Fortigate - Password Expiry date <= 30 days

Information

Ensure that the administrator password has an expiry date of at most 30 days. Enforcing strong password policies reduces the chance that a password will be compromised.

Solution

Use this command to configure higher security requirements for administrator passwords and
IPsec VPN pre-shared keys.

config system password-policy
set status {enable | disable}
set apply-to [admin-password ipsec-preshared-key]
set change-4-characters {enable | disable}
set expire <days>
set minimum-length <chars>
set min-lower-case-letter <num_int>
set min-upper-case-letter <num_int>
set min-non-alphanumeric <num_int>
set min-number <num_int>
set expire-status {enable | disable}
set expire-day <num_int>
end

See Also

https://docs.fortinet.com/document/fortigate/6.4.0/hardening-your-fortigate/612504/hardening-your-fortigate

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(d)

Plugin: FortiGate

Control ID: a0f51d611bd51e8488ca189eb75424efc70342ef8af1ccfb939fc73270b82fc9