Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kyle-hsuan
New Contributor III

FortiAuthenticator remote ldap user authenticated failed one time, then account status disabled

Hi

 

What I mean is that I configured the lockout setting to lock the account after five failed attempts, but when my user enters the wrong password just once, FAC disables the account user, and it has to be manually enabled.

kylehsuan_0-1756709753655.png

kylehsuan_2-1756709871429.png

 

FAC version 6.6.4

 

Thanks.

 

 

 

4 REPLIES 4
AEK
SuperUser
SuperUser

Hi Kyle

Keep in mind user locked is not the same as user disabled.

I don't know where this behavior is configured but I don't think in "User Lockout Policy".

AEK
AEK
Markus_M
Staff & Editor
Staff & Editor

Hi Kyle,

 

you can check on the monitor section what is with this user. Based on the second screenshot, bottom, I suppose the FortiGate could need a config adjustment on the RADIUS configuration:
https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Best-practices-on-hardening-Forti... describes that setting.

- Markus
kyle-hsuan
New Contributor III

Hi Markus

 

I have already specified RADIUS authentication, but it still gets disabled.

Markus_M
Staff & Editor
Staff & Editor

What do the regular logs state. So when the user was just enabled, entered the wrong password, and gets disabled. Also interesting as to what the user exactly authenticates to.

- Markus
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors