Configuring an SSH filter profile on FortiPAM to restrict SSH access to secret servers
The FortiPAM SSH filter allows you to control SSH access to a secret server so that only specific commands execute.
Starting FortiPAM 1.4.0, SSH filter profiles can operate in two modes:
-
Deny: You can configure a list of SSH command patterns that cannot be used by the FortiPAM user.
-
Allow: You can configure a list of SSH command patterns that can be executed by the user.
Other commands entered by the user are blocked by FortiPAM.