Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nbgiridar
New Contributor

Read only account to get device configuration

Hi All,

 

is it possible to create a read only account that can run below command 

 

config global config system console set out standard end show null 

5 REPLIES 5
Alexis_Esp
New Contributor

Hello,

 

I'm not sure I understand the question well, but I don't think you can filter permissions that much. Take a look at the access profiles: https://docs.fortinet.com/document/fortigate/6.2.2/cli-reference/2620/system-accprofile

 

and administration profiles: https://docs.fortinet.com/document/fortigate/latest/administration-guide/294491/administrator-profil...

 

You can filter much of the information to the administrator of your choice, but not as much.

 

nbgiridar

Thank you Alexis, 

 

i need an account that can run the above command but with out any permission to change any settings

Alexis_Esp

Hi,

 

if you only need the user to be unable to modify, a read only user is sufficient. If, in addition, you only want me to see certain parts of the configuration, you will need test with the profiles.

 

Br

Yurisk

Not exactly a read-only administrator user, but rather a user that can run only selected set of CLI commands - no, built-in means of Fortigate do not provide such option. 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
nbgiridar

thank you all

Labels
Top Kudoed Authors