Skip to main content
gsekar
Staff
Staff
September 25, 2024

Technical Tip: How to Limit Custom Admin User Permissions for Specific Commands

  • September 25, 2024
  • 0 replies
  • 1858 views
Description This article describes how to limit custom administrative user permissions for specific commands.
Scope FortiGate v7.4.4.
Solution

To configure the admin profile and enable the custom option under Permit usage of CLI commands:

  1. Go to system -> Admin profiles, select 'Create new' or edit the existing profiles ->Permit usage of CLI commands -> Custom and disable the permissions for the CLI access.

 

custom admin user cli restriction.png

 

Creating Administrator.

  1. Go to System -> Administrators, create a new admin user and set the Administrator profile to 'prof_admin'. This profile limits the admin's access to the specific CLI commands.

 

creating admin user.png

 

  1. Output: Try to run the restricted commands (execute, config ) and allowed commands (get commands and diagnose commands).

 

clioutput of the user.png