Skip to main content
bkashava
Staff
Staff
May 25, 2026

Technical Tip: FortiDDoS administrator login lockout behavior

  • May 25, 2026
  • 0 replies
  • 34 views

Description


This article explains the administrator login lockout behavior on FortiDDoS and clarifies the failed login threshold and lockout timer behavior.


Scope


FortiDDoS.


Solution


FortiDDoS includes a built-in administrator login protection mechanism to mitigate brute-force login attempts. On current firmware versions (branch v8.0.x), the following behavior is expected:

  1. The Source IP address is temporarily blocked after 3 failed login attempts.

  2. The 4th login attempt displays the message: IP has been blocked

  1. The lockout duration is 1 minute on FortiDDoS v8.0.0.

  2. Any additional login attempts during the lockout period reset the lockout timer back to 1 minute.


This behavior is hardcoded into the appliance and is currently not configurable through either the GUI or CLI.


It is recommended to upgrade to the latest General Availability firmware release to ensure behavior aligns with the latest product implementation and documentation.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!