[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4g-HWxVfeVedaV59z5RR-5Tqf6nfPjS_NVLBTp0H3Ic":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1078,"How can you distinguish between a Fortigate management page and a VPN login page during penetration testing?","You can differentiate them by the redirect URL. The management page redirects to `\u002Flogin?redir=%2F`, while the VPN login page redirects to `\u002Fremote\u002Flogin?lang=en`. Directly accessing the IP and examining the response helps identify which page is returned. For more on similar identification techniques, see the other articles in the [Penetration Basics](\u002Fnews\u002Fpenetration-basics-fortigate-identification-and-version-detection) series, such as [Zimbra version detection](\u002Fnews\u002Fpenetration-basics-zimbra-version-detection).","\u003Cp>You can differentiate them by the redirect URL. The management page redirects to `\u002Flogin?redir=%2F`, while the VPN login page redirects to `\u002Fremote\u002Flogin?lang=en`. Directly accessing the IP and examining the response helps identify which page is returned. For more on similar identification techniques, see the other articles in the [Penetration Basics](\u002Fnews\u002Fpenetration-basics-fortigate-identification-and-version-detection) series, such as [Zimbra version detection](\u002Fnews\u002Fpenetration-basics-zimbra-version-detection).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-basics-fortigate-identification-and-version-detection\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-you-distinguish-between-a-fortigate-management-page-and-a-vpn-login-page-1777480462651","Fortigate identification, management page, VPN login page, redirect URL",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},263,"Penetration Basics: Fortigate Identification and Version Detection","penetration-basics-fortigate-identification-and-version-detection","Master Fortigate identification (management vs VPN pages) & version detection with Python. Includes step-by-step details, code examples, and open-source scripts for penetration basics.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>Penetration Basics: Fortigate Identification and Version Detection\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>0x00 Preface\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Fortigate identification requires distinguishing between the management page and the VPN login page. Version detection involves extracting features based on page characteristics and matching precise versions using these features. This article will introduce methods to implement Fortigate identification and version detection using Python, along with open-source code.\u003C\u002Fp>\u003Cp>\u003Cstrong>0x01 Introduction\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article will cover the following content:\u003C\u002Fp>\u003Cp>Implementation Ideas\u003C\u002Fp>\u003Cp>Implementation Details\u003C\u002Fp>\u003Cp>Open-Source Code\u003C\u002Fp>\u003Cp>\u003Cstrong>0x02 Implementation Ideas\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Fortigate Identification\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Can be distinguished by the redirected URL\u003C\u002Fp>\u003Cp>Management page redirect URL: \u002Flogin?redir=%2F\u003C\u002Fp>\u003Cp>VPN login page redirect URL: \u002Fremote\u002Flogin?lang=en\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Version Detection\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>There exists a 32-bit hexadecimal string in the page source code that can be used as a feature for version identification; each version corresponds to a different 32-bit string\u003C\u002Fp>\u003Cp>\u003Cstrong>0x03 Implementation Details\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Fortigate Identification\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The method here is to directly access the IP and judge based on the page return result\u003C\u002Fp>\u003Cp>(1) Management Page\u003C\u002Fp>\u003Cp>A 32-bit hexadecimal string can be obtained from the return result\u003C\u002Fp>\u003Cp>(2) VPN Login Page\u003C\u002Fp>\u003Cp>The returned content is a redirect address; you need to parse the redirect address, reconstruct the URL, access it, and obtain a 32-bit hexadecimal string from the return result\u003C\u002Fp>\u003Cp>Example of the returned redirect address content:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透基础——Fortigate识别与版本探测\" src=\"\u002Fuploads\u002Fdocx_image_1769396801143_0_1b08ff8785.png\">Since the redirect URL is not fixed, you can extract the redirect URL via regex matching here. Example code:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透基础——Fortigate识别与版本探测\" src=\"\u002Fuploads\u002Fdocx_image_1769396803316_1_b4a05af7c3.png\">\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>When judging the version, you cannot use the allow_redirects=False parameter in the requests module to control redirection. The reason is as follows:\u003C\u002Fp>\u003Cp>When using the requests module, if you use the allow_redirects=False parameter, redirection is only disabled when the return status code is 301 