Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kiminou
New Contributor

How to prevent or forbid any CLI changes on Fortigate once it is integrate to FortiManager

Hello

We manage all fortigates from FortiManager, I want to prevent or forbid any changes directly on Fortigate, changes need to be done from fortimanager. How can I reach this goal ? Any suggestion will be welcome.

Thanks

1 REPLY 1
Yurisk
SuperUser
SuperUser

You can set up a custom Access Profile for such admins in which you disable everything-CLI. 

See example of how to enable CLI commands - just do the reverse, unselect CLi commands.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enable-config-options-in-custom-admin-acce...

 

If you want to force people to do changes only via FMG, just assign all admins on Fortigates read-only profile, and leave just one super_admin user (for emergency access) password of which is kept safe away from regular admins.

 

https://yurisk.info
https://yurisk.info
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors