Fortigate - Admin password lockout >= 300 seconds

Information

Admin password lockout >= 300 seconds. Enforcing a longer wait time for subsequent login attempts will provide for a less desirable target for attackers.

Solution

Issue the following command to configure the admin-lockout-duration.

config system global
set admin-lockout-duration <time_int>
end

See Also

https://docs.fortinet.com/document/fortigate/6.4.0/hardening-your-fortigate/612504/hardening-your-fortigate

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-7a., CSCv6|16.7

Plugin: FortiGate

Control ID: a46817b56a17d6f7d0ee4285fb71827852300057ea320a635d652094ea600088