Fortinet white logo
Fortinet white logo

Administration Guide

Administrators

Administrators

Use the System > Administrators page to configure administrator user accounts.

If the admin user's Admin Profile does not have Read Write privilege under System > Admin Profiles, the user can only view and edit their own information.

The following options are available:

Create New

Create a new administrator account.

Edit

Edit the selected entry.

Delete

Delete the selected entry.

Test Login

Test the selected user's login settings. If an error occurs, a debug message appears.

The following information is displayed:

Name

The administrator account name.

Type

The administrator type:

  • Local: User information is stored in the FortiDeceptor local database and authenticated locally by FortiDeceptor.
  • LDAP: User information is stored in the remote LDAP server. A copy of the username is stored in the FortiDeceptor local database (without password and other information), and is authenticated remotely by the LDAP server. See, LDAP Servers.
  • RADIUS: User information is stored in the remote RADIUS server. A copy of the username is stored in the FortiDeceptor local database (without password and other information), and is authenticated remotely by the RADIUS server. See, RADIUS Servers.

NOTE: For Single Sign-On (SSO), user information is stored in a remote Identity Provider (IdP) server. No user information is stored locally. Instead, FortiDeceptor acts as a Service Provider (SP). When a login request is received, FortiDeceptor redirects the request via SAML protocol to the IdP to complete the authentication. See Single Sign-On.

Profile

The Admin Profile the user belongs to.

To create a new user:
  1. Log in using an account with Read/Write access and go to System > Administrators.
  2. Click Create New.
  3. Configure the following:

    Administrator

    Name of the administrator account. The name must be 1 to 30 characters using upper-case letters, lower-case letters, numbers, or the underscore character (_) for Local and LDAP administrators.

    The character limit for RADIUS server administrators is 64 characters.

    Password, Confirm Password

    Password of the account. The password must be 6 to 64 characters using upper-case letters, lower-case letters, numbers, or special characters.

    This field is available when Type is set to Local.

    Type

    Select Regular Admin, Local, LDAP, or RADIUS.

    LDAP Server

    When Type is LDAP, select an LDAP Server. For more information, see LDAP Servers.

    RADIUS Server

    When Type is RADIUS, select a RADIUS Server. For more information, see RADIUS Servers.

    Regular Admin

    When Type is Regular Admin, the user will have almost all the same privileges of a Super admin, but cannot see or can change the Super Admin user profile.

    Only Super Admin and Regular Admin accounts can choose the Regular Admin type to create a new Regular Admin.

    When a Regular Admin logs in, they will not see the Super User account. Regular Admins can see and edit all other users. Regular Admins have access to the same Menu items and CLI Commands settings as a Super Admin.

    Push notification to mobile if applicable

    Enable FortiToken push notifications for mobile devices.

    This option is available when Type is RADIUS.

    Admin Profile

    Select the Admin Profile.

    Trusted Host 1, Trusted Host 2, Trusted Host 3

    Enter up to three IPv4 trusted hosts. Only users from trusted hosts can access FortiDeceptor.

    Trusted IPv6 Host 1, Trusted IPv6 Host 2, Trusted IPv6 Host 3

    Enter up to three IPv6 trusted hosts. Only users from trusted hosts can access FortiDeceptor.

    Comments

    Enter an optional comment.

    Setting trusted hosts for administrators limits the computers an administrator can use to log into FortiDeceptor. When you identify a trusted host, FortiDeceptor only accepts the administrator’s login from the configured IP address or subnet. Attempts to log in with the same credentials from another IP address or subnet are dropped.

  4. Click OK.
To edit a user account:
  1. Log in using an account with Read/Write access and go to System > Administrators.
  2. Select and account and click Edit.

    Only the admin user can edit its own settings.

    You must enter the old password before you can set a new password.

  3. Edit the account and click OK.
To delete one or more user accounts:
  1. Log in using an account with Read/Write access and go to System > Administrators.
  2. Select the user account you want to delete.
  3. Click Delete and confirm that you want to delete the user.
To test LDAP or RADIUS logins:
  1. Log in using an account with Read/Write access and go to System > Administrators.
  2. Select an LDAP or RADIUS user to test.
  3. Click Test Login.
  4. Enter the user password.
  5. Click OK.

    If an error occurs, a debug message appears.

When a remote RADIUS server is configured for two-factor authentication, RADIUS users must enter a FortiToken code or the code from email/SMS to complete login or to test login.

