7.1 Configuring the maximum login attempts and lockout period

Information

Configure maximum user login attempts and lockout period.

Rationale:

Failed user login attempts can indicate an attempt to gain access to the network. Limiting the number of attempts before the account is locked for a determined amount of time helps slow down brute force attempts and impedes malicious attempts to access user accounts.

Solution

On CLI:

config user setting
set auth-lockout-threshold 5
set auth-lockout-duration 300
end

Default Value:

auth-lockout-threshold: 3 auth-lockout-duration: 0

See Also

https://workbench.cisecurity.org/benchmarks/12961

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-18, 800-53|AC-18(1), 800-53|AC-18(3), 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SC-23

Plugin: FortiGate

Control ID: cbf82c2082b99aafcf7eea50936ffef98f7931f4191d2e3935caedcef06651cf