Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MustphaBassim
New Contributor III

SSLVPN user can change password for first login

Hello Dears

 

I asking about if the user can change the password of SSLVPN account without need for admin interaction from forticlient portal take in mind the forticlient is free one without using any external system

 

Bests

6 REPLIES 6
AEK
SuperUser
SuperUser

Hello

Hope the following link helps.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Password-expiration-policy-for-SSL-VPN-loc...

If this doesn't help, I think you still can play with password policy to force user change password on first login, e.g.: you set password with 10 characters, then you apply policy with minimum 12 characters. I think this should work.

 

But there is a better solution: in my organisation we use LDAP user database for SSL VPN, not FG local users. If you can do this I think this is much better, and you don't worry anymore for password management.

AEK
AEK
MustphaBassim
New Contributor III

Hello Dear 

Thnx for reply , about the LDAP could the user change password from forticlient itself since some users are not on our domain

Bests

AEK

Hi Mustapha

I didn't see this in our environment (IPA). When my LDAP password expires the VPN doesn't ask me to reset it.

Edit: it seems different with MS AD, according to the tech tip shared above.

AEK
AEK
MustphaBassim
New Contributor III

The problem we have many users across the world and they are not join to our DC 

Their password is shared by mail and we are planning to provide machine for making password generator without needs for human sending email to reception 

AEK

You may try setup a password policy to force user change password on first login.

E.g.:

  • Create a vpn test account
  • Give it a password of 10 characters
  • Then you apply a password policy with minimum 12 characters
  • Then try connect to VPN with this test user

I think this should ask your user to enter a new password of 12 characters since the first one (10 chars) doesn't comply with the policy.

AEK
AEK
mpeddalla
Staff
Staff

Hello @MustphaBassim  ,

 

Thank you for contacting the Fortinet Forum portal.

Please refer to the below article, these are few options with free forticlient :

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-allow-LDAP-user-to-change-password-...

https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/688719/ssl-vpn-with-ldap-user-password-...

 

 

Best regards,

Manasa.

 

If you feel the above steps helped to resolve the issue mark the reply as solved so that other customers can get it easily while searching on similar scenarios.

Labels
Top Kudoed Authors