Fortigate 81E Semi Admin User block edit of specific Policy Rule or Interface possible ?
Hi all,
I have several Fortigate 81E on different Branch Offices in use. SuperUser is always me & my team. But on some Branch Offices we have a Techi. For these Techi i already made some Read-Only User just to have a look at Policy and Logs if something gets blocked e.g. . As these branch offices are kinda independent they sometimes install severs that need to communicate with the outside world. This can happen if nobody of my team is at work. That's why im Wondering if its possible to give the Tech people at these branch offices write permission for the Firewall Policy, but deny them the use of some interfaces (this owuld be the interfaces to our internal network as their networks are DMZ and we only want several ports open to our network) or if its possible to mark several Firewall Policies as not editable for them ?
I'm pretty sure this won't work with the WebUI but maybe it's possible through cli ?
Thanks in advance!
Alex
