Showing posts with label FortiGate. Show all posts
Showing posts with label FortiGate. Show all posts
Fortigate Port Forwarding
- port Forwarding is used to remote from outside to inside network without using VPN but not secure
Configure Port Forwarding :
-Configure Virtual IP
-Create Security Policy to allow outside access to local VIP
-incoming Interface -outgoing interface : WAN - LAN
-Source Address - Destination Address : Internet -VIP (local Web server)
-Service : HTTP,HTTPS
Configure Port Forwarding :
-Configure Virtual IP
-Create Security Policy to allow outside access to local VIP
-incoming Interface -outgoing interface : WAN - LAN
-Source Address - Destination Address : Internet -VIP (local Web server)
-Service : HTTP,HTTPS
Fortigate IPSec/SSL VPN Configuration
- It's used to remote from public to private network to access local resource: Service & DATA
- It's secure tunnel connection by authentication & encrytion
- Type of VPN: IPSec & SSL
7.1 Configure IPSec VPN
- (Create VPN User)VPN-> User device-> create new -> user name : VPN1
- (Create VPN group) VPN->Group -> create New name - > group name : test -> add user VPN 1 to group test
- Create Policy to allow VPN user access to Internet
- Incoming Interface - Outgoing Interface : VPN -WAN មកពីក្រៅមកក្នុង Pre-share-key : password : Ex :12345
- Source Address -Destination Address : VPN IP Range - Internet
- Service: HTTP, HTTPS, DNS
- Configure IPSec VPN -> VPN->IPSec-wizard->name : IPSec VPN -> Temple Type: remoteAcess ->Fortigate VPN
- Configure VPN Client (FortiClient)
7.2 Configure SSL VPN
- Create VPN User & Group
- