2.2.1 Ensure 'Password Policy' is enabled

Information

It is important to use secure and complex passwords for preventing unauthorized access to the FortiGate device.

Attackers can use brute force password software to launch more than just dictionary attacks. Such attacks can discover common passwords where a letter is replaced by a number or symbol.Center for Internet Security (CIS) recommends that passwords should be at least 14 characters long with no limit on the enforced maximum number of characters

Solution

Can be modified from CLI or GUI.

From CLI, do the following:

config system password-policy
set status enable
set apply-to admin-password ipsec-preshared-key
set minimum-length 14
end

Or from GUI, do the following:

1) Log in to FortiGate as Super Admin
2) Go to 'System' > 'Settings'
3) Find the 'Password Policy' section
4) Default 'Password scope' is 'Off', change it to 'Both'
5) set 'Minimum length' to '14'

Impact:

Weak passwords can be easily discovered by hackers, which leads to unauthorized access to FortiGate. Depending on the access privilege of the compromised account, the attacker may modify important settings.

See Also

https://workbench.cisecurity.org/benchmarks/24708

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.4

Plugin: FortiGate

Control ID: 15e49e0ad6c669f83e5c6cb0cfb5eebde4a1a0a570fa5062d53b25cffd446132