Fortinet white logo
Fortinet white logo

CLI Reference

config system password-policy

config system password-policy

Configure password policy for locally defined administrator passwords and IPsec VPN pre-shared keys.

config system password-policy
    Description: Configure password policy for locally defined administrator passwords and IPsec VPN pre-shared keys.
    set apply-to {option1}, {option2}, ...
    set expire-day {integer}
    set expire-status [enable|disable]
    set login-lockout-upon-weaker-encryption [enable|disable]
    set min-lower-case-letter {integer}
    set min-non-alphanumeric {integer}
    set min-number {integer}
    set min-upper-case-letter {integer}
    set minimum-length {integer}
    set reuse-password [enable|disable]
    set reuse-password-limit {integer}
    set status [enable|disable]
end

config system password-policy

Parameter

Description

Type

Size

Default

apply-to

Apply password policy to administrator passwords or IPsec pre-shared keys or both. Separate entries with a space.

option

-

admin-password

Option

Description

admin-password

Apply to administrator passwords.

ipsec-preshared-key

Apply to IPsec pre-shared keys.

expire-day

Number of days after which passwords expire (1 - 999 days, default = 90).

integer

Minimum value: 1 Maximum value: 999

90

expire-status

Enable/disable password expiration.

option

-

disable

Option

Description

enable

Passwords expire after expire-day days.

disable

Passwords do not expire.

login-lockout-upon-weaker-encryption

Enable/disable administrative user login lockout upon downgrade (defaut = disable). If enabled, changing the FortiOS firmware to a version where safer passwords are unsupported will lock out administrative users.

option

-

disable

Option

Description

enable

Enable administrative user login lockout upon downgrade.

disable

Disable administrative user login lockout upon downgrade.

min-lower-case-letter

Minimum number of lowercase characters in password (0 - 128, default = 1).

integer

Minimum value: 0 Maximum value: 128

1

min-non-alphanumeric

Minimum number of non-alphanumeric characters in password (0 - 128, default = 1).

integer

Minimum value: 0 Maximum value: 128

1

min-number

Minimum number of numeric characters in password (0 - 128, default = 1).

integer

Minimum value: 0 Maximum value: 128

1

min-upper-case-letter

Minimum number of uppercase characters in password (0 - 128, default = 1).

integer

Minimum value: 0 Maximum value: 128

1

minimum-length

Minimum password length (12 - 128, default = 12).

integer

Minimum value: 12 Maximum value: 128

12

reuse-password

Enable/disable reuse of password.

option

-

enable

Option

Description

enable

Administrators are allowed to reuse the same password up to a limit.

disable

Administrators must create a new password.

reuse-password-limit

Number of times passwords can be reused (0 - 20, default = 0. If set to 0, can reuse password an unlimited number of times.).

integer

Minimum value: 0 Maximum value: 20

0

status

Enable/disable setting a password policy for locally defined administrator passwords and IPsec VPN pre-shared keys.

option

-

enable

Option

Description

enable

Enable password policy.

disable

Disable password policy.

config system password-policy

config system password-policy

Configure password policy for locally defined administrator passwords and IPsec VPN pre-shared keys.

config system password-policy
    Description: Configure password policy for locally defined administrator passwords and IPsec VPN pre-shared keys.
    set apply-to {option1}, {option2}, ...
    set expire-day {integer}
    set expire-status [enable|disable]
    set login-lockout-upon-weaker-encryption [enable|disable]
    set min-lower-case-letter {integer}
    set min-non-alphanumeric {integer}
    set min-number {integer}
    set min-upper-case-letter {integer}
    set minimum-length {integer}
    set reuse-password [enable|disable]
    set reuse-password-limit {integer}
    set status [enable|disable]
end

config system password-policy

Parameter

Description

Type

Size

Default

apply-to

Apply password policy to administrator passwords or IPsec pre-shared keys or both. Separate entries with a space.

option

-

admin-password

Option

Description

admin-password

Apply to administrator passwords.

ipsec-preshared-key

Apply to IPsec pre-shared keys.

expire-day

Number of days after which passwords expire (1 - 999 days, default = 90).

integer

Minimum value: 1 Maximum value: 999

90

expire-status

Enable/disable password expiration.

option

-

disable

Option

Description

enable

Passwords expire after expire-day days.

disable

Passwords do not expire.

login-lockout-upon-weaker-encryption

Enable/disable administrative user login lockout upon downgrade (defaut = disable). If enabled, changing the FortiOS firmware to a version where safer passwords are unsupported will lock out administrative users.

option

-

disable

Option

Description

enable

Enable administrative user login lockout upon downgrade.

disable

Disable administrative user login lockout upon downgrade.

min-lower-case-letter

Minimum number of lowercase characters in password (0 - 128, default = 1).

integer

Minimum value: 0 Maximum value: 128

1

min-non-alphanumeric

Minimum number of non-alphanumeric characters in password (0 - 128, default = 1).

integer

Minimum value: 0 Maximum value: 128

1

min-number

Minimum number of numeric characters in password (0 - 128, default = 1).

integer

Minimum value: 0 Maximum value: 128

1

min-upper-case-letter

Minimum number of uppercase characters in password (0 - 128, default = 1).

integer

Minimum value: 0 Maximum value: 128

1

minimum-length

Minimum password length (12 - 128, default = 12).

integer

Minimum value: 12 Maximum value: 128

12

reuse-password

Enable/disable reuse of password.

option

-

enable

Option

Description

enable

Administrators are allowed to reuse the same password up to a limit.

disable

Administrators must create a new password.

reuse-password-limit

Number of times passwords can be reused (0 - 20, default = 0. If set to 0, can reuse password an unlimited number of times.).

integer

Minimum value: 0 Maximum value: 20

0

status

Enable/disable setting a password policy for locally defined administrator passwords and IPsec VPN pre-shared keys.

option

-

enable

Option

Description

enable

Enable password policy.

disable

Disable password policy.