Hi All,
is it possible to create a read only account that can run below command
config global config system console set out standard end show null
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
I'm not sure I understand the question well, but I don't think you can filter permissions that much. Take a look at the access profiles: https://docs.fortinet.com/document/fortigate/6.2.2/cli-reference/2620/system-accprofile
and administration profiles: https://docs.fortinet.com/document/fortigate/latest/administration-guide/294491/administrator-profil...
You can filter much of the information to the administrator of your choice, but not as much.
Thank you Alexis,
i need an account that can run the above command but with out any permission to change any settings
Hi,
if you only need the user to be unable to modify, a read only user is sufficient. If, in addition, you only want me to see certain parts of the configuration, you will need test with the profiles.
Br
Not exactly a read-only administrator user, but rather a user that can run only selected set of CLI commands - no, built-in means of Fortigate do not provide such option.
thank you all
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.