- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Read only account to get device configuration
Hi All,
is it possible to create a read only account that can run below command
config global config system console set out standard end show null
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
I'm not sure I understand the question well, but I don't think you can filter permissions that much. Take a look at the access profiles: https://docs.fortinet.com/document/fortigate/6.2.2/cli-reference/2620/system-accprofile
and administration profiles: https://docs.fortinet.com/document/fortigate/latest/administration-guide/294491/administrator-profil...
You can filter much of the information to the administrator of your choice, but not as much.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you Alexis,
i need an account that can run the above command but with out any permission to change any settings
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
if you only need the user to be unable to modify, a read only user is sufficient. If, in addition, you only want me to see certain parts of the configuration, you will need test with the profiles.
Br
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not exactly a read-only administrator user, but rather a user that can run only selected set of CLI commands - no, built-in means of Fortigate do not provide such option.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
thank you all
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Update if anybody got to this thread. A possible answer to this may be utilising TACACS+ to authorise commands. It might be a killer depending on your use case, but still.
