Hi
What I mean is that I configured the lockout setting to lock the account after five failed attempts, but when my user enters the wrong password just once, FAC disables the account user, and it has to be manually enabled.
FAC version 6.6.4
Thanks.
Hi Kyle
Keep in mind user locked is not the same as user disabled.
I don't know where this behavior is configured but I don't think in "User Lockout Policy".
Hi Kyle,
you can check on the monitor section what is with this user. Based on the second screenshot, bottom, I suppose the FortiGate could need a config adjustment on the RADIUS configuration:
https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Best-practices-on-hardening-Forti... describes that setting.
Hi Markus
I have already specified RADIUS authentication, but it still gets disabled.
What do the regular logs state. So when the user was just enabled, entered the wrong password, and gets disabled. Also interesting as to what the user exactly authenticates to.
User | Count |
---|---|
2549 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.