Event Log Statistics DHCP Server Access Control Service CC Access Control Service Firewall Silence Events Stop Alarm Confirm Events Delete Events Read Box Logfiles Delete Box Logfiles Read Service Logfiles Delete Service Logfiles Read Box Statistics Delete Box Statistics Read Service Statistics Delete Service Statistics, to modify or remove entries from the status and access cache. Block Box Sync, to disable authentication sync. Terminate Connections Modify Connections Kill Handler Processes Dynamic Rule Control Toggle Trace Selecting this parameter together with View Trace Output and Change Settings enables the admin to run admintcpdump on the command line. See Command-Line Interface [3] for detailed information. View Trace Output, see note on parameter Toggle Trace. Change Settings, see note on parameter Toggle Trace. View Rule Set Manipulate Access Cache Entries 3 / 5
VPN Server Mail Router Virscan Service Secure-WebProxy 8. Click OK. 9. Send Changes and then Activate. Terminate VPN Tunnels Disable/Enable VPN Tunnels View Configuration View Stripped Attachments Retrieve Stripped Attachments Delete Stripped Attachments Allow Block Virus Pattern Update Allow Manual Virus Pattern Update Access Cache Management, to manipulate access cache entries Ticket Management, to process access request tickets Cert. Authorities Management, to accept/deny a root CA to modify CRL handling XML Services Management, to modify settings for RSS-feeds or Webservices (allow, scan, deny, delete) 4 / 5
Links 5 / 5