Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jefazo92
Contributor

Can configuration changes be password protected in a Fortigate?

Hi everyone,

 

I would want any changes in configaration or whitelist to require the user to write in their password before doing making the changes. I would want secure my Fortigate-100F in this way but have not found anything in the manual which suggest this can be implemented. Please would you mind telling me if what I want can be done?

4 REPLIES 4
jintrah_FTNT
Staff
Staff

Hi,

 

Would not the user authenticate with his password to access the device for making any config changes? A separate user account may be kept  with read only access for the user thereby restricting any config changes with this account.

 

Best regards,

Jin

 

 

AEK
SuperUser
SuperUser

Hello

I don't know such feature in FortiOS.

However what you can do is to reduce GUI timeout, like 5mn or less if you want.

Besides, in case you don't know it already, here is the official FOS/FGT hardening guide to harden your system in the best way.

https://docs.fortinet.com/document/fortigate/7.4.0/best-practices/555436/hardening

Hope it helps

AEK
AEK
ozkanaltas
Valued Contributor III

Hello @jefazo92 ,

 

In addition to what @AEK  and @jintrah_FTNT said, if you want the configuration to be approved by an approver before being implemented on the device, you can use FortiManager's workflow mode feature.

 

In this way, any changes your employees make will not be implemented without approval from the approver you have appointed.

 

https://docs.fortinet.com/document/fortimanager/7.4.3/administration-guide/424502/workflow-mode

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Yurisk
SuperUser
SuperUser

There is no such feature built-in.

 

As @ozkanaltas mentioned, there is Workspace Mode on the Fortimanager (and more limited feature on Fortigates) that forces you to comment any changes you make, but it is not a full blown Provisioning feature. I do use it from time to time for technical reasons, but have to say - I have never seen people IRL using it consistently. So, invest your time in it if you can instill it as part of a culture, otherwise it will not stick. 

E.g. for Fortigate https://yurisk.info/2022/04/04/fortigate-workspace-mode-commit-changes-example/

 

On a side note - there is Provisioning feature/blade in CheckPoint firewalls, fully developed solution with hierarchy who can do what changes, who can later approve or deny them, and ... I am yet to see orgs that use this feature as well :).  Such features add so much overhead in IT work, that they get abandoned very fast. 

 

You have an option in Fortigate to create administrative profiles, assigning more granular privileges to specific users. Like, you can create profile that is read-only in everything but allows changing VPN  usernames passwords and such. This feature is actually used a lot, have a look. 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors