Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
flamer
New Contributor II

Removing a single vdom from FM

hi all,

 

we have a 600D with 10 vdoms. The FM is logically connected in a secure DMZ. One of the vdom's is dedicated for a 3rd party who do all management of it. 

 

Is there  away I can either

1) remove the single vdom for fortimanager

2) provide an account that can write to the device without having super_admin access to all the other vdoms on the device

 

right now their account can login in, is presented with the "managed by foritmanager" message but read only mode is the only option. The only way I have found around this is changing the account to super admin which gives them the option to enter as read/write mode but I cannot lock them down to their specific vdom after that.

 

thanks

2 REPLIES 2
chall_FTNT
Staff
Staff

It looks like your goal is to allow this 3rd party access to their VDOM.  I would recommend you consider doing that through the FortiManager GUI by setting up a restricted admin account for them.  Individuals VDOMs can also be placed in separate ADOMs on the FortiManager.

 

As for the FGT GUI, by design, only super-admin accounts are given the option to override the Read-Only restriction.

Chris Hall
Fortinet Technical Support
flamer
New Contributor II

Thanks for that, I do realise adom in FM may be the only solution but our issue with that is, the Fortimanager has a Single IP in a private network, so the issue is they physically cannot get to that IP address range, currently they connect to an interface on the fortigate that is physically connected into their LAN. 

 

thanks

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors