Skip to main content
kiminou
New Member
September 2, 2025
Question

How to prevent or forbid any CLI changes on Fortigate once it is integrate to FortiManager

  • September 2, 2025
  • 1 reply
  • 416 views

Hello

We manage all fortigates from FortiManager, I want to prevent or forbid any changes directly on Fortigate, changes need to be done from fortimanager. How can I reach this goal ? Any suggestion will be welcome.

Thanks

1 reply

Yurisk
SuperUser
SuperUser
September 4, 2025

You can set up a custom Access Profile for such admins in which you disable everything-CLI. 

See example of how to enable CLI commands - just do the reverse, unselect CLi commands.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enable-config-options-in-custom-admin-access/ta-p/314351

 

If you want to force people to do changes only via FMG, just assign all admins on Fortigates read-only profile, and leave just one super_admin user (for emergency access) password of which is kept safe away from regular admins.