Skip to main content
Duy2003
Explorer
October 23, 2024
Question

Fortianalyzer: Add new user with super-user rights and admin role

  • October 23, 2024
  • 6 replies
  • 2087 views

Hi team,
I created an admin account (local) with admin-profile as super-user. Although it is the highest privilege, I cannot add device/edit, even though I checked the information in the admin-profile (super-user) and selected the add Device feature.
Thanks

 

6 replies

Jean-Philippe_P
Staff & Editor
Staff & Editor
October 25, 2024

Hello Duy2003, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Staff & Editor
Staff & Editor
October 28, 2024

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Staff & Editor
Staff & Editor
October 29, 2024

Hi again,

 

Can any of you @heng @vraev @emorlang_FTNT @AEK help @Duy2003 please?

 

Thanks in advance!

 

Jean-Philippe - Fortinet Community Team
AEK
SuperUser
SuperUser
October 29, 2024

Hi Duy

Can you post a screenshot of the profile and the user, and the related CLI config as well?

AEK
heng
Staff
Staff
December 1, 2024

Hi there, is the authenticated admin user that you used to login matched a different profile? Hence you are not able to edit/add. etc.

 

You can run CLI to check what profile it being matched for the same login user.

 

FMG01 # diagnose system admin-session list

*** entry 0 ***
session_id: 61590 (seq: 0)
username: admin
admin template: admin
from: GUI(172.16.122.1) (type 1)
profile: Super_User
adom: root
session length: 29 (seconds)
idle: 17 (seconds)

sjoshi
Staff
Staff
December 1, 2024

It seems that even though you assigned the Super_User profile to the admin account, the issue might be related to the specific permissions granted within that profile. Double-check the settings in the Super_User profile to ensure that the necessary permissions for adding devices and editing are enabled. If the problem persists, consider reviewing the device group access settings and policy package access for that administrator account.

 
Thanks, Salon