Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ede_pfau
SuperUser
SuperUser

admin login blocking time

On a FG310B, running 3.00MR7px, I see a lot of login attempts via ssh. After 3 unsuccessful attempts the FGT blocks access for 60 seconds. a) will it block the offending source IP only, or ssh access altogether? b) can you configure the blocking duration? In 24 hours, these creeps try every minute to get in. The source IP changes after 3 attempts. We see this a lot with other ssh servers as well. Prolonging the block duration would relieve the FGT and the logging device. Ede
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
5 REPLIES 5
Not applicable

concerning a) it only blocks the access from the IP that had to many unsuccessfull attempts. Login from other IP addresses is still possible. concerning b) I don' t know if it is possible to modify the value for the blocking-time, but I would suggest you use trusted hosts for your administrator accounts. Trusted hosts will make sure that login is only possible from the IPs you have specified as trusted hosts.(You can specify up to three hosts or networks) All attempts to log in from other IP addreses will be blocked.
ede_pfau
SuperUser
SuperUser

for b) I cannot use trusted hosts as I will access the FGT from a DSL line, meaning every 24h a different IP is allocated by our provider. Ede
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
emnoc
Esteemed Contributor III

To adjust the admin lock try the following in global settings set admin-lockout-duration set admin-lockout-threshold

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
ede_pfau
SuperUser
SuperUser

@emnoc, that is exactly what I needed. Thanks a lot. posts like yours should be made permanent for others to search. Ede
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
emnoc
Esteemed Contributor III

I have a Fortigate setup on a LAN segment that I have 2 honeypots locate on and it' s funny to see who, and what the internet trys to uses aganist your firewall. With email alert logging and syslog, I can get great information on when ssh session attempts are being executed.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors