Hi
I have two questions.
1. Is there a way to set admin-lockout-duration to 100000 and let another administrator unlock it when the account is locked?
2. Is the criteria by which the account is locked not the account name but IP based?
Thank you
Solved! Go to Solution.
Dear @Jin-Gyu ,
Setting admin-lockout-duration to 100000 and Unlocking by Another Administrator:
You can set the admin-lockout-duration to 100000 seconds using the CLI command:
config system global
set admin-lockout-duration 100000
end
However, unlocking a locked account by another administrator is not directly supported.
The lockout duration must pass, or the device must be rebooted to clear the lockout.
Criteria for Account Lockout:
The lockout is based on the account name, not the IP address.
Each administrator account has its own lockout settings, and the lockout is triggered by failed login attempts for that specific account.
Best regards,
Erlin
Dear @Jin-Gyu ,
Setting admin-lockout-duration to 100000 and Unlocking by Another Administrator:
You can set the admin-lockout-duration to 100000 seconds using the CLI command:
config system global
set admin-lockout-duration 100000
end
However, unlocking a locked account by another administrator is not directly supported.
The lockout duration must pass, or the device must be rebooted to clear the lockout.
Criteria for Account Lockout:
The lockout is based on the account name, not the IP address.
Each administrator account has its own lockout settings, and the lockout is triggered by failed login attempts for that specific account.
Best regards,
Erlin
Thank you for your answer!
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2678 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.