12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

System Administrators<br />

Access profiles<br />

Access profiles<br />

Each administrator account belongs to an access profile. The access profile<br />

separates <strong>FortiGate</strong> features into access control categories for which you can<br />

enable read and/or write access. The following table lists the web-based manager<br />

pages to which each category provides access:<br />

Table 29: Access profile control of access to Web-based manager pages<br />

Access control<br />

Admin Users<br />

Antivirus Configuration<br />

Auth Users<br />

Firewall Configuration<br />

FortiGuard Update<br />

IPS Configuration<br />

Log & Report<br />

Maintenance<br />

Network Configuration<br />

Router Configuration<br />

Spamfilter Configuration<br />

System Configuration<br />

VPN Configuration<br />

Webfilter Configuration<br />

Affected web-based manager pages<br />

System > Admin<br />

System > Admin > FortiManager<br />

System > Admin > Settings<br />

AntiVirus<br />

User<br />

Firewall<br />

System > Maintenance > FortiGuard Center<br />

Intrusion Protection<br />

Log & Report<br />

System > Maintenance<br />

System > Network > Interface<br />

System > Network > Zone<br />

System > DHCP<br />

Router<br />

AntiSpam<br />

System > Status, including Session info<br />

System > Config<br />

System > Hostname<br />

System > Network > Options<br />

System > Admin > FortiManager<br />

System > Admin > Settings<br />

System > Status > System Time<br />

VPN<br />

Web Filter<br />

Read-only access enables the administrator to view the web-based manager<br />

page. The administrator needs write access to change the settings on the page.<br />

You can now expand the firewall configuration access control to enable more<br />

granular control of access to the firewall functionality. You can control<br />

administrator access to policy, address, service, schedule, profile, and other (VIP)<br />

configurations.<br />

Note: When Virtual Domain Configuration is enabled (see “Settings” on page 175), only the<br />

administrators with the access profile super_admin have access to global settings. When<br />

Virtual Domain Configuration is enabled, other administrator accounts are assigned to one<br />

VDOM and cannot access global configuration options or the configuration for any other<br />

VDOM.<br />

For information about which settings are global, see “VDOM configuration settings” on<br />

page 72.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 169

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!