Administrators

Administrators

Use the System > Administrators page to configure administrator user accounts.

If the admin user's Admin Profile does not have Read Write privilege under System > Admin Profiles, the user can only view and edit their own information.

The following options are available:

Create New

Create a new administrator account.

Edit

Edit the selected entry.

Delete

Delete the selected entry.

Test Login

Test the selected user's login settings. If an error occurs, a debug message appears.

The following information is displayed:

Name

The administrator account name.

Type

The administrator type:

  • Local: User information is stored in the FortiDeceptor local database and authenticated locally by FortiDeceptor.
  • LDAP: User information is stored in the remote LDAP server. A copy of the username is stored in the FortiDeceptor local database (without password and other information), and is authenticated remotely by the LDAP server. See, LDAP Servers.
  • RADIUS: User information is stored in the remote RADIUS server. A copy of the username is stored in the FortiDeceptor local database (without password and other information), and is authenticated remotely by the RADIUS server. See, RADIUS Servers.

NOTE: For Single Sign-On (SSO), user information is stored in a remote Identity Provider (IdP) server. No user information is stored locally. Instead, FortiDeceptor acts as a Service Provider (SP). When a login request is received, FortiDeceptor redirects the request via SAML protocol to the IdP to complete the authentication. See Single Sign-On.

Profile

The Admin Profile the user belongs to.

To create a new user:
  1. Log in using an account with Read/Write access and go to System > Administrators.
  2. Click Create New.
  3. Configure the following:

    Administrator

    Name of the administrator account. The name must be 1 to 30 characters using upper-case letters, lower-case letters, numbers, or the underscore character (_) for Local and LDAP administrators.

    The character limit for RADIUS server administrators is 64 characters.

    Password, Confirm Password

    Password of the account. The password must be 6 to 64 characters using upper-case letters, lower-case letters, numbers, or special characters.

    This field is available when Type is set to Local.

    Type

    Select Regular Admin, Local, LDAP, or RADIUS.

    LDAP Server

    When Type is LDAP, select an LDAP Server. For more information, see LDAP Servers.

    RADIUS Server

    When Type is RADIUS, select a RADIUS Server. For more information, see RADIUS Servers.

    Regular Admin

    When Type is Regular Admin, the user will have almost all the same privileges of a Super admin, but cannot see or can change the Super Admin user profile.

    Only Super Admin and Regular Admin accounts can choose the Regular Admin type to create a new Regular Admin.

    When a Regular Admin logs in, they will not see the Super User account. Regular Admins can see and edit all other users. Regular Admins have access to the same Menu items and CLI Commands settings as a Super Admin.

    Push notification to mobile if applicable

    Enable FortiToken push notifications for mobile devices.

    This option is available when Type is RADIUS.

    Admin Profile

    Select the Admin Profile.

    Trusted Host 1, Trusted Host 2, Trusted Host 3

    Enter up to three IPv4 trusted hosts. Only users from trusted hosts can access FortiDeceptor.

    Trusted IPv6 Host 1, Trusted IPv6 Host 2, Trusted IPv6 Host 3

    Enter up to three IPv6 trusted hosts. Only users from trusted hosts can access FortiDeceptor.

    Comments

    Enter an optional comment.

    Setting trusted hosts for administrators limits the computers an administrator can use to log into FortiDeceptor. When you identify a trusted host, FortiDeceptor only accepts the administrator’s login from the configured IP address or subnet. Attempts to log in with the same credentials from another IP address or subnet are dropped.

  4. Click OK.
To edit a user account:
  1. Log in using an account with Read/Write access and go to System > Administrators.
  2. Select and account and click Edit.

    Only the admin user can edit its own settings.

    You must enter the old password before you can set a new password.

  3. Edit the account and click OK.
To delete one or more user accounts:
  1. Log in using an account with Read/Write access and go to System > Administrators.
  2. Select the user account you want to delete.
  3. Click Delete and confirm that you want to delete the user.
To test LDAP or RADIUS logins:
  1. Log in using an account with Read/Write access and go to System > Administrators.
  2. Select an LDAP or RADIUS user to test.
  3. Click Test Login.
  4. Enter the user password.
  5. Click OK.

    If an error occurs, a debug message appears.

When a remote RADIUS server is configured for two-factor authentication, RADIUS users must enter a FortiToken code or the code from email/SMS to complete login or to test login.