or 302. Here, Fortigate returns a status code of 200, so the allow_redirects=False parameter has no effect\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Version Detection\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>During actual testing, different versions of Fortigate all return 32-bit hexadecimal characters, but their formats are different. To improve matching efficiency and reduce workload, we choose to directly match the 32-bit hexadecimal characters in regex matching here. The example code is as follows:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透基础——Fortigate识别与版本探测\" src=\"\u002Fuploads\u002Fdocx_image_1769396809117_2_46e7260b4a.png\">\u003C\u002Fp>\u003Cp>During actual testing, there are cases where the output of response.text is garbled\u003C\u002Fp>\u003Cp>The process of researching solutions is as follows:\u003C\u002Fp>\u003Cp>Output response.headers, sample code:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透基础——Fortigate识别与版本探测\" src=\"\u002Fuploads\u002Fdocx_image_1769396810865_3_a50f5626a4.png\">\u003C\u002Fp>\u003Cp>Return result:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透基础——Fortigate识别与版本探测\" src=\"\u002Fuploads\u002Fdocx_image_1769396813140_4_b7d1b3a5e3.png\">\u003C\u002Fp>\u003Cp>Found the encoding format is x-gzip\u003C\u002Fp>\u003Cp>Therefore, we can perform an additional gzip decoding on response.text here to get the original data, the code is as follows:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透基础——Fortigate识别与版本探测\" src=\"\u002Fuploads\u002Fdocx_image_1769396814960_5_5d3dc2ef58.png\">The complete implementation code is as follows:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透基础——Fortigate识别与版本探测\" src=\"\u002Fuploads\u002Fdocx_image_1769396816269_6_13448f24d6.png\">\u003Cimg alt=\"【技术原创】渗透基础——Fortigate识别与版本探测\" src=\"\u002Fuploads\u002Fdocx_image_1769396820735_7_cb4c0fe0c4.png\">\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>If you encounter the error ERR_SSL_VERSION_OR_CIPHER_MISMATCH when accessing the SSL VPN Client page via a browser, the program will return the following result:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透基础——Fortigate识别与版本探测\" src=\"\u002Fuploads\u002Fdocx_image_1769396825055_8_a1e78ba934.png\">\u003C\u002Fp>\u003Cp>Solution:\u003C\u002Fp>\u003Cp>Just switch to Python2\u003C\u002Fp>\u003Cp>\u003Cstrong>0x04 Open Source Code\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The complete implementation code has been uploaded to GitHub, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002F3gstudent\u002FHomework-of-Python\u002Fblob\u002Fmaster\u002FFortigate_GetVersion.py\u003C\u002Fp>\u003Cp>The code supports distinguishing between management pages and VPN login pages, provides a VM version fingerprint database as an example, can automatically extract fingerprint features from the page, compare them with the fingerprint database, and identify the exact version.\u003C\u002Fp>\u003Cp>\u003Cstrong>0x05 Summary\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article introduces methods to implement Fortigate identification and version detection using Python, covers implementation details and open-source code, and serves as an excellent learning example.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>Penetration Basics: Fortigate Identification and Version Detection\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>0x00 Preface\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Fortigate identification requires distinguishing between the management page and the VPN login page. Version detection involves extracting features based on page characteristics and matching precise versions using these features. This article will introduce methods to implement Fortigate identification and version detection using Python, along with open-source code.\u003C\u002Fp>\u003Cp>\u003Cstrong>0x01 Introduction\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article will cover the following content:\u003C\u002Fp>\u003Cp>Implementation Ideas\u003C\u002Fp>\u003Cp>Implementation Details\u003C\u002Fp>\u003Cp>Open-Source Code\u003C\u002Fp>\u003Cp>\u003Cstrong>0x02 Implementation Ideas\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Fortigate Identification\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Can be distinguished by the redirected URL\u003C\u002Fp>\u003Cp>Management page redirect URL: \u002Flogin?redir=%2F\u003C\u002Fp>\u003Cp>VPN login page redirect URL: \u002Fremote\u002Flogin?lang=en\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Version Detection\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>There exists a 32-bit hexadecimal string in the page source code that can be used as a feature for version identification; each version corresponds to a different 32-bit string\u003C\u002Fp>\u003Cp>\u003Cstrong>0x03 Implementation Details\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Fortigate Identification\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The method here is to directly access the IP and judge based on the page return result\u003C\u002Fp>\u003Cp>(1) Management Page\u003C\u002Fp>\u003Cp>A 