Fortigate - Admin password lockout >= 300 seconds

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Admin password lockout >= 300 seconds. Enforcing a longer wait time for subsequent login attempts will provide for a less desirable target for attackers.

Solution

Issue the following command to configure the admin-lockout-duration.

config system global
set admin-lockout-duration <time_int>
end

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-7, CSCv6|16.7

Plugin: FortiGate

Control ID: 50e472778b9e777324311bbb06fc3eca9c34545348a22975f13bf3947cdf5b52