Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Raj_Pandey
New Contributor

admin-restrict-local enable with FMG integration issue

Please advise — my penetration testing team is recommending that I enable admin-restrict-local on the FortiGate firewall. However, if I do that, local admin logins will be completely blocked whenever remote authentication servers are reachable. My concern is about integrating the FortiGate device with FortiManager (FMG), which sometimes requires local credentials. If FMG tries to connect to the device using local admin credentials over the network (via SSH or HTTPS), those logins could be denied because of this restriction. Since FortiManager (FMG) and other management tools rely on local admin credentials or API access over the network, enabling admin-restrict-local—especially in restrictive modes like non-console-only or all—could disrupt those connections. So, would it be correct to assume that enabling this setting in a production environment is not advisable?

Security Architecture & Design Professional
Security Architecture & Design Professional
3 REPLIES 3
tbarua
Staff
Staff

HI Raj_Pandey,

You would like to know how restricting local admin authentication works when remote authentication server is running on FortiManager.
This can be done on the FortiGate via  CLI command. However, this feature is not supported on FortiManager.

You may restrict access with "Trusted hosts"The trusted hosts you define apply to both the GUI and to the CLI when accessed through SSH. CLI access through the console connector is not affected.
If you set trusted hosts and want to use the Console Access feature of the GUI, you must also set 127.0.0.1/255.255.255.255 as a trusted host.

Refer To:https://docs.fortinet.com/document/fortimanager/7.2.9/administration-guide/186508

 

Tuli
rosatechnocrat
Contributor III

Hi Raj,

 

Restricting the access using "admin-restrict-local" does not impact the connection from Fortimanager. Fortimanager will still be able to login and establish the connection. 

 

As a test you can perform the testing on a single Firewall and then can plan for enabling other firewalls across organization. 

Rosa Technocrat --

Also on YouTube---

Please do Subscribe
Rosa Technocrat --Also on YouTube---Please do Subscribe
kulanpu2
New Contributor

What policy are you pushing exactly to the local-in interface? Is this the same interface you use for FMG management? You might be inadvertently blocking FMG traffic to the Fortigate, so it stops half-way through. FMG uses port TCP 541.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors