Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AEK
SuperUser
SuperUser

No sudo on FortiNAC anymore?

Hi FNAC admins and 

It seems on FortiNAC-F 7.4 and 7.6 (didn't test on 7.2), when doing enter-shell the user admin can't do sudo.

Is there a special way to do that or has it just been removed?

AEK
AEK
1 Solution
ebilcari
Staff
Staff

In FNAC-OS, full root access via the shell is no longer possible. However, certain specific commands can still be executed using 'sudo' without requiring a password, such as:


sudo tcpdump port 1812 -vn

sudo grab-log-snapshot

sudo journalctl

sudo /bin/cmdb/upgrade FNAC_ESX-v7.4.1-build0451-FORTINET.out

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.

View solution in original post

2 REPLIES 2
ebilcari
Staff
Staff

In FNAC-OS, full root access via the shell is no longer possible. However, certain specific commands can still be executed using 'sudo' without requiring a password, such as:


sudo tcpdump port 1812 -vn

sudo grab-log-snapshot

sudo journalctl

sudo /bin/cmdb/upgrade FNAC_ESX-v7.4.1-build0451-FORTINET.out

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
AEK

Thanks for your feedback, Emirjon.

Farewell full access but indeed this is a very good security measure for such critical alliance.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors