Technical Tip: FortiDDoS administrator login lockout behavior
Description
This article explains the administrator login lockout behavior on FortiDDoS and clarifies the failed login threshold and lockout timer behavior.
Scope
FortiDDoS.
Solution
FortiDDoS includes a built-in administrator login protection mechanism to mitigate brute-force login attempts. On current firmware versions (branch v8.0.x), the following behavior is expected:
The Source IP address is temporarily blocked after 3 failed login attempts.
The 4th login attempt displays the message: IP has been blocked
The lockout duration is 1 minute on FortiDDoS v8.0.0.
Any additional login attempts during the lockout period reset the lockout timer back to 1 minute.
This behavior is hardcoded into the appliance and is currently not configurable through either the GUI or CLI.
It is recommended to upgrade to the latest General Availability firmware release to ensure behavior aligns with the latest product implementation and documentation.
