Skip to main content
ede_pfau
SuperUser
SuperUser
June 30, 2009
Question

admin login blocking time

  • June 30, 2009
  • 5 replies
  • 5029 views
On a FG310B, running 3.00MR7px, I see a lot of login attempts via ssh. After 3 unsuccessful attempts the FGT blocks access for 60 seconds. a) will it block the offending source IP only, or ssh access altogether? b) can you configure the blocking duration? In 24 hours, these creeps try every minute to get in. The source IP changes after 3 attempts. We see this a lot with other ssh servers as well. Prolonging the block duration would relieve the FGT and the logging device. Ede

    5 replies

    Contributor III
    June 30, 2009
    concerning a) it only blocks the access from the IP that had to many unsuccessfull attempts. Login from other IP addresses is still possible. concerning b) I don' t know if it is possible to modify the value for the blocking-time, but I would suggest you use trusted hosts for your administrator accounts. Trusted hosts will make sure that login is only possible from the IPs you have specified as trusted hosts.(You can specify up to three hosts or networks) All attempts to log in from other IP addreses will be blocked.
    ede_pfau
    SuperUser
    ede_pfauAuthor
    SuperUser
    June 30, 2009
    for b) I cannot use trusted hosts as I will access the FGT from a DSL line, meaning every 24h a different IP is allocated by our provider. Ede
    emnoc
    New Member
    June 30, 2009
    To adjust the admin lock try the following in global settings set admin-lockout-duration set admin-lockout-threshold
    ede_pfau
    SuperUser
    ede_pfauAuthor
    SuperUser
    July 1, 2009
    @emnoc, that is exactly what I needed. Thanks a lot. posts like yours should be made permanent for others to search. Ede
    emnoc
    New Member
    July 1, 2009
    I have a Fortigate setup on a LAN segment that I have 2 honeypots locate on and it' s funny to see who, and what the internet trys to uses aganist your firewall. With email alert logging and syslog, I can get great information on when ssh session attempts are being executed.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!