
Permission Type Descriptions
Write
In addition to read permission, the user can modify existing objects, but cannot add new objects or
delete existing objects.
For global parameters: the user can update allglobal parameters (including parameters that are not
already assigned a value). The user cannot, however, add or delete global objects (for example:
logins, clusters, and responders).
For clusters: the user can modifythe values assigned to allcluster parameters (including parameters
that are not already assigned a value). The user cannot add or delete a cluster object (for example, a
server or match rule.)
Create
In addition to write permission, the user can add new objects.
For global parameters: the user can add and delete global objects (for example: logins, clusters, and
responders).
For clusters: the user can add a cluster object (for example, a server or match rule.)
Delete
In addition to write permission, the user can delete existing objects.
For global parameters: the user can delete global objects (for example: logins, clusters, and
responders).
For clusters: the user can delete a cluster object (for example, a server or match rule.)
Required Task Permissions and Flags
The table below shows the permissions required for all object and administrative tasks in the CLI and the GUI.
Operation Permissions Required Flags Required Notes
adding a certificate file
write certificate_name
adding a CRL file
write crl
adding a private key file
write certificate_name
adding a certificate
create certificate
adding a cluster
create clusterwrite
vlan_name
read certificate_name
read crl_name
adding a CRL
create crl
adding a DNS server
write_
global
Copyright © 2013 Coyote Point Systems. A subsidiary of Fortinet, Inc.
All Rights Reserved.
501
Equalizer Administration Guide
Comentários a estes Manuais