Hi,
I have a FortiManager running 7.4 with three ADOMs. I am using tacacs+ wildcard authentication with accprofile override using Cisco ISE as authentication server. All administrators authentication get Read_Write profile for all ADOMs.
I would like to use the feature per-ADOM admin profile as described in this article to give administrators belonging to "Group1" to get Read_Write for one of the ADOMs and Read_Only for all of the others. From the article above this seems possible with ext-auth-adom-override enabled. However, I am not sure how this would be configured on the tacacs server as that is not covered in the article.
Today I send the following attributes from TACACS server:
service=fortigate
admin_prof=Read_Write
adom=Adom1
adom=Adom2
adom=Adom3.
How should I configure the tacacs server to send Read_Write for Adom1 and Read_Only for Adom2 and Adom3?
hi @FXD
check this article:
Configure RADIUS for authentication and a... - Fortinet Community
Thanks
Hi @asrour
I have read the article, which covers radius, but the examples are only showing how to give the same access profile to all of the ADOMs. I am trying to figure out how to give users in "Group1" read-write to ADOM1 and read-only to ADOM2 & ADOM3.
Going back to the article I found and linked in my previous post this seems possible, in that example users get Profile1 to ADOM1 and Profile2 to ADOM2.
User | Count |
---|---|
2551 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.