Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ictdude
New Contributor

Lost admin user need reset on a FGVM64-5.04-FW-build1011-151221 (fortigate virtual app)

Dear all,

 

We cant access the Fortigat. We need to reset the admin account.

 

(fortigate virtual appliance)  FGVM64-5.04-FW-build1011-151221

 

Its a virtual appliance running on Vmware. We are able to enter the config files.

So we can edit the files if needed.

 

Or how to enable the fortigate maintainer ? Its disabled.

We need to reset this by editing the config files directly. Thats the only

access we have,   We mounted the system with a linux boot cd. So thats how we can enter the system.

 

Help needed urgent !!!! 

1 Solution
ede_pfau

hi,

 

as Dave Hall has already posted, put a new password in cleartext into the config file. The entry will be converted to the encrypted form ("ENC b0980a8fddsjkfdlj...") by FortiOS at the next reboot.

 

IF you can, boot up the FGT, 'restore' the config, and after the reboot you can use the new password.

IF you can't restore (because of lack of admin rights...) then you can put the config onto a USB stick, set the auto-config option (cf. CLI Reference), and reboot.

 

So you see, physical access control is key to a secure firewall!

Ede Kernel panic: Aiee, killing interrupt handler!

View solution in original post

Ede Kernel panic: Aiee, killing interrupt handler!
6 REPLIES 6
Dave_Hall
Honored Contributor

If you have access to an unencrypted  config file, just look for the config system admin section, then edit the password in the "admin" section.  eg.

 

config system admin edit "admin" set password <enter new password> next end

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
ictdude

Dave Hall wrote:

If you have access to an unencrypted  config file, just look for the config system admin section, then edit the password in the "admin" section.  eg.

 

config system admin edit "admin" set password <enter new password> next end

The config file looks likt this:

 

set password ENC AK1wTiFOMv7*******

Looks like a special password ..  ENC AK1

Experience with this ? Will that work ? Will try and let you know.

 

Option 2 how to enable the maintainer account ?

 

Also i have 2 config files ?

cfg0000000001 and cfg0000000002  what file is the "master"

1 or 2 ?

 

 

 

 

ede_pfau

hi,

 

as Dave Hall has already posted, put a new password in cleartext into the config file. The entry will be converted to the encrypted form ("ENC b0980a8fddsjkfdlj...") by FortiOS at the next reboot.

 

IF you can, boot up the FGT, 'restore' the config, and after the reboot you can use the new password.

IF you can't restore (because of lack of admin rights...) then you can put the config onto a USB stick, set the auto-config option (cf. CLI Reference), and reboot.

 

So you see, physical access control is key to a secure firewall!

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
ictdude

ede_pfau wrote:

hi,

 

as Dave Hall has already posted, put a new password in cleartext into the config file. The entry will be converted to the encrypted form ("ENC b0980a8fddsjkfdlj...") by FortiOS at the next reboot.

 

IF you can, boot up the FGT, 'restore' the config, and after the reboot you can use the new password.

IF you can't restore (because of lack of admin rights...) then you can put the config onto a USB stick, set the auto-config option (cf. CLI Reference), and reboot.

 

So you see, physical access control is key to a secure firewall!

Thnx i will test this fryday !!!! I keep you all updated :)

ictdude

ede_pfau wrote:

hi,

 

as Dave Hall has already posted, put a new password in cleartext into the config file. The entry will be converted to the encrypted form ("ENC b0980a8fddsjkfdlj...") by FortiOS at the next reboot.

 

IF you can, boot up the FGT, 'restore' the config, and after the reboot you can use the new password.

IF you can't restore (because of lack of admin rights...) then you can put the config onto a USB stick, set the auto-config option (cf. CLI Reference), and reboot.

 

So you see, physical access control is key to a secure firewall!

Here is my config as you can see i did change the password to admin.

After reboot password is still there but cant login

 

config system admin     edit "admin"         set accprofile "super_admin"         set vdom "root"             config dashboard-tabs                 edit 1                     set name "Status"                 next             end             config dashboard                 edit 1                     set tab-id 1                     set column 1                 next                 edit 2                     set widget-type licinfo                     set tab-id 1                     set column 1                 next                 edit 3                     set widget-type jsconsole                     set tab-id 1                     set column 1                 next                 edit 4                     set widget-type sysres                     set tab-id 1                     set column 2                 next                 edit 5                     set widget-type gui-features                     set tab-id 1                     set column 2                 next                 edit 6                     set widget-type alert                     set tab-id 1                     set column 2                     set top-n 10                 next             end         set password admin

ictdude

UPDATE 2:

 

Is it possible that we are editing the wrong file ? Because all instructions do not work.

The file that we are editing is the  Location:  /config/cfg0000000001

 

Is there a other file binary and or encrypted ? Or in a database ?

 

Are we editing the correct file ?

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors