Skip to main content
MustphaBassim
New Member
March 2, 2024
Question

SSLVPN user can change password for first login

  • March 2, 2024
  • 7 replies
  • 8110 views

Hello Dears

 

I asking about if the user can change the password of SSLVPN account without need for admin interaction from forticlient portal take in mind the forticlient is free one without using any external system

 

Bests

7 replies

AEK
SuperUser
SuperUser
March 2, 2024

Hello

Hope the following link helps.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Password-expiration-policy-for-SSL-VPN-local-user/ta-p/192723

If this doesn't help, I think you still can play with password policy to force user change password on first login, e.g.: you set password with 10 characters, then you apply policy with minimum 12 characters. I think this should work.

 

But there is a better solution: in my organisation we use LDAP user database for SSL VPN, not FG local users. If you can do this I think this is much better, and you don't worry anymore for password management.

AEK
MustphaBassim
New Member
March 2, 2024

Hello Dear 

Thnx for reply , about the LDAP could the user change password from forticlient itself since some users are not on our domain

Bests

AEK
SuperUser
SuperUser
March 2, 2024

Hi Mustapha

I didn't see this in our environment (IPA). When my LDAP password expires the VPN doesn't ask me to reset it.

Edit: it seems different with MS AD, according to the tech tip shared above.

AEK
mpeddalla
Staff
Staff
March 3, 2024

Hello @MustphaBassim  ,

 

Thank you for contacting the Fortinet Forum portal.

Please refer to the below article, these are few options with free forticlient :

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-allow-LDAP-user-to-change-password-at-first/ta-p/243530

https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/688719/ssl-vpn-with-ldap-user-password-renew

 

 

Best regards,

Manasa.

 

If you feel the above steps helped to resolve the issue mark the reply as solved so that other customers can get it easily while searching on similar scenarios.

jkashmire
New Member
July 5, 2024

I think using a mix of letters, numbers, and symbols is key. But it's not just about complexity; it's about uniqueness too. Each account deserves its own special password—none of that one-size-fits-all nonsense. And maybe throw in a passphrase that means something to you but is tough for others to guess.

 

The idea of a "strong password" has never felt more crucial. I remember when I used to think "password123" was clever—boy, was I wrong! Learning about these vulnerabilities really makes you rethink how you protect your online stuff.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.