Course menu

Module 1: Getting StartedLesson 1.5 (5 of 5 in this module)5 of 18 in the FortiGate Administrator course

Administrators, backups and firmware

Admin accounts and profiles, trusted hosts, configuration backups and revisions, and upgrading firmware safely.

Intermediate · 10 min read

What you will learn

After this lesson, you can create administrators with the least privilege they need, restrict where they can log in from, back up and restore the configuration, and plan a firmware upgrade.

  • Admin profiles
  • Trusted hosts
  • Backups
  • Firmware upgrades

FortiGate administration covers who can manage the device and how: administrator accounts with access profiles that grant read or read-write rights per area, trusted hosts that limit the source addresses an admin may log in from, and the routine work of backing up the configuration and upgrading FortiOS along a supported path.

In simple terms: Give each person their own login with only the rights they need, let them log in only from the office network, keep a copy of the configuration, and upgrade carefully.

A real-life situation

A help-desk team needs to read logs on FGT1 to answer user calls, but must not change policies. A contractor needs temporary access to configure VPNs. And next month FGT1 has to move from one FortiOS release to a newer one. None of that should depend on one shared password or on luck.

Administrators and access profiles

config system accprofile edit helpdesk-read set fwgrp read set loggrp read set netgrp read set sysgrp read set vpngrp none next end config system admin edit alice set accprofile helpdesk-read set vdom root set password <a-strong-password> set trusthost1 10.0.1.0 255.255.255.0 next end

helpdesk-read can look at firewall objects, logs, network and system settings but change nothing. alice can log in only from the LAN (10.0.1.0/24): trusted hosts are checked before the password.

  • super_admin has every right; keep it for very few people. prof_admin can manage everything in its VDOM except other administrators and global settings.
  • Trusted hosts apply per administrator. If one admin has no trusted hosts, that account can be tried from anywhere management access is enabled.
  • Administrators can authenticate against RADIUS, TACACS+ or LDAP (remote admins), so leavers are removed in one place, and can use two-factor login with FortiToken, email or SMS codes.

Lockout and idle timeout

config system global set admintimeout 10 set admin-lockout-threshold 3 set admin-lockout-duration 300 end

Idle sessions log out after 10 minutes. After 3 failed login attempts, further attempts are locked out for 300 seconds, which slows down password guessing.

Backups and restores

  • GUI: the admin menu (top right) › Configuration › Backup. Choose to encrypt the file with a password.
  • CLI: execute backup config tftp FGT1.conf 10.0.1.50 (FTP and USB work too).
  • Restore: Configuration › Restore or execute restore config …. The FortiGate reboots with the restored configuration.
  • Revisions: FortiOS can keep configuration revisions on the device, so a recent working version is a click away.

A backup restores cleanly only to the same model and FortiOS version. Take one before every significant change and before every upgrade, and keep copies off the device.

Firmware upgrades

  1. Read the release notes for the target version: supported models, known issues, changed defaults and removed features.
  2. Check the upgrade path. Jumping several releases at once can corrupt or drop configuration; Fortinet publishes the supported intermediate versions in its upgrade path tool.
  3. Back up the configuration (encrypted) and note the current version.
  4. Upgrade in a maintenance window, from System › Firmware & Registration or execute restore image …. The device reboots.
  5. Verify: version, interfaces, routes, VPNs, a test session through each important policy, and the logs.

Why it works this way

A firewall's configuration is the security policy of the whole organisation, so changes to it must be limited, traceable and reversible. Named accounts and access profiles make every change traceable to a person; trusted hosts reduce who can even try to log in; backups and the upgrade path make changes reversible.

Common mistakes

  • Leaving the default admin account in daily use with no trusted hosts.
  • Giving help-desk staff super_admin because creating a profile seemed like extra work.
  • Upgrading straight to the newest release without checking the upgrade path or release notes.
  • Keeping the only backup on the FortiGate itself.

Key takeaways

✅ Key takeaways
  • One account per administrator, with an access profile that grants only what they need.
  • Trusted hosts, lockout and idle timeout reduce the risk of stolen or guessed passwords.
  • Back up (encrypted) before every change and upgrade; restores reboot the device.
  • Upgrade along the published path, after reading the release notes, then verify.

Check yourself

Predict · scenario 1

alice has trusted host 10.0.1.0/24 and the correct password. She tries to log in from home (198.51.100.20) over a port with HTTPS allowed. What happens?

Predict · scenario 2

Which built-in profile can create and delete other administrators?

Predict · scenario 3

FGT1 runs a release several versions behind. What should you check before upgrading to the newest one?

FAQ

Should everyone share the admin account?
No. Shared accounts make the logs useless, because every change appears as 'admin', and make it impossible to remove one person's access. Create a named account per person, or authenticate admins through RADIUS, TACACS+ or LDAP.
Is a backup file sensitive?
Yes. It contains the whole configuration, including password hashes, VPN keys and certificates. Encrypt it with a password when you save it and store it like any other secret.