FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
gonzalezw
Staff
Staff
Article Id 312931
Description This article describes how to restore the 'admin account' when no other admin accounts are available, relying solely on an existing backup file.
Scope FortiGate v7.2.4 and later.
Solution
  1. Hard reset the device: Technical Tip: How To Reset To Factory Default Configuration using external button
  2. Look in the backup file for the following line:

 

config system admin
    edit "admin"

        set password ENC SH28VIvRtYEOIwFnrVEwQ1JNX+9GoopNKSrus9NVar40k5N7ouu5x4JjzJtkME=

 

  1. Delete the line: 'set password ENC SH28VIvRtYEOIwFnrVEwQ1JNX+9GoopNKSrus9NVar40k5N7ouu5x4JjzJtkME=' and save the changes in the file editor.
  2. Upgrade the Firmware version of FortiGate to the same backup file version. 
  3. Log into the unit using the default IP: https://192.168.1.99, then upload the backup file.

 

 Upload config file.jpg

 
 

Upload config file 2.jpg

 

  1. After the FortiGate completes the reboot process, enter the username 'admin' and leave the password field blank. Once the firewall is back online, hit 'Enter', and it will be possible to log in.
  2. After successfully logging in, the option to update the admin password will be accessible.

 

Select the 'admin' user and select 'Edit.

 

update password 1.jpg

 

Select 'Change Password', and create a new password. 

 

update password 2.jpg.png

 

Note:

It is a best practice to have a second super_admin account to avoid going through the process above. 

Contributors