FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Rajneesh
Staff
Staff
Article Id 400128
Description This article describes the use and impact of the password policy configured on the existing IPsec tunnels.
Scope FortiGate.
Solution

The configured expiration policy exclusively applies to administrator logins. IPsec pre-shared keys are not subject to this policy and will remain valid indefinitely unless manually modified, thereby not affecting tunnel continuity.

 

This will take effect when the user tries to change the tunnels' pre-shared key; during that time, the password policy will take effect, and the user will have to match the conditions defined under the password policy.

 

IPSECPSK.png

 

The password policy is enforced only when a user attempts to update the pre-shared key for IPsec VPN tunnels. At that point, the system will require compliance with the defined policy parameters, such as minimum character length and ensuring the new password differs from the previous one.

Contributors