FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
FortiArt
Staff
Staff
Article Id 361016
Description This article describes some of the CLI commands only available when logging into FortiGate using the supper_admin profile, but not using the prof_admin, Console_Debug, or super_admin_readonly profiles.
Scope FortiGate.
Solution When logging into FortiGate using prof_admin, Console_Debug, or super_admin_readonly profiles, the following commands will show the respective error message:

Capture.PNG

 

In general, all fnsysctl commands relevant to system resources checks and file system checks will require a super_admin profile to run successfully.

 

There are some slight differences in the execute commands between the prof_admin, Console_Debug profiles, and super_admin_readonly profile. For example the following 2 commands work when logging into FortiGate using prof_admin and Console_Debug profiles:

 

execute_time.PNG

 

However, the above 2 commands will not work when logging into FortiGate using the super_admin_readonly profile:

 

execute_time_readonly.PNG

 

In summary, to get full access to all CLI commands necessary for troubleshooting need to log into FortiGate using super_admin profile.