Fortinet white logo
Fortinet white logo

Administration Guide

Cleanup of Legacy Authentication CLI to Complete Site Publish Transition (8.0.0)

Cleanup of Legacy Authentication CLI to Complete Site Publish Transition (8.0.0)

FortiWeb 8.0.0 finalizes the removal of the legacy authentication framework by clearing all related CLI tables and options. This completes the transition to Site Publishing as the unified mechanism for offloading HTTP authentication and managing user access control.

The previous implementation relied on local user definitions, user groups, authentication rules, and policies. While the associated GUI elements were removed in 7.6.1, backend support remained available through the CLI. In this release, that remaining functionality has now been retired.

CLI Removals in 8.0.0

The following CLI commands and configuration elements have been removed:

CLI Path

Change

config user local-user Removed
config user user-group Removed
config waf http-authen http-authen-rule Removed
config waf http-authen http-authen-policy Removed
config waf web-protection-profile inline-protection Removed http-authen-policy
config waf web-protection-profile offline-protection Removed http-authen-policy (Option already removed in 7.6.1)

These changes prevent the creation or modification of legacy authentication configurations via the CLI.

Site Publish as the Replacement

All authentication offloading is now handled through Site Publish. This approach supports direct integration with remote authentication servers (LDAP, RADIUS, NTLM, KDC, SAML, and TACACS+) and enables advanced capabilities such as login page customization, two-factor authentication, user attribute forwarding, and optional SSO.

To configure authentication offloading:

  • Define remote authentication servers under User > Remote Server

  • Add the servers to an Authentication Server Pool

  • Create a Site Publish rule that references the pool

  • Apply the rule in a server policy

Cleanup of Legacy Authentication CLI to Complete Site Publish Transition (8.0.0)

Cleanup of Legacy Authentication CLI to Complete Site Publish Transition (8.0.0)

FortiWeb 8.0.0 finalizes the removal of the legacy authentication framework by clearing all related CLI tables and options. This completes the transition to Site Publishing as the unified mechanism for offloading HTTP authentication and managing user access control.

The previous implementation relied on local user definitions, user groups, authentication rules, and policies. While the associated GUI elements were removed in 7.6.1, backend support remained available through the CLI. In this release, that remaining functionality has now been retired.

CLI Removals in 8.0.0

The following CLI commands and configuration elements have been removed:

CLI Path

Change

config user local-user Removed
config user user-group Removed
config waf http-authen http-authen-rule Removed
config waf http-authen http-authen-policy Removed
config waf web-protection-profile inline-protection Removed http-authen-policy
config waf web-protection-profile offline-protection Removed http-authen-policy (Option already removed in 7.6.1)

These changes prevent the creation or modification of legacy authentication configurations via the CLI.

Site Publish as the Replacement

All authentication offloading is now handled through Site Publish. This approach supports direct integration with remote authentication servers (LDAP, RADIUS, NTLM, KDC, SAML, and TACACS+) and enables advanced capabilities such as login page customization, two-factor authentication, user attribute forwarding, and optional SSO.

To configure authentication offloading:

  • Define remote authentication servers under User > Remote Server

  • Add the servers to an Authentication Server Pool

  • Create a Site Publish rule that references the pool

  • Apply the rule in a server policy