32-bit hexadecimal string can be obtained from the return result\u003C\u002Fp>\u003Cp>(2) VPN Login Page\u003C\u002Fp>\u003Cp>The returned content is a redirect address; you need to parse the redirect address, reconstruct the URL, access it, and obtain a 32-bit hexadecimal string from the return result\u003C\u002Fp>\u003Cp>Example of the returned redirect address content:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透基础——Fortigate识别与版本探测\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396801143_0_1b08ff8785-1.png\">Since the redirect URL is not fixed, you can extract the redirect URL via regex matching here. Example code:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透基础——Fortigate识别与版本探测\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396803316_1_b4a05af7c3-1.png\">\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>When judging the version, you cannot use the allow_redirects=False parameter in the requests module to control redirection. The reason is as follows:\u003C\u002Fp>\u003Cp>When using the requests module, if you use the allow_redirects=False parameter, redirection is only disabled when the return status code is 301 or 302. Here, Fortigate returns a status code of 200, so the allow_redirects=False parameter has no effect\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Version Detection\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>During actual testing, different versions of Fortigate all return 32-bit hexadecimal characters, but their formats are different. To improve matching efficiency and reduce workload, we choose to directly match the 32-bit hexadecimal characters in regex matching here. The example code is as follows:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透基础——Fortigate识别与版本探测\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396809117_2_46e7260b4a-1.png\">\u003C\u002Fp>\u003Cp>During actual testing, there are cases where the output of response.text is garbled\u003C\u002Fp>\u003Cp>The process of researching solutions is as follows:\u003C\u002Fp>\u003Cp>Output response.headers, sample code:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透基础——Fortigate识别与版本探测\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396810865_3_a50f5626a4-1.png\">\u003C\u002Fp>\u003Cp>Return result:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透基础——Fortigate识别与版本探测\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396813140_4_b7d1b3a5e3-1.png\">\u003C\u002Fp>\u003Cp>Found the encoding format is x-gzip\u003C\u002Fp>\u003Cp>Therefore, we can perform an additional gzip decoding on response.text here to get the original data, the code is as follows:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透基础——Fortigate识别与版本探测\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396814960_5_5d3dc2ef58-1.png\">The complete implementation code is as follows:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透基础——Fortigate识别与版本探测\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396816269_6_13448f24d6-1.png\">\u003Cimg alt=\"【技术原创】渗透基础——Fortigate识别与版本探测\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396820735_7_cb4c0fe0c4-1.png\">\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>If you encounter the error ERR_SSL_VERSION_OR_CIPHER_MISMATCH when accessing the SSL VPN Client page via a browser, the program will return the following result:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透基础——Fortigate识别与版本探测\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396825055_8_a1e78ba934-1.png\">\u003C\u002Fp>\u003Cp>Solution:\u003C\u002Fp>\u003Cp>Just switch to Python2\u003C\u002Fp>\u003Cp>\u003Cstrong>0x04 Open Source Code\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The complete implementation code has been uploaded to GitHub, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002F3gstudent\u002FHomework-of-Python\u002Fblob\u002Fmaster\u002FFortigate_GetVersion.py\u003C\u002Fp>\u003Cp>The code supports distinguishing between management pages and VPN login pages, provides a VM version fingerprint database as an example, can automatically extract fingerprint features from the page, compare them with the fingerprint database, and identify the exact version.\u003C\u002Fp>\u003Cp>\u003Cstrong>0x05 Summary\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article introduces methods to implement Fortigate identification and version detection using Python, covers implementation details and open-source code, and serves as an excellent learning example.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",276,"Onedaysec",3,"published","2026-02-02T07:25:19.984Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Fortigate Identification & Version Detection (Python Basics Guide)","Fortigate identification, Fortigate version detection, Python Fortigate script, Fortigate penetration testing, open-source Fortigate code, Fortigate management page, Fortigate VPN login page, Fortigate fingerprint matching",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],1081,1080,1079,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.787Z","2026-07-23T16:02:29.875Z","draft","2026-07-23T16:16:32.635Z"]