Hi everyone,
I would want any changes in configaration or whitelist to require the user to write in their password before doing making the changes. I would want secure my Fortigate-100F in this way but have not found anything in the manual which suggest this can be implemented. Please would you mind telling me if what I want can be done?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
Would not the user authenticate with his password to access the device for making any config changes? A separate user account may be kept with read only access for the user thereby restricting any config changes with this account.
Best regards,
Jin
Hello
I don't know such feature in FortiOS.
However what you can do is to reduce GUI timeout, like 5mn or less if you want.
Besides, in case you don't know it already, here is the official FOS/FGT hardening guide to harden your system in the best way.
https://docs.fortinet.com/document/fortigate/7.4.0/best-practices/555436/hardening
Hope it helps
Hello @jefazo92 ,
In addition to what @AEK and @jintrah_FTNT said, if you want the configuration to be approved by an approver before being implemented on the device, you can use FortiManager's workflow mode feature.
In this way, any changes your employees make will not be implemented without approval from the approver you have appointed.
https://docs.fortinet.com/document/fortimanager/7.4.3/administration-guide/424502/workflow-mode
There is no such feature built-in.
As @ozkanaltas mentioned, there is Workspace Mode on the Fortimanager (and more limited feature on Fortigates) that forces you to comment any changes you make, but it is not a full blown Provisioning feature. I do use it from time to time for technical reasons, but have to say - I have never seen people IRL using it consistently. So, invest your time in it if you can instill it as part of a culture, otherwise it will not stick.
E.g. for Fortigate https://yurisk.info/2022/04/04/fortigate-workspace-mode-commit-changes-example/
On a side note - there is Provisioning feature/blade in CheckPoint firewalls, fully developed solution with hierarchy who can do what changes, who can later approve or deny them, and ... I am yet to see orgs that use this feature as well :). Such features add so much overhead in IT work, that they get abandoned very fast.
You have an option in Fortigate to create administrative profiles, assigning more granular privileges to specific users. Like, you can create profile that is read-only in everything but allows changing VPN usernames passwords and such. This feature is actually used a lot, have a look.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1721 | |
1098 | |
752 | |
447 | |
234 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.