Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Anne
New Contributor III

Prof_ Admin -- Authentication Failure

Hi there, 310B 4.3.6 VDOM' s enabled I am a super admin and created a new local admin account. Selected Admin Profile as " Prof_admin" and Virtual Domain as a VDOM for this customer. We are not using Two-factor Authentication and I have not restricted this admin login from Trusted Hosts. When I try to access the firewall Gui using https, I get the username and the password prompt. I enter the correct username and password and I get the message " AUthentication Failure" . I changed the Admin profile of the same admin to " super admin" and it works fine. This was working fine in the past and we did not change anything. edit " test" set remote-auth disable set peer-auth disable set trusthost1 0.0.0.0 0.0.0.0 set trusthost2 0.0.0.0 0.0.0.0 set trusthost3 0.0.0.0 0.0.0.0 set trusthost4 0.0.0.0 0.0.0.0 set trusthost5 0.0.0.0 0.0.0.0 set trusthost6 0.0.0.0 0.0.0.0 set trusthost7 0.0.0.0 0.0.0.0 set trusthost8 0.0.0.0 0.0.0.0 set trusthost9 0.0.0.0 0.0.0.0 set trusthost10 0.0.0.0 0.0.0.0 set ip6-trusthost1 ::/0 set ip6-trusthost2 ::/0 set ip6-trusthost3 ::/0 set ip6-trusthost4 ::/0 set ip6-trusthost5 ::/0 set ip6-trusthost6 ::/0 set ip6-trusthost7 ::/0 set ip6-trusthost8 ::/0 set ip6-trusthost9 ::/0 set ip6-trusthost10 ::/0 set accprofile " prof_admin" set comments ' ' set vdom " VDOM222" unset ssh-public-key1 unset ssh-public-key2 unset ssh-public-key3 set schedule ' ' config dashboard-tabs edit 1 set name " Status" next end config dashboard edit 1 set widget-type sysinfo set name ' ' set tab-id 1 set column 1 set status open next edit 2 set widget-type licinfo set name ' ' set tab-id 1 set column 1 set status open --More-- next edit 8 set widget-type tr-history set name ' ' set tab-id 1 set column 1 set interface " port2" set tr-history-period1 3600 set tr-history-period2 86400 set tr-history-period3 2592000 set refresh enable set status open next edit 3 set widget-type jsconsole set name ' ' set tab-id 1 set column 1 set status open next edit 4 set widget-type sysres --More-- set name ' ' set tab-id 1 set column 2 set time-period 0 set chart-color 0 set view-type real-time set status open next edit 5 Can someone please help..
5 REPLIES 5
Anne
New Contributor III

Fixed the issue. thanks for viewing.
Tommy_Rogers
New Contributor

I am having a similar issue under the same circumstance. You did not post your fix. Can you please share what you did? We had a VDOM called CampusLAN and one of my comrades logged into the CLI with the intention to edit this VDOM. He entered campuslan by mistake and it created a new VDOM. He then deleted the VDOM and afterwards the Prof_Admin for that VDOM quit working. I have tried adding a new admin, deleting all the Prof_Admin accounts and recreating them, rebooting, and none of these worked. Any help would be a blessing. Thanks
Tommy Rogers FCNSA FCNSP
Tommy Rogers FCNSA FCNSP
Anne
New Contributor III

Let me explain our scenario. I (as a super admin) access the firewall by connecting (https/ssh) to a public ip (lets say IP1 )assigned to the external VLAN interface of our root VDOM. I created a new profile admin and assigned him VDOM X. VDOM X has a external VLAN interface which is configured with a different ip (lets say IP2). When this prof admin makes an attempt to connect to IP1 (ssh/https), he gets prompted to logon with user name and password but when he logs on, he gets the message " Authentication Failure" When the same admin connects to IP2 (ssh/https), it works fine. If I change the prof of this admin from " prof_admin" to " super_admin" , he can connect from anywhere and once connected, is able to logon as well. So in my case, I was making an attempt for my prof_admin to connect to IP1 which was failing but working fine if connect to IP2. I am not sure if i have been able to explain it properly or not. I have tried my best. Are you having the same issues? Thanks Anne
DELMAS
New Contributor

I faced the same issue and finally found out :)

 

The reason of the problem (thereby, the solution) is explained here : http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-virtual-domains-54/5-Troubleshooting/...

 

"An administrator can only access their VDOM through interfaces that are assigned to that VDOM. If interfaces on that VDOM are disabled or unavailable there will be no method of accessing that VDOM by its local administrator. The super_admin will be required to either bring up the interfaces, fix the interfaces, or move another interface to that VDOM to restore access."

 

So if you give access for an administrator (let's say "toto") to a specific VDOM through an interface which is in another VDOM where toto has no access, the login will not work until you give him access to the vdom where the interface is.

 

So an administrator can access to its vdom only through an interface of that same vdom.

emnoc
Esteemed Contributor III

Question is the user logging into vdom "VDOM222"? If not that's why it's failing.

 

Ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors