Skip to main content
Panamajack
New Member
September 1, 2017
Question

Fortigate 81E Semi Admin User block edit of specific Policy Rule or Interface possible ?

  • September 1, 2017
  • 3 replies
  • 3348 views

Hi all,

 

I have several Fortigate 81E on different Branch Offices in use. SuperUser is always me & my team. But on some Branch Offices we have a Techi. For these Techi i already made some Read-Only User just to have a look at Policy and Logs if something gets blocked e.g. . As these branch offices are kinda independent they sometimes install severs that need to communicate with the outside world. This can happen if nobody of my team is at work. That's why im Wondering if its possible to give the Tech people at these branch offices write permission for the Firewall Policy, but deny them the use of some interfaces (this owuld be the interfaces to our internal network as their networks are DMZ and we only want several ports open to our network) or if its possible to mark several Firewall Policies as not editable for them ?

 

I'm pretty sure this won't work with the WebUI but maybe it's possible through cli ? 

 

Thanks in advance!

 

Alex

    3 replies

    ede_pfau
    SuperUser
    SuperUser
    September 1, 2017

    Nope, not that I know of. GUI and CLI are equivalent in this point.

    Either customer techie has to wait and cannot set up servers at any arbitrary time during the day/week.

    Or, you secure your network from your side of the policy. Which will not keep him from creating traffic to other ports.

    In the end, it's a question of who is responsible if a config change created a security risk. The one willing to take the blame will get the authorization. This should be the one with the most experience and knowledge.

    Panamajack
    New Member
    September 1, 2017

    Thanks Ede!

     

    Well than i guess me and my team will be the only one that can create policy rules. 

    ede_pfau
    SuperUser
    SuperUser
    September 1, 2017

    [thumbs up!]

    If I find someone has changed the config on a FGT that I manage I decline responsibility right away. No intention to play hide and seek.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!