Fortinet Scanning Minimum Privileges
Scanner Requirements
The scanner requires an Administrator user with read or read/write permissions in the network or system group for configuration.
Create System Access Profile
Create New Access Profile Using CLI
Create or update a profile with the following configuration, or a later version.
Fortinet # config global # Only for the VDOM target
Fortinet (global) or Fortinet # config system accprofile
Fortinet (accprofile) # edit <profile_name>
Fortinet (<profile_name>) # set secfabgrp read
Fortinet (<profile_name>) # set authgrp read
Fortinet (<profile_name>) # set loggrp read
Fortinet (<profile_name>) # set fwgrp read
Fortinet (<profile_name>) # set vpngrp read
Fortinet (<profile_name>) # set utmgrp read
Fortinet (<profile_name>) # set wanoptgrp read
Fortinet (<profile_name>) # set wifi read
Fortinet (<profile_name>) # set ftviewgrp read
Fortinet (<profile_name>) # set sysgrp custom
Fortinet (<profile_name>) # set netgrp custom
Fortinet (<profile_name>) # config netgrp-permission
Fortinet (netgrp-permission) # set cfg read
Fortinet (netgrp-permission) # set route-cfg read
Fortinet (netgrp-permission) # end
Fortinet (<profile_name>) # config sysgrp-permission
Fortinet (sysgrp-permission) # set admin read-write
Fortinet (sysgrp-permission) # set cfg read-write
Fortinet (sysgrp-permission) # set upd read
Fortinet (sysgrp-permission) # set mnt read
Fortinet (sysgrp-permission) # end
Fortinet (<profile_name>) # set cli-diagnose enable
Fortinet (<profile_name>) # set cli-get enable
Fortinet (<profile_name>) # set cli-exec enable
Fortinet (<profile_name>) # set cli-show enable
Fortinet (<profile_name>) # set cli-config enable
Fortinet (<profile_name>) # end
CLI permissions are added to FortiGate OS 7.4.2.
Before FortiOS 7.4.2, CLI access was not broken down by command type (get, show, exec, and diagnose). Instead, CLI permission was tied directly to GUI access permission. For more information, refer to CLI system permissions.
Validate Profile Configuration
Validate a profile using the following configuration:
Fortinet # show system accprofile <profile_name>
config system accprofile
edit "profile_name"
set secfabgrp read
set ftviewgrp read
set authgrp read-write
set sysgrp custom
set netgrp custom
set loggrp read
set fwgrp read
set vpngrp read
set utmgrp read
set wanoptgrp read
set wifi read
set cli-diagnose enable
set cli-get enable
set cli-show enable
set cli-exec enable
set cli-config enable
config netgrp-permission
set cfg read
set route-cfg read
end
config sysgrp-permission
set admin read-write
set upd read
set cfg read-write
set mnt read
end
next
end
Create a New Access Profile Using GUI
To create a new access profile for scan:
- Sign in to the UI as an Admin user.
- Navigate to System > Admin Profiles.
- Click Create New.
- Type a user name and comment (comment is optional).
- Provide the following access permissions:
- Provide the Read access to Security Fabric, Firewall, and Log & Report.
- Provide the Read-Write access to User & Device.
- Under Network > provide the Read access to Configuration and Router.
- Under System > provide the Read-Write access to Administrator Users
- Under System > provide the Read access to FortiGuard Updates, Configuration, and Maintenance.
- Provide the Read to Security Profile.
- Provide the Read Access to VPN, WAN Opt & Cache, and Wifi & Switch.
- Set Permit usage of CLI Commands to Enable.
