Fortinet white logo
Fortinet white logo

Administration Guide

Configuring basic system settings

Configuring basic system settings

The basic system settings page includes configuration options for the following settings and features:

  • Hostname
  • Web UI language
  • Management service ports
  • DNS
  • Virtual domain
Before you begin:
  • You must have Read-Write permission for System settings.
To configure basic system settings:
  1. Go to System > Settings.
  2. The configuration page displays the Basic tab.

  3. Complete the configuration as described in Basic settings configuration.
  4. Save the configuration.

Basic settings configuration

Settings Guidelines
Hostname You can configure a hostname to facilitate system management. If you use SNMP, for example, the SNMP system name is derived from the configured hostname.The hostname can be up to 35 characters in length. It can include US-ASCII letters, numbers, hyphens, and underscores, but not spaces and special characters.

The System Information widget and the get system status CLI command display the full hostname. If the hostname is longer than 16 characters, the name is truncated and ends with a tilde ( ~ ) to indicate that additional characters exist, but are not displayed.
Language

Select from the following supported languages:

  • English

  • Simplified Chinese

  • Japanese

  • Spanish

  • Traditional Chinese

  • Portuguese

Idle Timeout Log out an idle administrator session. The default is 30 minutes.

HTTPS Server Cert

Select a certificate object.

Default Intermediate CA Group

Select an Intermediate CA group.

SSH Port Specify the port for the SSH service. Usually, SSH uses port 22.
Telnet Port Specify the port for the Telnet service. Usually, Telnet uses port 25.
Primary DNS The system must be able to contact DNS servers to resolve IP addresses and fully qualified domain names. Your Internet service provider (ISP) might supply IP addresses of DNS servers, or you might want to use the IP addresses of your own DNS servers. You must provide unicast, non-local addresses for your DNS servers. Localhost and broadcast addresses are not accepted.

Incorrect DNS settings or unreliable DNS connectivity can cause issues with other features, such as FortiGuard services and NTP system time.
Secondary DNS IPv4/IPv6 address of the secondary DNS server for your local network.
Virtual Domain Enables the virtual domain feature. Before you enable it, make sure you understand how the system implements virtual domains. See Virtual Domain.

Virtual Domain Mode

The Virtual Domain Mode option is available if Virtual Domain is enabled.

Select the virtual domain mode:

  • Independent Network — each VDOM functions independently within its own network, unaffected by activity from other VDOMs on the system.
  • Share Network — VDOMs function as administrative domains (ADOMs), sharing the same network interface and routing between all ADOMs.

For details, see Enabling the Virtual Domain feature and selecting the Virtual Domain Mode.

HTTP Port Specify the port for the HTTP service. Usually, HTTP uses port 80.

Redirect to HTTPS

When enabled, all HTTP connections to FortiADC will be redirected to HTTPS. HTTPS-Redirect switch is enabled by default.

HTTPS Port Specify the port for the HTTPS service. Usually, HTTPS uses port 443.
Config Sync Enable Enable/disable the configuration synchronization feature. This feature is related to Pushing/pulling configurations, not HA synchronization. Disabled by default.

Pre Login Banner

Enable/disable the pre-login banner feature to show login disclaimer messages. Disabled by default.

Admin Bypass VDOM Check

The Admin Bypass VDOM Check option is available if Virtual Domain is enabled and the Virtual Domain Mode is Independent Network.

Once enabled, all non-root VDOM administrators can login through the root VDOM interface without needing root VDOM privileges. From the root VDOM interface, the non-root VDOM administrator can access and modify the settings relating to their designated non-root VDOM.

This is disabled by default.

Note: When the Admin Bypass VDOM Check is enabled, admin event logs are recorded solely under the root VDOM, regardless of the VDOM assigned to the user. This is due to the way the log API handles event logging, allowing event logging for only one VDOM at a time.

OWASP Top10 Compliance

Enable OWASP Top10 Compliance to view the security compliance rate for each SLB virtual server in FortiView.

This is disabled by default.

For details, see OWASP Top 10 Compliance.

Feedback Options

Upload detection statistics to FortiGuard

Enable or disable FortiADC detection statistics upload to FortiGuard. This is enabled by default.

For details, see Sending FortiADC Threat Telemetry to FortiGuard.

