The content you are looking for has been archived. View related content below.
Description
Solution
Additional info:
Once logged into the FortiGate with the maintainer account (as described below), if the FortiGate is running FortiOS 6.0.3 or later, enter the execute factoryreset command to return the FortiGate to its default configuration.
This can be useful if the admin administrator account was deleted.
In newer versions of the BIOS, expect some changes to the behavior of the maintainer account. These changes will include:
- The countdown timer for how log enter the credentials has increased. Starting from when the device powers up, there will be 60 seconds instead of 30.
- Using the maintainer account and resetting a password cause a log to be created; making these actions traceable for security purposes.
- The account will be able to reset the password for any super-admin profile user in addition to the default admin user. This takes into account the possibility that the default account has been renamed.
- The only thing the maintainer account has permission to do is reset the passwords of super-admin profile accounts.
What is needed:
- Console cable
- Terminal software such as Putty.exe (Windows) or Terminal (MacOS)
- Serial number of the FortiGate device
Procedure:
Step 1
Connect the computer to the firewall via the Console port on the back of the unit.
In most units, this is done either by a Serial cable or an RJ-45 to Serial cable. There are some units that use a USB cable and FortiExplorer to connect to the console port.
Resetting a lost admin password for the VM-s using the maintainer account is not possible.
In this case, reverting to a snapshot or re-provisioning the VM and restoring the configuration (without a password for the admin account) is the only solution.
Step 2
Start the terminal software.
Step 3
Connect to the firewall using the following:
FortiGate-60C (18:52-06.18.2010)Step 7
Ver:04000010
Serial number: FGT60C3G10xxxxxx
CPU(00): 525MHz
Total RAM: 512 MB
NAND init... 128 MB
MAC Init... nplite#0
Press any key to display configuration menu...
......
reading boot image 1163092 bytes.
Initializing firewall...
System is started.
login:
# config system adminIn a unit where VDOMs are enabled:
edit admin
set password
end
# config globalIf the FortiGate is running FortiOS 6.0.3 or later, enter the following command to reset the FortiGate to its factory default configuration.
config system admin
edit admin
set password
end
# execute factoryresetWarning:
# config system globalTo enable:
set admin-maintainer disable
end
# config system global
set admin-maintainer enable
end
Starting with FortiOS 7.2.4 the maintainer account was removed.
Users who lose their password must have physical access to the FortiGate and perform a TFTP restore of the firmware in order to regain access to the FortiGate.
Related documents:
https://docs.fortinet.com/document/fortigate/7.2.0/new-features/482897/remove-maintainer-account-7-2...
https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/556915#Factory
This article is applicable for 7.0 fortiOS also.
Note:- Starting with FortiOS 7.2.4 the maintainer account was removed.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.