Access Panorama to firewall Gui context and CLI context.
Hello, good morning, I reiterate, thank you again for the information, help and support. Please support the following topic:
Currently, with the account that logs me into Panorama, as long as I have access and permissions to all contexts, I was able to change the context to enter the firewall locally and for traceability of changes and settings, the user is added Panorama.User, when you make changes, modifications, commit etc on the equipment.
OK now the issue is the following, how can I do the same thing I do in the GUI ( Context change ), but this time by CLI ? is there any option for it. In other words, to avoid having to use a local admin user, for example, in the firewall, to log in SSH/CLI, is there this option and simply change the context/CLI? Or do I have to log in directly via CLI/SSH to each firewall? To log in, do I have to have a local user in the destination firewall? Or as this firewall is being managed and administered by PANORAMA, can I use the "Same Panorama user" that is, a valid PANORAMA user, to log in directly via CLI/SSH to the firewall or must I have a local user?
Please your support to review this issue, since I can not find documentation that refers to this topic.
Thank you very much, I remain attentive cordial greetings.
You can't, there is no context switching possible in CLI. You'll always need a local account on the firewall to be able to ssh in