Skip to main content
ssan239
Explorer II
November 22, 2024
Question

Fortigate RBAC

  • November 22, 2024
  • 3 replies
  • 1363 views

is it possible on Fortinet to get only access to SDWAN using RBAC?

Means Users should only access SDWAN module and not the other team will manage the Firewall policies.

 

Is it achievable in Fortigate?

Regards,

Sanjay S

3 replies

johnathan
Staff
Staff
November 22, 2024

Not sure what you mean by "RBAC". There isn't a specific permission for SDWAN, you best bet would be to give them 'Network' permissions but this is probably wider than you want. 

Never trust a computer you can't throw out a window.
funkylicious
SuperUser
SuperUser
November 22, 2024

Hi,
You could create admin profiles with similar permissions to what you would need, described below in the link, at least for the firewall policy part.

SD-WAN part would be in the Network menu, I would guess.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-admin-profiles-on-the-FortiGate-for/ta-p/266237

"jack of all trades, master of none"
pminarik
Staff
Staff
November 22, 2024

SD-WAN configuration is part of the "Network" (CLI: netgrp) permissions. Note that this also covers interface configuration, routing, etc.

Firewall policy configurations are controlled by the "Firewall" (fwgrp) permissions.