Read-Only Remote Access to Your Firewall's WebAdmin
There are plenty of situations where someone needs to see what is happening on a firewall without needing — or being allowed — to change it. A junior network engineer reviewing a routing table. An auditor inspecting firewall rules before a compliance review. A help-desk analyst checking interface status during an outage. An MSSP customer who wants visibility into their own managed device but should not be touching the configuration.
Until now, the only way to give someone access to a managed firewall’s WebAdmin was the same access you would give anyone else: full write access. You could restrict access by role at the platform level, but anyone who could reach the device’s web interface had an interface with no guardrails. Today, NetDefense adds read-only remote access to WebAdmin — a purpose-built mode designed for exactly these situations.
What read-only mode gives you
When you open a device’s WebAdmin in read-only mode, you get complete read-only access to the firewall’s web interface — the same view any administrator would have, across the full breadth of the UI. You can see everything happening in real time.
What you cannot do is make a change. Configuration forms are unavailable, write operations are blocked, and terminal or shell access is not available in read-only sessions. The interface is a window, not a keyboard.
Who it’s for
The natural audience is anyone who needs visibility without write authority:
- Auditors and compliance staff reviewing firewall policy or confirming a configuration state — they can inspect what they need without any risk of modification.
- NOC and help-desk teams investigating connectivity issues or checking interface status — they get enough context to triage without being able to accidentally change something during an investigation.
- Junior or trainee staff who are still learning the ropes — they can explore a live firewall safely.
- MSSP customers who want to see into their own managed device — you can hand out visibility without sharing administrative control.
The common thread is least privilege: give someone exactly the access the job requires, and nothing more.
How to use it
From the device’s page in the NetDefense web console, open the WebAdmin remote access panel and choose the read-only option. The firewall’s web interface opens in a browser tab in browse-only mode. No extra software to install, no separate credentials to issue.
The session rides NetDefense’s secure relay — the same infrastructure used for standard WebAdmin sessions. There are no inbound firewall ports to open and no VPN to set up.
The enforcement model
The read-only constraint is enforced on the device itself, not in the browser. This matters.
A purely UI-level restriction — where the underlying session was still capable of writes, but the interface hid the write controls — would leave a meaningful gap: a sufficiently determined user could interact with the underlying interface directly and bypass what the UI was hiding. That is not the model here.
In a read-only session, the firewall’s web server blocks configuration writes and terminal access at the session level. There is no write capability to reach around the UI to find, because the server will not accept one from that session. Even with a modified or instrumented client, the enforcement is on the device, not in the presentation. The constraint survives the client.
The read-only permission set covers the full firewall UI — you can see every status page, diagnostic view, and log the device exposes. The only thing that is off is the ability to write.
Safe to hand out widely
Because the read-only constraint is enforced server-side, read-only sessions are safe to issue to people you would not otherwise trust with firewall access. An auditor who only needs to see firewall rules does not need an account capable of changing them. A help-desk tier that only needs interface status does not need to be able to modify routing. You can expand who can see your firewalls without expanding who can change them.
The session uses the same relay-based transport as all NetDefense remote access: no inbound ports on the device, no VPN tunnel to the customer network. The firewall reaches out; the session travels back over that established channel. The read-only constraint is at the device end, so the relay simply carries what the session permits — and the session only permits reads.
Getting started
Read-only remote access is available now for all managed devices. From any device detail page in the NetDefense web console, open the WebAdmin remote access panel and select the read-only option.
For full documentation on remote device access, see the Remote Access guide.
Join the discussion in our Community
Enjoyed this post? Explore more in the documentation.