Description |
This article describes how to clear the 'Admin login disabled' lockout due to multiple login failures on earlier FortiOS versions. |
Scope |
FortiGate v6.4.12 and earlier, v7.0.10 and earlier, v7.2.3 and earlier. |
Solution |
In v7.2.3 and earlier, it is possible to clear a locked-out source IP by re-configuring the admin-lockout-duration value to a lower value and waiting for the new lower value.
FGT# config system global
FGT# config system global
After the 5-second lockout duration, the disabled admin would have access again. Re-configure the value back to the previous lockout-duration once the disabled admin is cleared.
The lockout duration is based on the IP address. The same admin user may still log in from a different IP source.
Note: The method detailed above is no longer permitted beginning in v6.4.13, v7.0.11, v7.2.4, and v7.4.0. In later firmware versions, the only options to mitigate an administrative lockout for a particular source IP address are:
For admin best practice, refer to the following document. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.