Skip to main content
JNDias
Staff & Editor
Staff & Editor
June 24, 2023

Technical Tip: FortiGate with multiple wildcard admins authentications and VDOMs

  • June 24, 2023
  • 0 replies
  • 3489 views
Description This article explains when to use remote admin accounts to manage a FortiGate. It is a normal practice to have external authentication for the Firewall administrator to log in or for Guest sponsor access, but it is necessary to take special attention when there are VDOMs.
Scope FortiGate v6.4, v7.0, v7.2, v7.4, v7.6.
Solution

Definition:

  • Remote (Match a user on a remote server Group).
  • Remote+Wildcard (Match all users in a remote server Group).

 

When FortiOS receives a system login request, it first looks for a system admin account whose name exactly matches the requested name. If it cannot find an exact match, FortiOS will look for a wildcard system admin account, either global or vdom specific, whichever comes first. In this case, the global wildcard account is always returned first, which is expected according to source codes.


It is recommended to have one wildcard admin per VDOM, otherwise, the authentication will only be done towards the group with the most alphabetical order preference. 'Global wildcard admin user' will be present in all VDOMs, thus if the name of the group makes it first in the list it will be the only one matched for all wildcard users. This is also true, when wildcard users refers to user groups that belong to different servers ( Radius, LDAP or TACACS) . It is recommended to have each Firewall administrator as a 'remote' only 'Match a user on remote server Group'. This also means it is necessary to create one global wildcard system admin account or one wildcard system admin account for each VDOM, not one for both.

 

Create a user that will then be mapped to a Remote Group.

 

2023-06-23_17-20.png

 

Although it is possible to use 'Remote+Wildcard', it is necessary to keep in mind the limitation of having only one group.

 

Consider the following option:

Have admin (Remote+Wildcard) settings for admin profiles or guest admins attached to the correct VDOM (access should be acquired from the VDOM Management IP), then have admin (Remote) settings for the global admin.

 

Related documents:

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!