Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MustphaBassim
New Contributor III

SSLVPN user can change password for first login

Hello Dears

 

I asking about if the user can change the password of SSLVPN account without need for admin interaction from forticlient portal take in mind the forticlient is free one without using any external system

 

Bests

7 REPLIES 7
AEK
SuperUser
SuperUser

Hello

Hope the following link helps.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Password-expiration-policy-for-SSL-VPN-loc...

If this doesn't help, I think you still can play with password policy to force user change password on first login, e.g.: you set password with 10 characters, then you apply policy with minimum 12 characters. I think this should work.

 

But there is a better solution: in my organisation we use LDAP user database for SSL VPN, not FG local users. If you can do this I think this is much better, and you don't worry anymore for password management.

AEK
AEK
MustphaBassim
New Contributor III

Hello Dear 

Thnx for reply , about the LDAP could the user change password from forticlient itself since some users are not on our domain

Bests

AEK

Hi Mustapha

I didn't see this in our environment (IPA). When my LDAP password expires the VPN doesn't ask me to reset it.

Edit: it seems different with MS AD, according to the tech tip shared above.

AEK
AEK
MustphaBassim
New Contributor III

The problem we have many users across the world and they are not join to our DC 

Their password is shared by mail and we are planning to provide machine for making password generator without needs for human sending email to reception 

AEK

You may try setup a password policy to force user change password on first login.

E.g.:

  • Create a vpn test account
  • Give it a password of 10 characters
  • Then you apply a password policy with minimum 12 characters
  • Then try connect to VPN with this test user

I think this should ask your user to enter a new password of 12 characters since the first one (10 chars) doesn't comply with the policy.

AEK
AEK
mpeddalla
Staff
Staff

Hello @MustphaBassim  ,

 

Thank you for contacting the Fortinet Forum portal.

Please refer to the below article, these are few options with free forticlient :

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-allow-LDAP-user-to-change-password-...

https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/688719/ssl-vpn-with-ldap-user-password-...

 

 

Best regards,

Manasa.

 

If you feel the above steps helped to resolve the issue mark the reply as solved so that other customers can get it easily while searching on similar scenarios.

Manasa
jkashmire
New Contributor II

I think using a mix of letters, numbers, and symbols is key. But it's not just about complexity; it's about uniqueness too. Each account deserves its own special password—none of that one-size-fits-all nonsense. And maybe throw in a passphrase that means something to you but is tough for others to guess.

 

The idea of a "strong password" has never felt more crucial. I remember when I used to think "password123" was clever—boy, was I wrong! Learning about these vulnerabilities really makes you rethink how you protect your online stuff.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors