Skip to main content
Adonist
New Member
September 14, 2018
Solved

Mass create or bulk import users

  • September 14, 2018
  • 9 replies
  • 22639 views

Hi,

 

We are switching our firewall to Fortigate and will be using SSLVPN with local users.

Is there a way to mass create users or import it from a csv ?

 

Thanks

    Best answer by ede_pfau

    Two hints:

     

    1- if you have a long user list, don't directly paste it to the CLI. Chances are high that you will get a timing error, and that not all of the input is actually 'taken'. Rather, submit the same file (which is a partial config file) via 'Advanced > Batch command'. This will upload all data first, and then import into the running config.

     

    2- if you have along user list, consider adding your LDAP (or MS-AD) as a 'remote user'. User management (who is granted SSLVPN access, who is removed from SSLVPN etc.) is then done via LDAP management. For instance, if you connect the FGT to your MS-AD, and create a user group in the MS-AD like 'SSLVPN users', you grant VPN access by dropping a user into this group. User management is completely independent of the Fortigate, and the config on your FGT is not touched in the future.

     

    Of course, this only pays out if you already manage users by LDAP or MS-AD.

     

    BTW, you can also grant admin access via LDAP, using a 'remote admin wildcard account'. Sound difficult but isn't.

     

    These methods are well documented in the Cookbook or KB.

    9 replies

    xsilver_FTNT
    Staff
    Staff
    September 14, 2018

    Sure, every user is just record in 'config user local'.

    Have s look into CLI or CLI guide on http://docs.fortinet.com  for more details.

    So you can prepare those configs in advance and then drop them to console.

    Preparation can range from utilizing any text processing tool to make a template and fill those variables as usernames, to programming languages like Perl or Python to gather user data from LDAP reform them to text output written directly to FortiGate's command line via SSH session opened by your small coded tool.

    Adonist
    AdonistAuthor
    New Member
    September 14, 2018

    Thank you for the reply Tomas!

    If i can prepare like a template with them and drop in the cli that would be great.

    Thank you again for that!

    ede_pfau
    SuperUser
    ede_pfauAnswer
    SuperUser
    September 14, 2018

    Two hints:

     

    1- if you have a long user list, don't directly paste it to the CLI. Chances are high that you will get a timing error, and that not all of the input is actually 'taken'. Rather, submit the same file (which is a partial config file) via 'Advanced > Batch command'. This will upload all data first, and then import into the running config.

     

    2- if you have along user list, consider adding your LDAP (or MS-AD) as a 'remote user'. User management (who is granted SSLVPN access, who is removed from SSLVPN etc.) is then done via LDAP management. For instance, if you connect the FGT to your MS-AD, and create a user group in the MS-AD like 'SSLVPN users', you grant VPN access by dropping a user into this group. User management is completely independent of the Fortigate, and the config on your FGT is not touched in the future.

     

    Of course, this only pays out if you already manage users by LDAP or MS-AD.

     

    BTW, you can also grant admin access via LDAP, using a 'remote admin wildcard account'. Sound difficult but isn't.

     

    These methods are well documented in the Cookbook or KB.

    Thought Leadership. Security Summit. Thursday, November 12th, PGA National Resort, Palm Beach Gardens, FL.
    Thought Leadership. Security Summit. Thursday, October 8th. Disney's Grand Californian Hotel & SPA, Anaheim, CA.