FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
Somashekara_Hanumant
Staff & Editor
Staff & Editor
Article Id 412638
Description This article describes that when local users receive a password expiry email from the self-service portal and select the provided URL, they encounter a '403 Forbidden' error.
Scope FortiAuthenticator, FortiAuthenticator Cloud.
Solution

Requirement:

  • Password Policy.
  • Self-service portal.
  • Self-service policy.
  • Local user.
  • SMTP server.

 

Password Policy:

 

p_policy.JPG

 

Note: When 'Maximum password age:" is set to 14 days and 'Send password renewal reminder on:' is also left as default (14,7,3,1) then FortiAuthenticator does not send the password expiry warning message on the same day of user creation, either admin should change the default settings to (13,7,3,1) if not user will get the email on 7th day.

 

Portals:

 

self_portal.JPG

 

Portal Policy:

 

p_policy2.png

 

Creating a Local user:

 

user_cre.JPG

 

User Group:

 

user_group.JPG

 

SMTP Server:

 

smtp.JPG

 

User gets a password expiration email:

 

Once the user gets a password expiry email, then the user tries to access the URL which is mentioned on Portal Policies, then the user gets below message.

 

forbiden.jpg

 

To resolve this issue on FortiAuthenticator VM or Hardware, the admin should enable the captive portal on the respective interface, the user should be able to open the link and reset the password, after accepting the disclaimer that which admin selected while configuring the Portal.

User will be prompted to authenticate. The user needs to authenticate using existing user credentials. Once successfully authenticated, select the Password to reset the password.

 

reset.JPG

 

On FortiAuthenticator Cloud, the Captive portal can be enabled under System -> Administration -> Access Rights

 

cloud.JPG