A real-life situation
A help-desk team needs to read logs on FGT1 to answer user calls, but must not change policies. A contractor needs temporary access to configure VPNs. And next month FGT1 has to move from one FortiOS release to a newer one. None of that should depend on one shared password or on luck.
Administrators and access profiles
config system accprofile
edit helpdesk-read
set fwgrp read
set loggrp read
set netgrp read
set sysgrp read
set vpngrp none
next
end
config system admin
edit alice
set accprofile helpdesk-read
set vdom root
set password <a-strong-password>
set trusthost1 10.0.1.0 255.255.255.0
next
endhelpdesk-read can look at firewall objects, logs, network and system settings but change nothing. alice can log in only from the LAN (10.0.1.0/24): trusted hosts are checked before the password.
- super_admin has every right; keep it for very few people. prof_admin can manage everything in its VDOM except other administrators and global settings.
- Trusted hosts apply per administrator. If one admin has no trusted hosts, that account can be tried from anywhere management access is enabled.
- Administrators can authenticate against RADIUS, TACACS+ or LDAP (remote admins), so leavers are removed in one place, and can use two-factor login with FortiToken, email or SMS codes.
Lockout and idle timeout
config system global
set admintimeout 10
set admin-lockout-threshold 3
set admin-lockout-duration 300
endIdle sessions log out after 10 minutes. After 3 failed login attempts, further attempts are locked out for 300 seconds, which slows down password guessing.
Backups and restores
- GUI: the admin menu (top right) › Configuration › Backup. Choose to encrypt the file with a password.
- CLI:
execute backup config tftp FGT1.conf 10.0.1.50(FTP and USB work too). - Restore: Configuration › Restore or
execute restore config …. The FortiGate reboots with the restored configuration. - Revisions: FortiOS can keep configuration revisions on the device, so a recent working version is a click away.
A backup restores cleanly only to the same model and FortiOS version. Take one before every significant change and before every upgrade, and keep copies off the device.
Firmware upgrades
- Read the release notes for the target version: supported models, known issues, changed defaults and removed features.
- Check the upgrade path. Jumping several releases at once can corrupt or drop configuration; Fortinet publishes the supported intermediate versions in its upgrade path tool.
- Back up the configuration (encrypted) and note the current version.
- Upgrade in a maintenance window, from System › Firmware & Registration or
execute restore image …. The device reboots. - Verify: version, interfaces, routes, VPNs, a test session through each important policy, and the logs.
Why it works this way
A firewall's configuration is the security policy of the whole organisation, so changes to it must be limited, traceable and reversible. Named accounts and access profiles make every change traceable to a person; trusted hosts reduce who can even try to log in; backups and the upgrade path make changes reversible.
Common mistakes
- Leaving the default admin account in daily use with no trusted hosts.
- Giving help-desk staff super_admin because creating a profile seemed like extra work.
- Upgrading straight to the newest release without checking the upgrade path or release notes.
- Keeping the only backup on the FortiGate itself.
Key takeaways
- One account per administrator, with an access profile that grants only what they need.
- Trusted hosts, lockout and idle timeout reduce the risk of stolen or guessed passwords.
- Back up (encrypted) before every change and upgrade; restores reboot the device.
- Upgrade along the published path, after reading the release notes, then verify.
Check yourself
alice has trusted host 10.0.1.0/24 and the correct password. She tries to log in from home (198.51.100.20) over a port with HTTPS allowed. What happens?
Which built-in profile can create and delete other administrators?
FGT1 runs a release several versions behind. What should you check before upgrading to the newest one?