Skip to main content
Lukino
Explorer
August 6, 2018
Question

Read_Only permission - plus diagnose commands

  • August 6, 2018
  • 1 reply
  • 4761 views

Hi guys,

I've one customer that needs read-only access to the fortigate, 

all works fine when I set up the "Administrator Profile" with read-only permission.

now my customer want to launch the "diagnose sniffer packet" command on the CLI, 

but is not possible with such permissions

is there a way to give him these kind of commands, without give him too many read-write permissions?

 

thanks so much 

1 reply

ede_pfau
SuperUser
SuperUser
August 6, 2018

I thnik permissions are not so detailed as to be able to allow single command verbs within 'diag'. RO users do not have access to the 'diag' command branch.