Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jefazo92
Contributor

How can one edit the time in the bad logon reset counter?

Hi everyone, 

 

By default Fortigate is set to have a maximum of 3 password attempts and a 60 second lockout. But I want to set the bad logon counter to 15 seconds so that after a user has typed in for the first or second time the wrong credentials (before reaching the password attempt threshold) and waits for 15 seconds, the number of wrongly typed passwords is reset back to 0 and he can retry again. What commands should I run to make this happen?

4 REPLIES 4
hbac
Staff
Staff
jefazo92

Thank you @hbac but that is not what I am referring to. I already implemented those commands, but what I want is to change is the time one has to wait for the wrong password count to go back to 0 after, let's say, 15 seconds of no retry. This is independent from the lockout threshold and the lockout period

abarushka
Staff
Staff

Hello,

 

In case you are referring to administrator logging in, you may find useful the link below:

 

config system global
    set admin-lockout-threshold <failed_attempts>
    set admin-lockout-duration <seconds>
end

 

https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/631730/setting-the-administrator-passwo...

FortiGate
jefazo92

Thank you @abarushka but it is not what I am looking for. Please refer to my post and my reply to hbac to understand better what I want to implement.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors