Please advise — my penetration testing team is recommending that I enable admin-restrict-local on the FortiGate firewall. However, if I do that, local admin logins will be completely blocked whenever remote authentication servers are reachable. My concern is about integrating the FortiGate device with FortiManager (FMG), which sometimes requires local credentials. If FMG tries to connect to the device using local admin credentials over the network (via SSH or HTTPS), those logins could be denied because of this restriction. Since FortiManager (FMG) and other management tools rely on local admin credentials or API access over the network, enabling admin-restrict-local—especially in restrictive modes like non-console-only or all—could disrupt those connections. So, would it be correct to assume that enabling this setting in a production environment is not advisable?
HI Raj_Pandey,
You would like to know how restricting local admin authentication works when remote authentication server is running on FortiManager.
This can be done on the FortiGate via CLI command. However, this feature is not supported on FortiManager.
You may restrict access with "Trusted hosts"The trusted hosts you define apply to both the GUI and to the CLI when accessed through SSH. CLI access through the console connector is not affected.
If you set trusted hosts and want to use the Console Access feature of the GUI, you must also set 127.0.0.1/255.255.255.255 as a trusted host.
Refer To:https://docs.fortinet.com/document/fortimanager/7.2.9/administration-guide/186508
Hi Raj,
Restricting the access using "admin-restrict-local" does not impact the connection from Fortimanager. Fortimanager will still be able to login and establish the connection.
As a test you can perform the testing on a single Firewall and then can plan for enabling other firewalls across organization.
What policy are you pushing exactly to the local-in interface? Is this the same interface you use for FMG management? You might be inadvertently blocking FMG traffic to the Fortigate, so it stops half-way through. FMG uses port TCP 541.
User | Count |
---|---|
2656 | |
1410 | |
810 | |
699 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.