FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
JaskiratM
Staff
Staff
Article Id 224990

Description

 

This article describes on how to connect to a FortiGate VM deployed in AWS as an EC2 instance using a serial/console connection.

If a super-admin user lost the password to the EC2 instance, the only way to retrieve the password is using a maintainer through a console to the Firewall.

Prior to 2021, it was not possible to access the FortiGate as an EC2 instance using a console connection. 

After the introduction of the NITRO CPU in AWS, now it is possible to access the console.

 

Scope

 

FortiGate VM deployed in AWS.

 

Solution

 

1) Go to the EC2 dashboard in the AWS Management Console and check the Processor that the FortiGate instance is running on. In order to have console access, it has to be running on a compute-optimized non-metal NITRO CPU provided by AWS.

Instance types - Amazon Elastic Compute Cloud

 

This article lists all the non-metal CPU processors. It is advised to use the following CPUs for best optimization with our FortiGate image to access the console: C5, C5a, C5ad, C5d, C5n, C6a, C6g, C6gd, C6gn, C6i, C6id , Hpc6a.

 

If the EC2 instance is running on a different CPU, then it needs to be temporarily changed (This change might incur some extra costs while the EC2 runs on a different processor)In order to change the instance type, the EC2 instance needs to be in the stopped instance state.

JaskiratM_0-1664292994222.png

 

Once the EC2 instance is in a stopped state, select the instance, select ACTIONS - > INSTANCE SETTINGS - > CHANGE INSTANCE TYPE

 

JaskiratM_1-1664292994235.png

 

Now, the EC2 dashboard will give an option to alter the processor. Change it to anyone of the Processors listed above and apply the changes

 

2) Confirm the EC2 instance type has changed to the NITRO CPU (in this case it is C5.Large). Once confirmed initiate the instance from INSTANCE STATE - > START

 

JaskiratM_2-1664293064217.png

 

3) Once the Instance has been initiated, select CONNECT at the top information bar.

 

JaskiratM_3-1664293075263.png

 

4) The AWS dashboard will now provide an option to connect using EC2 serial console.

 

JaskiratM_4-1664293086020.png

 

5) Select 'connect' and a new window with the console session will appear

 

JaskiratM_5-1664293096020.png

 

6) Now follow the maintainer process listed below in the article to perform the password reset or for any other purpose which involves a console connection.

 

Technical Tip: Reset a lost admin password on a Fo... - Fortinet Community

 

Related document:

Instance types - Amazon Elastic Compute Cloud

 

Technical Tip: Reset a lost admin password on a Fo... - Fortinet Community

Contributors