FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
lkumar
Staff
Staff
Article Id 352663
Description This article describes creating admin users who can access the firewall to only perform the packet capture and will not have any other access.
Scope FortiGate.
Solution

 

  1. To create an admin user to perform only the packet capture, log in to the firewall with a super admin credentials.
  2. Navigate to System -> Admin Profiles. In the Admin profiles tab, select Create New.

Picture1.png

 

  1. Add the Name for the Admin profile.
  2. In the Access Permissions tab, check for the Network in Access Control and under Permissions, select Custom.
  3. In the Packet Capture tab, select Read/Write to provide the permission for the Packet Capture(To allow captures from CLI, set permit usage of CLI commands to custom and enable diagnostic).
  4. Select OK.

Picture2.png

 

Screenshot 2025-09-26 153528.png

  1. Once the admin profile is created, select System -> Administrators and, in the Administrator tab, select Create New.

 

Picture3.png

 

  1. Provide the username and password. In the Administrator profile tab, select the profile name.
  2. Select OK.

 

Picture4.png

 

  1. Once the Administrator is created, log out of the firewall and log in using the credentials for the created account (Admin1).

Picture5.png

 

  1. Select Network -> Diagnostics to see that the user has permissions only to perform the packet capture.

 

Picture6.png 

  1. Select the Interface, specify the number of packets to capture in the Maximum captured packets field, set the required filters, and then select 'Start Capture'.

                                    caputre.png

 

CLI captures:

 

Screenshot 2025-09-26 153935.png