Rule ID
SV-234168r960840_rule
Version
V1R5
CCIs
CCI-000044
By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-forcing, is reduced.
Log in to the FortiGate GUI with Super-Admin privilege.
1. Open a CLI console, via SSH or available from the GUI.
2. Confirm the output from the following command:
# show full-configuration system global | grep -i admin-lockout
The output should be:
set admin-lockout-duration 900
set admin-lockout-threshold 3
If the admin-lockout-duration is not set to 900 and admin-lockout-threshold is not set to 3, this is a finding.Log in to the FortiGate GUI with Super-Admin privilege.
1. Open a CLI console, via SSH or available from the GUI.
2. Run the following commands:
# config system global
# set admin-lockout-duration 900
# set admin-lockout-threshold 3
# end