System Admin
Access profiles
FortiGate-5000 series Administration Guide
01-28008-0013-20050204
123
When you set trusted hosts for all administrators, the FortiGate unit does not respond
to administrative access attempts from any other hosts. This provides the highest
security. If you leave even one administrator unrestricted, the unit accepts
administrative access attempts on any interface that has administrative access
enabled, potentially exposing the unit to attempts to gain unauthorized access.
The trusted hosts you define apply both to the web-based manager and to the CLI
when accessed through telnet or SSH. CLI access through the console connector is
not affected.
Access profiles
Go to
System > Admin > Access Profile
to add access profiles for FortiGate
administrators. Each administrator account belongs to an access profile. You can
create access profiles that deny access or allow read-only or both read and write
access to FortiGate features.
When an administrator has only read access to a feature, the administrator can
access the web-based manager page for that feature but cannot make changes to the
configuration. There are no Create or Apply buttons and lists display only the
View (
) icon instead of icons for Edit, Delete or other modification commands.
Access profile list
Figure 48: Access profile list
Note:
If you set trusted hosts and want to use the Console Access feature
of the web-based
manager, you must also set 127.0.0.1/255.255.255.255 as a trusted host. For more
information on the Console Access feature, see
“Console Access” on page 28
.
Create New
Add a new access profile.
Profile Name
The name of the access profile.
Delete icon
Select to delete the access profile.
You cannot delete an access profile that has administrators assigned to it.
You cannot ever delete the prof_admin access profile.
Edit icon
Select to modify the access profile.
Содержание FortiGate FortiGate-5020
Страница 86: ...86 01 28008 0013 20050204 Fortinet Inc Dynamic IP System DHCP ...
Страница 118: ...118 01 28008 0013 20050204 Fortinet Inc FortiManager System Config ...
Страница 254: ...254 01 28008 0013 20050204 Fortinet Inc CLI configuration User ...
Страница 318: ...318 01 28008 0013 20050204 Fortinet Inc CLI configuration Antivirus ...
Страница 350: ...350 01 28008 0013 20050204 Fortinet Inc Using Perl regular expressions Spam filter ...
Страница 370: ...370 01 28008 0013 20050204 Fortinet Inc CLI configuration Log Report ...
Страница 382: ...382 01 28008 0013 20050204 Fortinet Inc Glossary ...
Страница 402: ...402 01 28008 0013 20050204 Fortinet Inc Index ...