Created on 11-20-2024 07:38 AM Edited on 11-20-2024 07:41 AM By Jean-Philippe_P
Description | The article describes how to resolve an issue where the two-factor email expiry timer does not take effect. |
Scope | FortiGate. |
Solution |
Originally, the two factor expiry timer was developed for authentication for RADIUS, LDAP, TACACS or for firewall policy authentication and not intended to be used for the local administrator authentication.
In this example, an administrator account was created and setup for two factory authentication using email:
config system admin
In the global settings, the two-factor email timer was set to 30 seconds:
config system global set two-factor-email-expiry 30 end
However, after the two-factor code was sent to the email and after waiting for more than the configured 30 seconds, the administrator login was still successful.
The two-factor expiry timer may be fixed on v7.2.11 and v7.6.1. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.