AnsweredHot!Help admin without super_admin permission

Author
Micky182
New Member
  • Total Posts : 13
  • Scores: 2
  • Reward points: 0
  • Joined: 2018/11/11 01:56:37
  • Status: offline
2019/11/14 10:35:01 (permalink)
0

Help admin without super_admin permission

Hi, 
I've a very huge problem about admin rights. I've a new costumer with a Fortigate firewall and i've reset the fortigate admin password(because they didn't had);.. but i still haven't the full super_admin permission.
 
In fact the account can't see Administrators profile and i figured out that the admin account is an prof_admin.
Is it possible to change an admin account from prof_admin to super admin?
 
In the past i've done with a backup config but i had the backup file. Now i've no config backups files and no way to backup or restore fortigate config with the prof_admin account. I'm also wondering if there is another hidden account as super_admin?
 
I'm very stuck in this bad situation and i can't do a factory reset.
#1
Toshi Esumi
Expert Member
  • Total Posts : 1802
  • Scores: 151
  • Reward points: 0
  • Joined: 2014/11/06 09:56:42
  • Status: offline
Re: Help admin without super_admin permission 2019/11/14 11:06:00 (permalink) ☼ Best Answerby Micky182 2019/11/14 23:51:47
0
You need to be a "suer_admin" to make a user as a super_admin. If you don't have, or know the password for, any other super_admin users on the box, you need to go through the password recovering process you can find somewhere in this forum or on the internet. The "maintainer" user for the process must be a super_user so you can change anything you want to change.
#2
Micky182
New Member
  • Total Posts : 13
  • Scores: 2
  • Reward points: 0
  • Joined: 2018/11/11 01:56:37
  • Status: offline
Re: Help admin without super_admin permission 2019/11/14 23:57:26 (permalink)
0
Hi,
 
I've tried but from maintainer account o can't change the accprofile from pro_admin to super_admin because i get an the error -61. You think is possible from maintainer change the profile of other users?
 
Thank you very much,
Michele.
 
#3
Dave Hall
Expert Member
  • Total Posts : 1548
  • Scores: 167
  • Reward points: 0
  • Joined: 2012/05/11 07:55:58
  • Location: Canada
  • Status: offline
Re: Help admin without super_admin permission 2019/11/15 07:03:42 (permalink)
0
Try creating a temp admin account with super_admin rights. Then try logging into the fgt normally with this temp admin account.
 
e.g.
 
config system admin
edit "temp_admin"
set accprofile "super_admin"
set password <password>
next
end


Alternately, see if you can perform a backup of the config to a USB stick (san password) and see if you can read it later (in a text editor) you should be able to edit/change/add the accprofile line to your admin account, save it as a new config and try uploading that via USB or via the GUI (following a factory reset).  A word of caution about this approach as you need to be absolutely sure you have a couple of good backups of the config running on the fgt. 
 
 
 

NSE4/FMG-VM64/FortiAnalyzer-VM/5.4/6.0 (FWF40C/FW92D/FGT200D/FGT101E)/ FAP220B/221C
#4
ede_pfau
Expert Member
  • Total Posts : 6127
  • Scores: 496
  • Reward points: 0
  • Joined: 2004/03/09 01:20:18
  • Location: Heidelberg, Germany
  • Status: online
Re: Help admin without super_admin permission 2019/11/17 03:43:30 (permalink)
0
As stated before, only a super_admin can create a super_admin account. So, no dice.
What I'd try is to login as 'maintainer', export the config, change the account setting, and restore. It might work but I haven't tried before. Logging in as 'maintainer' is a tedious job, also.

Ede

" Kernel panic: Aiee, killing interrupt handler!"
#5
Jump to:
© 2019 APG vNext Commercial Version 5.5