FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
gsekar
Staff
Staff
Article Id 344163
Description This article describes how to limit custom administrative user permissions for specific commands.
Scope FortiGate v7.4.4.
Solution

To configure the admin profile and enable the custom option under Permit usage of CLI commands:

  1. Go to system -> Admin profiles, select 'Create new' or edit the existing profiles ->Permit usage of CLI commands -> Custom and disable the permissions for the CLI access.

 

custom admin user cli restriction.png

 

Creating Administrator.

  1. Go to System -> Administrators, create a new admin user and set the Administrator profile to 'prof_admin'. This profile limits the admin's access to the specific CLI commands.

 

creating admin user.png

 

  1. Output: Try to run the restricted commands (execute, config ) and allowed commands (get commands and diagnose commands).

 

clioutput of the user.png

 

 

 

 

 

 

 

Contributors