| Description | This article describes the TACACS attributes that need to be configured on a TACACS server to override accprofile. |
| Scope | FortiSwitch 7.4.x and above. |
| Solution |
In some deployments, it is required to allow remote administrators to log in to FortiSwitch using a TACACS server, where the TACACS server assigns role-based access (for example, read-only or read-write) based on the administrator’s credentials.
Refer to the following configuration:
config user tacacs+
config user group
config system admin
service = fortigate {
Note: <Profile name> should be configured to the same value as it is on the FortiSwitch. For example, the FortiSwitch Configuration is:
config system accprofile
Related document: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.