AFA users and roles
Relevant for: AFA Administrators
This section describes the users, roles, permissions, and authentication supported in AFA, and how AFA administrators can manage AFA users and roles.
AFA users and roles provide the basis for authentication across both AFA and FireFlow.
AFA authentication
ASMS supports authentication via an LDAP or RADIUS authentication server, Single Sign On (SSO), or the local AFA database.
Configuring an authentication server or SSO provides additional functionality, such as associating each AFA role with a specific LDAP group. In such cases, users are automatically assigned roles according to their LDAP group membership.
Note: When an authentication server or SSO is configured, user credentials and roles are managed on the external server. In such cases, any changes made directly in AFA are overwritten the next time the user logs in.
For more details, see:
- Configure user authentication. Describes how to configure an authentication server or SSO.
- Manage users and roles in AFA. Describes how to manage users and roles directly in AFA.
AFA user types and permissions
AFA supports the following types of users:
Administrators |
Can perform any task. For example, in addition to the tasks that non-administrative users can perform, administrators can also:
|
Non-administrator privileged users | Can run analyses, generate reports, view policies and reports, view network map and monitoring changes, and run traffic simulation queries. |
Each user is assigned one of the following access levels as part of their default permission profile:
For more details, see Manage users and roles in AFA.