Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ntluan56
New Contributor II

About vdom user configuration backup permission

Hello everyone,

 

We recently upgraded FortiOS from version 6.2.15 to 7.2.5. Our current configuration setting is as follows:

  • Admin Profiles → System → Configuration is set to "Read," allowing vdom users to back up their configuration. However, they cannot enable "Feature Visibility."

After the upgrade to 7.2.5, vdom users encounter an "Access denied" error when attempting to back up their configurations. To temporarily address this issue, we had to grant "Read/Write" permissions, but this inadvertently allowed users to enable "Feature Visibility" for their vdom.

Are there any better solutions or approaches to resolve this issue?

 

Best regards

3 REPLIES 3
ekrishnan
Staff
Staff

Hi,

 

I believe this is a change in newer version and either you need to choose access NONE for the system config to achieve your goal, I am afraid no other way can be seen as the Feature visibility is tagged under the system config on the current versions.

 

EK
Nchandan
Staff
Staff

Refining permissions, using RBAC, conducting regular audits, providing training, and implementing safeguards like workflow approval and monitoring, you can resolve the issue of "Access denied" errors during configuration backups while preventing unintended changes to "Feature Visibility" by VDOM users.

ntluan56
New Contributor II

Dear Nchandan and Ekrishnan,
Since vdom users are our customers, we are considering announcing this to them.

Thank you for your support.

Labels
Top Kudoed Authors