Configuring basic system settings

Configuring basic system settings

The basic system settings page includes configuration options for the following settings and features:

  • Hostname
  • Web UI language
  • Management service ports
  • DNS
  • Virtual domain
Before you begin:
  • You must have Read-Write permission for System settings.
To configure basic system settings:
  1. Go to System > Settings.
  2. The configuration page displays the Basic tab.

  3. Complete the configuration as described in Basic settings configuration.
  4. Save the configuration.

Basic settings configuration

Settings Guidelines
Hostname You can configure a hostname to facilitate system management. If you use SNMP, for example, the SNMP system name is derived from the configured hostname.The hostname can be up to 35 characters in length. It can include US-ASCII letters, numbers, hyphens, and underscores, but not spaces and special characters.

The System Information widget and the get system status CLI command display the full hostname. If the hostname is longer than 16 characters, the name is truncated and ends with a tilde ( ~ ) to indicate that additional characters exist, but are not displayed.
Language

Select from the following supported languages:

  • English

  • Simplified Chinese

  • Japanese

  • Spanish

  • Traditional Chinese

  • Portuguese

Idle Timeout Log out an idle administrator session. The default is 30 minutes.

HTTPS Server Cert

Select a certificate object.

Default Intermediate CA Group

Select an Intermediate CA group.

SSH Port Specify the port for the SSH service. Usually, SSH uses port 22.
Telnet Port Specify the port for the Telnet service. Usually, Telnet uses port 25.
Primary DNS The system must be able to contact DNS servers to resolve IP addresses and fully qualified domain names. Your Internet service provider (ISP) might supply IP addresses of DNS servers, or you might want to use the IP addresses of your own DNS servers. You must provide unicast, non-local addresses for your DNS servers. Localhost and broadcast addresses are not accepted.

Incorrect DNS settings or unreliable DNS connectivity can cause issues with other features, such as FortiGuard services and NTP system time.
Secondary DNS IPv4/IPv6 address of the secondary DNS server for your local network.
Virtual Domain Enables the virtual domain feature. Before you enable it, make sure you understand how the system implements virtual domains. See Virtual Domain.

Virtual Domain Mode

The Virtual Domain Mode option is available if Virtual Domain is enabled.

Select the virtual domain mode:

  • Independent Network — each VDOM functions independently within its own network, unaffected by activity from other VDOMs on the system.
  • Share Network — VDOMs function as administrative domains (ADOMs), sharing the same network interface and routing between all ADOMs.

For details, see Enabling the Virtual Domain feature and selecting the Virtual Domain Mode.

HTTP Port Specify the port for the HTTP service. Usually, HTTP uses port 80.

Redirect to HTTPS

When enabled, all HTTP connections to FortiADC will be redirected to HTTPS. HTTPS-Redirect switch is enabled by default.

HTTPS Port Specify the port for the HTTPS service. Usually, HTTPS uses port 443.
Config Sync Enable Enable/disable the configuration synchronization feature. This feature is related to Pushing/pulling configurations, not HA synchronization. Disabled by default.

Pre Login Banner

Enable/disable the pre-login banner feature to show login disclaimer messages. Disabled by default.

Admin Bypass VDOM Check

The Admin Bypass VDOM Check option is available if Virtual Domain is enabled and the Virtual Domain Mode is Independent Network.

Once enabled, all non-root VDOM administrators can login through the root VDOM interface without needing root VDOM privileges. From the root VDOM interface, the non-root VDOM administrator can access and modify the settings relating to their designated non-root VDOM.

This is disabled by default.

Note: When the Admin Bypass VDOM Check is enabled, admin event logs are recorded solely under the root VDOM, regardless of the VDOM assigned to the user. This is due to the way the log API handles event logging, allowing event logging for only one VDOM at a time.

OWASP Top10 Compliance

Enable OWASP Top10 Compliance to view the security compliance rate for each SLB virtual server in FortiView.

This is disabled by default.

For details, see OWASP Top 10 Compliance.

Feedback Options

Upload detection statistics to FortiGuard

Enable or disable FortiADC detection statistics upload to FortiGuard. This is enabled by default.

For details, see Sending FortiADC Threat Telemetry to FortiGuard.