Understanding Access Profiles and Users
Access Profiles
Fortinet product
software
uses the concept of Access Profiles to define the access level of a
user. Access profiles control which CLI commands an administrator account can
access. Access profiles can assign either read, write, or no access to each area of
the
software.
You must
have
read access level rights
to view
configurations.
To make configuration changes, you must have write access level rights.
Write
Access is
required
to view configurations and
troubleshoot
using the
get,
diagnose,
and
exec
commands.
Unlike other Administrator
accounts,
the
default
Administrator account named
admin
exists by default and cannot be deleted. The
admin
account is
similar
to a
root
administrator
account.
This administrator account always has full permission to view and change all
device
configuration options, including viewing and changing all other administrator
accounts. However, its name and permissions cannot be changed.
Setting up the LiveAssurance User:
This user can be assigned to the predefined super_admin level profile
to execute all the required
get
<x>,
exec
<x>,
and
diagnose
<x>
CLI commands.
The
get
and
exec
CLI
commands
can be
executed with a Read-Only
user
but not the
diagnose
commands.
Therefore,
it is strongly recommended to create, or use an existing account, with admin
(read-write) level rights so the LiveAssurance
automation platform can provide more content around potential issues and remediation
steps for all Fortinet Rules.
Configuring the LiveAssurance User:
This example adds a
new
administrator account that uses a new administrative access profile
with full read-write access. Account
access
will be limited to connections from a specific IP subnet. The configuration is
applied via
https
access to the
device,
so a user with admin privilege rights is required to perform the following steps
(e.g. the default admin user).
An
existing user account
(such as
the default admin account in this example) can be
reused by the LiveAssurance Monitoring
Platform.
Step 1: Creating a New Administrative Profile
Navigate
to . Create a new
Administration
Profile that allows the
user
with this profile to run all the
get,
exec,
and
diagnose
CLI commands.
| FortiGate | FortiAnalyzer |
|---|---|
|
|
|
|
|
|
exec,
get
and
diagnose
commands via CLI. The default prof_admin and super_admin can also be
used.Step 2: Creating and Assigning a New User
A new administrator is added and assigned to the new admin-profile by navigating to . Create a new administrator account for the user and assign it to the profile that was just created (that is, indeni-user in this example). You can restrict access to the firewall to login from Trusted Hosts Only by adding the IP address range to one of the Trusted Host fields. You can use the IP address of the LiveAssurance Server in case that this account is used only by LiveAssurance.
| FortiGate | FortiAnalyzer |
|---|---|
|
|
|
|
|
|
Step 3: Verification & Results
Once you have successfully added the credentials and successfully interrogated a device, log in using an account with admin rights (for example, the default admin account) and navigate to , and view the System Information widget.
Verification:
- FortiGate: Select Details for the Current Administrator to view all administrators logged in. Confirm that the LiveAssurance server has logged in to the Fortinet firewall by using the newly created user and an SSH session.
- FortiAnalyzer: View the System Information widget and select Current Sessions List.
| FortiGate | FortiAnalyzer |
|---|---|
|
|
|
|
|
Event Log navigation:
- FortiGate: Navigate to .
- FortiAnalyzer: Navigate to .
| FortiGate | FortiAnalyzer |
|---|---|
|
|
|
In both cases: look at the upper pane to see more activity, such as the successful login of the LiveAssurance account. Select the entry for the new administrator login to display more details in the lower pane, confirming the new administrator account logged in from an IP address within the ranges specified in the Trusted Hosts field.
Frequently Asked Questions
Which Fortinet devices does LiveAssurance support ?
LiveAssurance currently only supports FortiGate firewalls and FortiAnalyzer log management appliances.
How does LiveAssurance communicate with FortiGate firewalls and FortiAnalyzer log management appliances?
The LiveAssurance platform collects information from FortiGate and FortiAnalyzer via direct SSH access to the devices. Now, let’s see that in action by using FortiGate as an example.
As is illustrated above, LiveAssurance has been installed and configured with the private IP address 10.10.8.116.
Here we see that a FortiGate VM64 has been discovered and is now being monitored by the LiveAssurance platform. Remember, LiveAssurance uses the admin Fortinet user to get direct access via SSH to the FortiGate. As a result, an admin user with the source IP address of 10.10.8.116 is logged in to the firewall.
In summation, LiveAssurance collects all the required information for analysis via SSH access to a Fortinet Firewall, so a user with super-admin rights should be assigned to the user.
What does LiveAssurance do to ensure that it is not negatively impacting the performance of the device?
Thorough testing has been performed at the LiveAssurance Lab to determine the recommended minimum CPU and Memory requirements of a Fortinet firewall required to be monitored by the LiveAssurance platform.
It was noted that an increased demand for Memory and CPU utilization was recorded during the discovery (interrogation) of the Fortinet firewall by the LiveAssurance platform. This is expected behavior. We recorded a drop, and stabilization, of systems resources after discovery and normal Rule interrogation against the devices began.
It is strongly recommended that the Fortinet Firewall have a minimum 4 CPU cores and 4GB RAM to ensure peak device performance. All mid-range Fortinet Firewalls, starting from the FG-100E Series, have the minimum hardware requirements to be effectively monitored by LiveAssurance.
You can review the CPU/RAM resources and utilization of a firewall by running the
following command:
get
system performance
status
If I already have FortiManager, why do I still need LiveAssurance?
If I already have FortiAnalyzer, why do I still need LiveAssurance?
FortiAnalyzer and LiveAssurance are different products and LiveAssurance now monitors FortiAnalyzer devices.