FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
maydin
Staff
Staff
Article Id 268426
Description

This article describes how to create a restricted user for EMS to get web filter updates.

EMS can be configured with a FortiGate user to get web filter profiles regularly, this can be seen in the following link : 
Importing a Web profile from FortiOS or FortiManager.


EMS needs to use a FortiGate user for this. Since this is only a read operation, this user can be restricted. 

Scope All FortiGate.
Solution

This is a read operation on security profiles, so the user configured in EMS only needs this access. An admin profile for this access can be configured like below : 

 

admin_profile.png

 

And this profile should be chosen in user configuration : 

 

user_config.png

 

Now, EMS can be configured with this user to pull web filter profiles and updates like the below screenshot: 

 

EMS_config.png

 

After configuration, it can be seen that EMS has no issues pulling web filter profiles: 

 

EMS_first_successful_sync.png

 

Further testing can be done by updating the web filter profile named 'default'. It can be seen below that EMS got the update successfully: 

 

EMS_succesful_update.png

 

On FortiGate, successful logon of the user can also be observed: 

 

Fortigate_succesful_logons.png

 

Result: For EMS to pull web filter profiles from FortiGate, an admin with read rights on security profiles is enough.