How To: Password protect remote configuration changes from profile scripts

How To: Password protect remote configuration changes from profile scripts

Overview

ZPE Cloud provides a great way to remotely manage your ZPE Nodegrids and make configuration changes from the cloud.  However, in some cases such as:
  1. You are a very paranoid System Administrator
  2. You work with other ZPE Cloud admins/operators with same permission levels as you.
  3. You want to protect against the proverbial "fat finger" mistake.
Therefore, you may want to lock down your Nodegrid from remote configuration changes initiated in the cloud using profiles.  Profiles are a powerful tool for ZTP and other management activities, but in your situation, it isn't ideal to just have any admin/operator change your device configuration, perhaps by mistake.

Enable File Protection

The first step is to "Enable File Protection" on Nodegrid.  In the web UI, navigate to Security-->Services, then check the box "Enable File Protection" and provide a password.  This is the password that must be provided when pusing a profile/script from ZPE Cloud to this device.




Configure Password Protected

Now, from the cloud, any profile that is to be applied to this device, must provide the password you set in "Enable File Protection" in order to run successfully.