1

I made an error while configuring my admin account on the FortiGate 60d and enabled forti token for 2 step authentication. Thing is I enabled the wrong token and I do not have that device with me. Now when I try to login to the GUI using my admin credentials, it asks for the token code "which I don't have"!!

What should I do in order to get back into the account without having to reset it.

Thank You for your help in advance guys!

mat
  • 11

1 Answers1

1

This thread is quite dated but someone might still be looking for a solution.

Yes, there is a way back in if you have physical access and some tools (namely, a terminal app to access the serial port, and the serial-to-RJ45 cable). This is described here in Fortinet's recipe (http://docs.fortinet.com/uploaded/files/1708/Resetting_a_lost_admin_password.pdf).

The Fortigate will reboot but will retain it's configuration. You will have to change the 2F authentication in the CLI (CLI reference available at docs.fortinet.com).

Note that in recent versions of FortiOS you can disable this recovery option. Then there's is no recovery once the admin account is inaccessible.

user1016274
  • 1,619