This topic describes how to manage AFA users and roles in the AFAAdministration area.
Note: If you have an authentication server or SSO configured, user credentials must be managed on your external server. If your user roles are assigned based on LDAP group membership, roles must be managed on the LDAP server. In these cases, any changes made directly in AFA are overwritten the next time the user logs in. For more details, see Configure user authentication.
Tip: AFA users and roles provide the basis for authentication across both AFA and FireFlow. If you are an AFA administrator, but not a FireFlow administrator, you can also access FireFlow role and user management via the AFAAdministration area. For more details, see Manage FireFlow users and roles.
In this topic:
Add or edit users
This procedure describes how to add and edit AFA users directly in the AFA database.
Click your username at the top-right to access the AFAAdministration area.
Click the USERS/ROLES tab to display the user and role tables. For example:
To add a new user, click the New button below the user table. To edit an existing user, click the edit button at the right side of the row you want to edit.
In the user form that appears, select and enter values as needed:
Select the user roles to assign to the user. The user is automatically granted permissions specified in the assigned roles.
Tip: If you assign additional permissions to this user, the user will have both the permissions inherited from their roles, as well as additional permissions assigned to the user.
Define the scenarios in which this user receives notifications from AFA:
Changes in risks
The user is notified for each change detected in risks.
Changes in policy
The user is notified for each change detected in policies.
Every group report
The user is notified for each group report generated.
Every report
The user is notified for each report generated.
Every configuration change
The user is notified for each configuration change detected.
Rules and VPN Users about to expire
The user is notified when device rules and/or VPN users are about to expire.
Tip: To configure the number of days before rule or VPN user expiration that AFA should send a notification, complete the Days before expiration alerts field in the General sub-tab of the Options tab in the Administration area.
This procedure describes how to add and edit user roles.
Tip: If you have an LDAP server configured, associate AFA user roles with specific LDAP user groups to have each user in the group automatically inherit the AFA role.
Do the following:
Click your username at the top-right to access the AFAAdministration area.
Click the USERS/ROLES tab to display the user and role tables. For example:
To add a new role, click the New button under the role table. To edit an existing role, click the edit button in the row for the role you want to edit.
In the user form that appears, select and enter values as needed:
Enter the DN of the LDAP group that corresponds to this role.
When users who are members of this LDAP group log in, they will automatically be granted this role.
For example: cn=network_users,ou=organization,o=mycompany,c=us
Note: This field is enabled only if you have AFA configured to fetch user data from an LDAP server.
To enable this field, select the Fetch user data from LDAP option on the OPTIONS > Authentication tab in the AFAAdministration area. For details, see Import user data from an LDAP server.
Landing Page
Select Firewall Analyzer or FireFlow. Select Automatic to use the default landing page for the selected role.