12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

System Administrators<br />

Administrators<br />

Figure 91: Administrator account configuration - PKI authentication<br />

Administrator<br />

Type<br />

User Group<br />

Wildcard<br />

Password<br />

Confirm<br />

Password<br />

Trusted Host #1<br />

Trusted Host #2<br />

Trusted Host #3<br />

Access Profile<br />

Enter the login name for the administrator account.<br />

The name of the administrator should not contain the characters<br />

()#"'. Using these characters in the administrator account name can<br />

result in a cross site scripting (XSS) vulnerability.<br />

Select the type of administrator account:<br />

• Regular: Select to create a Local administrator account.<br />

• RADIUS: Select to authenticate the administrator using a RADIUS<br />

server. RADIUS authentication for administrators must be configured<br />

first. See “Configuring RADIUS authentication for administrators” on<br />

page 163.<br />

• PKI: Select to enable certificate-based authentication for the<br />

administrator. Only one configured administrator can have the PKI<br />

option enabled at all times.<br />

If you are using RADIUS or PKI certificate-based authentication, select<br />

the administrator user group that includes the RADIUS server/PKI (peer)<br />

users as members of the User Group. The administrator user group<br />

cannot be deleted once the group is selected for authentication.<br />

Select to allow all accounts on the RADIUS server to be administrators.<br />

This is available only if RADIUS is selected.<br />

Enter a password for the administrator account. For improved security,<br />

the password should be at least 6 characters long.<br />

If RADIUS is enabled, the <strong>FortiGate</strong> unit attempts RADIUS authentication<br />

first, and if that fails, it attempts password authentication.<br />

This is not available if Wildcard is selected. Not available when PKI<br />

authentication is selected.<br />

Type the password for the administrator account a second time to<br />

confirm that you have typed it correctly.<br />

This is not available if Wildcard is selected. Not available when PKI<br />

authentication is selected.<br />

Optionally, type the trusted host IP address and netmask that<br />

administrator login is restricted to on the <strong>FortiGate</strong> unit. You can specify<br />

up to three trusted hosts. These addresses all default to 0.0.0.0/0.<br />

Setting trusted hosts for all of your administrators can enhance the<br />

security of your system. For more information, see “Using trusted hosts”<br />

on page 168.<br />

Select the access profile for the administrator. The pre-configured<br />

super_admin profile provides full access to the <strong>FortiGate</strong> unit. You can<br />

also select Create New to create a new access profile. For more<br />

information on access profiles, see “Configuring an access profile” on<br />

page 172.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 167

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!