12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Access profiles<br />

System Administrators<br />

The access profile has a similar effect on administrator access to CLI <strong>com</strong>mands.<br />

The following table shows which <strong>com</strong>mand types are available in each access<br />

control category. You can access “get” and “show” <strong>com</strong>mands with read access.<br />

Access to “config” <strong>com</strong>mands requires write access.<br />

Table 30: Access profile control of access to CLI <strong>com</strong>mands<br />

Access control<br />

Admin Users (admingrp)<br />

Antivirus Configuration (avgrp)<br />

Auth Users (authgrp)<br />

Firewall Configuration (fwgrp)<br />

FortiProtect Update (updategrp)<br />

IPS Configuration (ipsgrp)<br />

Log & Report (loggrp)<br />

Maintenance (mntgrp)<br />

Network Configuration (netgrp)<br />

Router Configuration (routegrp)<br />

Available CLI <strong>com</strong>mands<br />

system admin<br />

system accprofile<br />

antivirus<br />

user<br />

firewall<br />

Use the set fwgrp custom and config<br />

fwgrp-permission <strong>com</strong>mands to set some<br />

firewall permissions individually. Selections can<br />

be made for policy, address, service, schedule,<br />

profile, and other (VIP) configurations. For more<br />

information, see <strong>FortiGate</strong> CLI Reference.<br />

system autoupdate<br />

execute update-av<br />

execute update-ips<br />

execute update-now<br />

ips<br />

alertemail<br />

log<br />

system fortianalyzer<br />

execute log<br />

execute formatlogdisk<br />

execute restore<br />

execute backup<br />

execute batch<br />

execute usb-disk<br />

system arp-table<br />

system dhcp<br />

system interface<br />

system zone<br />

execute dhcp lease-clear<br />

execute dhcp lease-list<br />

execute clear system arp table<br />

execute interface<br />

router<br />

execute router<br />

execute mrouter<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

170 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!