The content you are looking for has been archived. View related content below.
Created on
01-09-2021
01:46 AM
Edited on
10-27-2025
04:16 AM
By
Jean-Philippe_P
Description
This article describes how to recover access to FortiManager/FortiAnalyzer Hardware when the admin password is lost, to restore access, download and install firmware from a local TFTP server, via Console on the FortiManager/FortiAnalyzer hardware.
To restore the old config back on the FortiManager/FortiAnalyzer, it is necessary to have a backup of the config and contact Fortinet Support to remove the password if unknown, before the restore process.
Note.
Installing firmware from a local TFTP server via console resets the FortiManager/FortiAnalyzer system settings to default.
Disclaimer.
After reloading the firmware image on the Hardware unit, make sure to reconfigure the System Settings accordingly, as explained at the end of this article.
Otherwise, it risks data loss and corruption.
Any action taken upon the information in this article is strictly at its own risk.
Scope
FortiAnalyzer.
Components.
TFTP server (the following is the recommended TFTP software).
Recommended TFTP software.
TFTPD32 - Open Source tftp server for Windows there: Tftpd64.
Solution
Steps to reset and push the new Firmware.
Notes.
Some console prompts in this procedure include a default value in square brackets, for example, [image.out]. To use this default value, press Enter.
Terminal client communication parameters.
8 bits
no parity
1 stop bit
9600 baud
Flow Control = None
Restart the FortiManager/FortiAnalyzer.
When the console displays 'Press any key to display configuration menu...', press the space bar or any other key.
When a list of choices with the letter of Alphabet comes up, press G to continue.
Connect the computer running the TFTP server to the FortiManager/FortiAnalyzer unit. The port is prompted in the console output as below:
Please connect TFTP server to Ethernet port "1"
Enter TFTP server address [192.168.1.168]:
Enter Local Address [192.168.1.188]:
Enter File Name [image.out]:
The console periodically displays a "#" (pound or hash symbol) to show the download progress.
11. When the download completes, the console displays a message similar to below: Press D.
Save as Default firmware/Backup firmware/Run image without saving:[D/B/R]?D
The FortiManager/FortiAnalyzer unit installs the new firmware image and restarts. The installation may take a few minutes to complete.

Optional: Restore System Level Settings using Backup Config File: (only working if the backup is not password-protected, mandatory since v7.0.13, v7.2.10, v7.4.6).
Additional note: If the backup is encrypted, it is possible to decrypt it with tools.
First, connect to the VPN to Ottawa, then enter:
https://tools.ott.fortilab.net/config-decrypt
Provide backup file and current password. It will generate a file with a .tar.gz file.
If a recent backup of the config file exists, the admin password can be removed, and the system-level settings can be restored once the above steps have been completed.
Before removal:
After removal:
Related articles:
Technical Tip: Formatting and loading FortiGate firmware image using TFTP
Technical Note: FortiManager Tips and Best Practices Guide
Technical Tip: Resetting the admin password for FortiManager/FortiAnalyzer hardware
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.