Configure RBAC Roles | Check Point WAF

This guide explains how to assign RBAC roles to users in the Check Point Portal.

RBAC enables administrators to control which actions users can perform within the platform.

Available roles:

Permission Inheritance

If a user is assigned multiple roles, the highest permission level applies.

For example:

Permissions Matrix

Permission Admin Security Manager Operator (NOC) Read Only Monitor Read Only
View policies ✓ ✓ ✓ ✓ ✗
Manage exceptions ✓ ✓ ✓ ✗ ✗
Disable / tune protections ✓ ✓ ✓ ✗ ✗
View logs and analytics ✓ ✓ ✓ ✓ ✗
Create / manage protected applications ✓ ✓ ✗ ✗ ✗
Attach protection to new assets (for example, enable protections...) ✓ ✓ ✗ ✗ ✗
Manage WAF service settings (for example, General Settings) ✓ ✓ ✗ ✗ ✗
Manage users ✓ ✗ ✗ ✗ ✗
Create new behaviors (Response / Trigger) ✓ ✓ ✗ ✗ ✗
Adjust existing behaviors (Response / Trigger) ✓ ✓ ✓ ✗ ✗
View Monitoring page ✓ ✓ ✓ ✓ ✓
Initialize tenant ✓ ✗ ✗ ✗ ✗

Add a User and Assign Roles

  1. Open the WAF Portal.

  2. Navigate to Account Settings > Users.

  3. Click New or choose an existing user

  4. Under Global Role, select a global role if required.

  5. Under Specific Service Roles:

  6. Select WAF as the service.

    1. Select one or more RBAC roles.
  7. Click Add.

Roles can also be assigned via the Account Settings > Users Groups