Hi,
I need to use someone to update signatures on Fortigate firewalls and not willing to give him super admin admin account. Is there any way to create an account with the minimum permissions just to be able to use execute restore ... command and update the firewall?
Regards,
Solved! Go to Solution.
Hi @mhdganji
You may want to try with the following setting:
config sysgrp-permission
set upd read-write
set cfg read
set mnt read-write
end
I'm using this except set admin ...
upd read/write
cfg read
mnt read/write
set scope global
This is the output
Get antivirus database from tftp server ok
command fail return code -85
Seems to be working but what is the -85 error code? Anyway to find the details about this error code and the results of the command?
Hi @mhdganji
You may want to try with the following setting:
config sysgrp-permission
set upd read-write
set cfg read
set mnt read-write
end
Hi mhdganji,
That was a clear explaination. Please try solution provided by my colleague(kcheng), and let us know your finding.
:)
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.