Friday, October 30, 2020

HOWTO: lock out users from fortios

 FortiOS does not have a direct mean for disabling an administrator account. 


So if you want to be config exclusive and prevent others from gaining access, you have to use a readonly or a accessprofile with nothing allowed.


Take this user ansible and the accprofile assigned;





So if this user does login to the fortigate,  he will be limited to executing NO commands


e.g 




Ken Felix 
NSE ( network security expert) and Route/Switching Engineer
kfelix  -----a----t---- socpuppets ---dot---com
     ^      ^
=(  @  @ )=
         o

        /  \

No comments:

Post a Comment