Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Akid
New Contributor

Autorize a specific command with Administrator profile

Hi there,

I would like to know how to allow a profile to use the "diagnose" command. Currently we have a readonly profile with everything set to readonly, but we don't know wich section is in control for the access to this command.

Is there a document who describe the relationship between access control sections and commands related to it ?

 

Regards !

2 REPLIES 2
emnoc
Esteemed Contributor III

I don't believe that would be possible, the AAA function in  FortiOS is a "access profile" based and not commands.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Nicholas_Doropoulos

Hi Akid,

 

Below is a document that should explain how different admin profiles can be created:

 

http://help.fortinet.com/fweb/537/Content/FortiWeb/fortiweb-admin/config_access_profiles.htm

 

That being said, Fortigate is not modular enough yet to associate a profile with a subset of specified commands.

 

I hope that helps.

NSE5, CCSE, CCNA R&S, CompTIA A+, CompTIA Network+, CompTIA Security+, MTA Security, ITIL v3

NSE5, CCSE, CCNA R&S, CompTIA A+, CompTIA Network+, CompTIA Security+, MTA Security, ITIL v3
Labels
Top Kudoed Authors