Created on
10-19-2020
12:34 PM
Edited on
01-03-2025
12:31 AM
By
Jean-Philippe_P
Description
This article describes how to configure per-VDOM administrators.
Scope
FortiGate.
Solution
Per-VDOM administrators can be created to access only the management or traffic VDOM.
These administrators have to use either the prof_admin administrator profile, or a custom profile.
A per-VDOM administrator can only access the FortiGate through a network interface that is assigned to the VDOM that they are assigned to.
The interface has also to be configured to allow management access.
It can also connect to the FortiGate using the console port.
To assign an administrator to multiple VDOMs, it has to be created at the global level.
When creating an administrator at the VDOM level, the super_admin administrator profile cannot be used.
To create a per-VDOM administrator From GUI:
If a specific user account needs to access the FortiGate GUI with Specific VDOM only, with the same WAN interface it will not work, the user needs to add one more WAN Interface and move root VDOM to Specific VDOM.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.