FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
vraev
Staff
Staff
Article Id 289383
Description

 

This article will describe the IPS profile enhancement under FortiManager.

 

Scope

 

FortiManager v7.4.2 and upward.

 

Solution

 

IPS object is introduced to separate the Firewall administrator from the IPS administrator and is an enhancement of the administrator profile.

Added the below as part of the profile configuration:

 

config system admin profile
policy-ips-attrs : none

 

user_no_ips_profile.png

  

After the profile for the new user is prepared, it can be assigned to the new user.

When the new user interacts with policies that had IPS and SSH they are grayed out, which means that the access to them is restricted.

 

user_no_ips.png

 

If the new user tries to create a new policy through GUI, CLI script, or API calls with the IPS profile to Policy Package or ADOM Database, an error would be shown that this user has no written permission to set it up.

 

user_no_ips_profile_script.png

 

Example:

 

no_ips_profile_742.gif

 

Troubleshooting:

Connect with a local 'admin' account under CLI and start the following debugs.

After that try to connect with the password change user:

 

diagnose debug reset

diagnose debug application auth 255

diagnose debug timestamp enable

diagnose debug enable

 

user_pass_troubleshooting.png

 

diagnose debug disable

diagnose debug reset

 

After reviewing the connected user/s, disable the debugs.

 

Related article:

Technical Tip: How to configure the 'Password Change User' admin profile in v7.4.2 FortiManager and ...

Contributors