FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
iskandar_lie
Staff
Staff
Article Id 227086
Description This article describes how to restrict SSH and telnet jump host
Scope

Scenario: 

Restrict FortiGate to be used as jump host for certain user 

Solution

1) Disable permission to execute SSH or telnet commands in an administrator access profile:

 

iskandar_lie_0-1666120008512.png

 

2) Configure an administrator in the profile:

 

iskandar_lie_1-1666120066949.png

 

3)  Log in as 'user1', and attempt to connect to another host using SSH or telnet:

'user1' cannot connect to another host using either ssh nor telnet 

 

iskandar_lie_2-1666120088205.png

 

Fortinet Documentation:

https://docs.fortinet.com/document/fortigate/7.2.0/new-features/936614/restrict-ssh-and-telnet-jump-...

Contributors