Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
JimBo
New Contributor II

JSconsole access to Fortigate

Today we received a security audit assessment from a 3rd party security company. They indicated they can login successfully to our border FortiGate firewall using jsconsole from a trusted management interface. The trusted management interface is connected to the Out-of-band (OOB) Management network and is restricted to specific internal users including the 3rd party security company performing the audit.

 

Can anyone speak to this access, good, bad, indifferent?

Can jsconsole be used to make changes to the firewall?

Is there a way to block jsconsole access?

Thank you

 

Thank You JimBo
Thank You JimBo
1 REPLY 1
mpapisetty
Staff
Staff

Hi @JimBo ,

If the access is from a trusted management interface from a known user and with the appropriate credentials, I do not see any concern. 

 

I believe JSConsole would be able to access most GUI based applications and not just FortiGate for APIs, automation, debugging etc. Did the 3rd party security company raise a specific concern about this access? 

 

With regards to the other question of blocking access, I believe the only access control is based on protocols allowed on an interface (like ssh, https, ping etc). If JSConsole is using an allowed protocol on an interface, it would be able to access the firewall. 

HTH
Manoj Papisetty
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors