Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Konrad1311
New Contributor II

Using Forticlient you can bypass AD password policy

Hello, 
I have strange situation related to my configuration of  SSL VPN and LDAP users on my FG100F unit.
Currently all people in my agencies using their LDAP accounts to connect VPN and work remotely. 
Last week one person reported to me that it is possible to change expired password using Forticlient. 
It is normal because I have configuration which allows to users to change their Windows (LDAP) password. 
Unfortunately this user changed password for exactly the same as he had before. 

In my GPO I have password history for last 10 and compliance policy on high level (at least 10 characters etc.)
But for now I see that it is possible to change it though Forticlient 

 

Does anyone know how to force FortiGate to use AD policy during password change ? 

 

BR 

Konrad

1 Solution
ebilcari
Staff
Staff

This behavior comes from the nature of Windows Server (AD + LDAP). As you have mentioned the authentication and the password reset from FGT/FCT is done while using LDAP, while the password history compliance is pushed through GPO. Technically this password policy is not related at all to the LDAP protocol.

As I know, FGT can not read and interpret GPO restrictions. You can try to find out if Windows Server can apply restrictions for password reset via LDAP to make the reset password procedure fail if an old password is used. This will make the end user to try with a different password next time.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.

View solution in original post

2 REPLIES 2
ebilcari
Staff
Staff

This behavior comes from the nature of Windows Server (AD + LDAP). As you have mentioned the authentication and the password reset from FGT/FCT is done while using LDAP, while the password history compliance is pushed through GPO. Technically this password policy is not related at all to the LDAP protocol.

As I know, FGT can not read and interpret GPO restrictions. You can try to find out if Windows Server can apply restrictions for password reset via LDAP to make the reset password procedure fail if an old password is used. This will make the end user to try with a different password next time.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Konrad1311
New Contributor II

Hello @ebilcari ,
I will try to find some workaround of this issue 
Thank you for you answer!

Konrad

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors