Admin profiles
System Admin
FortiGate Version 4.0 Administration Guide
222
01-400-89802-20090424
Admin profiles
Each administrator account belongs to an admin profile. The admin profile separates
FortiGate features into access control categories for which an administrator with
read/write access can enable none (deny), read only, or read/write access.
The following table lists the web-based manager pages to which each category provides
access:
Read-only access enables the administrator to view the web-based manager page. The
administrator needs write access to change the settings on the page.
You can expand the firewall configuration access control to enable more granular control
of access to the firewall functionality. You can control administrator access to policy,
address, service, schedule, profile, and other virtual IP (VIP) configurations.
Table 39: Admin profile control of access to Web-based manager pages
Access control
Affected web-based manager pages
Admin Users
System > Admin
System > Admin > Central Management
System > Admin > Settings
Antivirus Configuration
UTM > AntiVirus
Auth Users
User
Firewall Configuration
Firewall
FortiGuard Update
System > Maintenance > FortiGuard
IM, P2P & VoIP Configuration
IM, P2P & VoIP > Statistics
IM, P2P & VoIP > User > Current Users
IM, P2P & VoIP > User > User List
IM, P2P & VoIP > User > Config
IPS Configuration
UTM > Intrusion Protection
Log&Report
Log&Report
Maintenance
System > Maintenance
Network Configuration
System > Network > Interface
System > Network > Zone
System > DHCP
Router Configuration
Router
Spamfilter Configuration
UTM > AntiSpam
System Configuration
System > Status, including Session info
System > Config
System > Hostname
System > Network > Options
System > Admin > Central Management
System > Admin > Settings
System > Status > System Time
VPN Configuration
VPN
Webfilter Configuration
UTM > Web Filter
Note:
When
Virtual Domain Configuration
is enabled (see
administrators with the admin profile super_admin have access to global settings. Other
administrator accounts are assigned to one VDOM and cannot access global configuration
options or the configuration for any other VDOM.
For information about which settings are global, see
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...