System Admin Administrators
FortiGate Version 3.0 MR4 Administration Guide
01-30004-0203-20070102 143
System Admin
This section describes how to configure administrator accounts on your FortiGate
unit. Administrators access the FortiGate unit to configure its operation. In its
factory default configuration, the unit has one administrator, admin. After
connecting to the web-based manager or the CLI, you can configure additional
administrators with various levels of access to different parts of the FortiGate unit
configuration.
This section includes the following topics:
• Administrators
• Access profiles
• FortiManager
• Settings
• Monitoring administrators
Administrators
There are two levels of administrator accounts:
• regular administrator - an administrator with any access profile other than
super_admin
• system administrator - includes the original system administrator ‘admin’, and
any other administrators assigned to the super_admin profile
A regular administrator account has access to configuration options as
determined by its access profile. If virtual domains are enabled, the regular
administrator is assigned to one VDOM and cannot access global configuration
options or the configuration for any other VDOM. For information about which
options are global and which are per-VDOM, see “VDOM configuration settings”
on page 62 and “Global configuration settings” on page 63.
Any administrator assigned to the super_admin access profile, as well as the
default administrator account ‘admin’, has full access to the FortiGate unit
configuration. In addition, they can:
• enable VDOM configuration
• create VDOMs
• configure VDOMs
• assign regular administrators to VDOMs
• configure global options
You cannot restrict or modify the privileges of the original ‘admin’ administrator.
You cannot delete the ‘admin’ account, but you can rename it, define trusted
hosts for it, and change its password. By default, ‘admin’ has no password.
Note: Always end your FortiGate session by logging out, in the CLI or the GUI. If you do
not, the session remains open.