Create an Admin User for Scan
Create a New Scan User Using CLI
Fortinet # config global # Only for the VDOM target
Fortinet (global) or Fortinet # config system admin (To Create Administrator User for scanning)
Fortinet (admin) # edit "scan_user" # New User will be created with the name specified inside double quotes
new entry 'scan_user' added
Fortinet (scan_user) # set accprofile profile_name
Fortinet (scan_user) # set password <New User Password>
Please enter current administrator password: *********
Fortinet (scan_user) # set vdom root # Mandatory for VDOM Target/Optional for Non VDOM Target
Fortinet (scan_user) # end
Please enter current administrator password: *********
Validate the Profile Admin Setting
Fortinet # show system admin scan_user
config system admin
edit "scan_user"
set accprofile "profile_name"
set vdom "root"
set password ........
next
end
Create a New User Using UI
- Browse for the link https://<server_ip>, and sign in as an Admin user.
- Navigate to System > Administrator.
- Click Create New > Administrator.
- In the Username box, type a correct user name.
- In the Type list, click Local User.
- In the Password and Conform Password boxes, type a password.
- In the Administrator Profile list, click a newly created profile.
For more information, see Create an Admin User for Scan. - Click OK.
Commands Required for Scanning
diagnose debug info
diagnose sys ntp status
execute log display
get firewall policy
get router info routing-table static
get system info admin ssh
get system interface
get system status
show antivirus profile
show full-configuration
show full-configuration antivirus heuristic
show full-configuration antivirus profile
show full-configuration antivirus settings
show full-configuration application list
show full-configuration authentication scheme
show full-configuration dnsfilter profile
show full-configuration firewall DoS-policy
show full-configuration firewall local-in-policy
show full-configuration firewall policy
show full-configuration firewall service custom
show full-configuration firewall ssl setting
show full-configuration firewall ssl-ssh-profile
show full-configuration ips global
show full-configuration ips sensor
show full-configuration log disk setting
show full-configuration log eventfilter
show full-configuration log fortianalyzer2 setting
show full-configuration log fortianalyzer3 setting
show full-configuration log fortianalyzer setting
show full-configuration log fortianalyzer setting
show full-configuration log memory setting
show full-configuration log setting
show full-configuration log syslogd2 setting
show full-configuration log syslogd3 setting
show full-configuration log syslogd4 setting
show full-configuration log syslogd setting
show full-configuration router bgp
show full-configuration system accprofile
show full-configuration system admin
show full-configuration system auto-install
show full-configuration system automation-stitch
show full-configuration system autoupdate push-update
show full-configuration system autoupdate schedule
show full-configuration system csf
show full-configuration system dhcp server
show full-configuration system dns
show full-configuration system fortiguard
show full-configuration system global
show full-configuration system ha
show full-configuration system interface
show full-configuration system interface ssl.root
show full-configuration system netflow
show full-configuration system ntp
show full-configuration system password-policy
show full-configuration system password-policy
show full-configuration system proxy-arp
show full-configuration system replacemsg admin
show full-configuration system replacemsg admin pre_admin-disclaimer-text
show full-configuration system session-helper
show full-configuration system settings
show full-configuration system snmp community
show full-configuration system snmp sysinfo
show full-configuration system snmp user
show full-configuration system zone
show full-configuration user group
show full-configuration user ldap
show full-configuration user local
show full-configuration user radius
show full-configuration user setting
show full-configuration user tacacs
show full-configuration user tacacs+
show full-configuration vpn ssl settings
show full-configuration webfilter profile
show log syslogd setting
show system snmp community
show user local
show user tacacs+
Troubleshoot SSH Login Issues for a Newly Created User
To ensure a successful scan, log in to the UI, create the default dashboard, and edit a password. Until you complete these steps, the scan_user cannot log in directly to the system, and hence the scan fails.
- Browse for the link https://<server_ip>.
- Sign in with the following user credentials: for example, scan_user and the newly created password.
- Click Begin to start with the default setup at FortiGate.
- Click Comprehensive to apply all the default dashboard settings to a new administrator user (for example, scan_user).
- Click a user name list > Change Password.
- Ensure that a user is accessible and is not blocked by any policy.
- Qualys validates this procedure on the lab target FortiGate-VM64 v7.6.3, build3510,250415.