- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FortiGate local admin console access only
Hello,
I was wondering if it's possible to lock down a local admin account for console access only?
I know that you can do it in the global settings, but I only want to lock down one admin account with no mfa to console access only. I attempted to create an admin account and have it's trusted host as 127.0.0.1/32 but got an error. I would like to do this in the trusted host if possible and avoid using a local in policy. In the back of my mind I am thinking about cloud based FortiGate's that have been orphaned from internet access and can only access them through the cloud native console session.
FortiGate firmware version 7.2.10
- Labels:
-
Authentication
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Update:
I tried applying the 127.0.0.1/32 to the trusted host I got the following error: Ip address must be a class A, B, or C ip.
However, I did a 0.0.0.0/32 address and that worked. I confirmed I could reach the FortiGate console from Azure on that admin account. Would using a 0.0.0.0/32 address open any security risk?
