I've noticed that there is a Guest user by default on the Fortigates. Under User & Device and then User Definition there is a user called guest that is a member of the Guest-group. Attached is a screenshot of the Guest user I am talking about.
Can the guest user authenticate to the SSL VPN? Should the guest user be disabled or deleted? If you look at the configuration in a text editor you can see that the guest user user has a password assigned to it. The password is encrypted so I am not sure what that password is.
I did some Google'ing before posting this message and couldn't find any information regarding the guest user.
Thanks for the help.
Hi com2irq5,
note that guest user is member of Guest-group.
Firewall policies mainly work with user groups.
Therefore, if you check Ref. counter for references then you should see that Guest-group is not used in SSL and so user cannot authenticate to SSL VPN, untill you set that explicitly.
This also answers the question 'Should the guest user be disabled or deleted?'. It's not used anywhere further in the config so it's harmless so I do not see need to delete that. Some default parts cannot be even deleted, but this one can. Feel free to do so if you are suspicious.
Default guest mechanism should accept guest user with any password.
Best regards,
Tomas
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
The short answer;
yes delete it and the group
( cmds to check reference via cli )
diag sys checkused user.local.name guest
diag sys checkused user.group.name Guest-group
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1749 | |
1114 | |
765 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.