FortiADC Radius/Tacacs Admin Auth
Hello
I'm trying to configure Radius/Tacacs authentication for admin/user access to the FortiADC. Version: 7.4.4 Build0347 (Mature)
I've created the radius server and a user account with the wildcard flag enabled.
Authentication is via Cisco ISE
This all works fine for super_admin access, users can authenticate and given full privilege's to all vdoms.
However, I'd like to have certain user only have read-only access to all vdoms.
I've created a read-only access-profile and an associated ISE policy-set sending the read-only group attributes, however, when a read-only user logs on, they are still given full super_admin access.
The usual command on something like a Fortigate 'set accprofile-override enable' is missing from the ADC CLI so I cannot add this to the wildcard user.
I'm assuming the user account with the wildcard flag cannot change the access profile without this.
Can anyone advise if what I'm attempting to do is available on the ADC?
And if not, is there a workaround or different configuration I can use to achieve the same result?
Thanks
