Skip to main content
xdail
Visitor III
March 15, 2024
Solved

Local account lockout policy - FortiGateRugged 60F 7.4.2

  • March 15, 2024
  • 1 reply
  • 2119 views

Hello,
I am trying to implement unsuccessful login attempts policy for local users.
So if the user puts 5 times wrong password then he will be locked for some time.
There are two local admin accounts.

I have setup this, but the problem is that it will lockout whole firewall for login and not only user

config system global
    set admin-lockout-duration 300
    set admin-lockout-threshold 10
end

So I have tried this setting, but it seems that it is not triggered. Is this setting even relevant for local administrators ?

config user setting
    set auth-lockout-threshold 5
    set auth-lockout-duration 900
end

Thank you
BR.
D

Best answer by ozkanaltas

Hello @xdail ,

 

Admin lockout time bans the admin's IP address, not the user. If you change your IP address, you can log in again. 

 

The second one is related to local users such as the ssl-vpn connection, not an administrator user. 

 

1 reply

ozkanaltas
Valued Contributor III
March 15, 2024

Hello @xdail ,

 

Admin lockout time bans the admin's IP address, not the user. If you change your IP address, you can log in again. 

 

The second one is related to local users such as the ssl-vpn connection, not an administrator user. 

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.