Hello
We manage all fortigates from FortiManager, I want to prevent or forbid any changes directly on Fortigate, changes need to be done from fortimanager. How can I reach this goal ? Any suggestion will be welcome.
Thanks
You can set up a custom Access Profile for such admins in which you disable everything-CLI.
See example of how to enable CLI commands - just do the reverse, unselect CLi commands.
If you want to force people to do changes only via FMG, just assign all admins on Fortigates read-only profile, and leave just one super_admin user (for emergency access) password of which is kept safe away from regular admins.
User | Count |
---|---|
2549 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.