FortiWeb
A FortiWeb can be configured to join a Security Fabric through the root or downstream FortiGate.
AACastillo
Staff
Staff
Article Id 414944
Description This article discusses about situation when it's wanted to delete the 'admin' user account in FortiWeb and alternatives ways to protect using this account.
Scope FortiWeb.
Solution

In some cases, it is wanted to delete the default 'admin' user in FortiWeb; however 'admin' user cannot be deleted or change its administration profile (prof_admin).

 

01a.png

 

This is because the 'admin' user has special rights, like restoring passwords of other administrators; no other account can be considered a complete replacement.

 

To try to avoid using this administrator account, modifications can be made in the 'admin' configuration using a different FortiWeb administrator user with Access Profile 'prof_admin':

 

  1. Go to System -> Admin -> Administrators, select 'admin' and then Edit:

 

02a.png

 

In IPv4 Trusted Hosts, configure an IP address that cannot connect to FortiWeb; for example, 1.2.3.4/32. To finish, select OK.

 

03a.png

 

  1. Go to System -> Admin -> Administrators, select 'admin' and then Change Password:

     

04a.png

 

Configure a password in New Password and Confirm Password with a high degree of complexity (at least 12 characters, including upper and lower case letters, digits, and special characters; something like shown in the example). To finish, select OK.

 

05a.png