Skip to main content

Working with a FortiGate account

Last update:

Create an administrator account

  1. Connect to the firewall.
  2. In the FortiGate control panel, go to SystemAdministrators.
  3. Click Create newSystem administrator.
  4. Specify the login and password with which the administrator will connect to the firewall.
  5. Select a profile. A profile is an administrator role with access to firewall settings. By default, the super_admin profile with full access to settings is available. You can create a new profile under SystemAdmin Profiles.
  6. Click OK.

Change the password for the administrator account

  1. Connect to the firewall.
  2. In the FortiGate control panel, go to SystemAdministrators.
  3. Select the administrator login from the list.
  4. Switch to edit mode.
  5. Select Change password.
  6. Enter your old password.
  7. Enter a new password.
  8. Repeat the new password.
  9. Press OK.

Configure account lockout

By default, the account is locked out for 60 seconds after three password attempts. You can change the number of password attempts and the time to wait until the next password attempt.

  1. Connect to the firewall.

  2. Configure the number of password attempts and the waiting time:

    config system global
    set admin-lockout-threshold <admin_lockout_threshold>
    set admin-lockout-duration <admin_lockout_duration>
    end

    Specify:

    • <admin_lockout_threshold> - number of attempts to enter the password. The default setting is three attempts. You can specify a value from 1 to 10;
    • <admin_lockout_duration> - waiting time in seconds, after which you can enter the password again. The default setting is 60 seconds. You can specify a value from 1 to 4294967295.

Rename the account

You cannot rename the account under which you connected to the firewall.

  1. Connect to the firewall under an account with the profile super_admin or another profile with access to the settings in the System.
  2. In the FortiGate control panel, go to SystemAdministrators.
  3. Select the administrator login from the list.
  4. Switch to edit mode.
  5. Change the administrator login.
  6. Press OK.