Hi there,
I would like to know how to allow a profile to use the "diagnose" command. Currently we have a readonly profile with everything set to readonly, but we don't know wich section is in control for the access to this command.
Is there a document who describe the relationship between access control sections and commands related to it ?
Regards !
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I don't believe that would be possible, the AAA function in FortiOS is a "access profile" based and not commands.
PCNSE
NSE
StrongSwan
Hi Akid,
Below is a document that should explain how different admin profiles can be created:
http://help.fortinet.com/fweb/537/Content/FortiWeb/fortiweb-admin/config_access_profiles.htm
That being said, Fortigate is not modular enough yet to associate a profile with a subset of specified commands.
I hope that helps.
NSE5, CCSE, CCNA R&S, CompTIA A+, CompTIA Network+, CompTIA Security+, MTA Security, ITIL v3
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.