Created on
‎06-17-2025
04:26 AM
Edited on
‎08-27-2025
10:49 AM
By
Stephen_G
Description | This article describes how to handle an issue where an admin user with a super_admin_readonly administrator profile cannot run diagnostic commands in the CLI. |
Scope | FortiGate v7.4.x and above. |
Solution |
While creating an admin user account from the GUI, under System -> Administrators:
From v7.4.x, the diagnostic commands cannot be run by the admin user with the super_admin_readonly profile, as this has been disabled under CLI permits.
The super_admin_readonly profile cannot be edited from the GUI:
From the CLI, the changes cannot be made to the admin profile.
As an alternative, another administrator profile with read-only permissions that permit usage of the CLI commands 'enabled' can be created and assigned to the admin accounts.
With the profile above, the admin user can run the diagnose commands, as well as other CLI commands.
Note: 'super_admin_readonly' profile cannot be edited, hence admin can create a new admin profile and customize the permission to run the config/diagnostic/execute/get/show commands.
As FGT-30G is a low-end model with limited memory resources, it is advised to check the memory utilization regularly to avoid high memory utilization or device going into memory conserve mode.
FGT30G # get sys performance status
FGT30G # get hardware status
FGT30G # diagnose sys logdisk usage
Related documents: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.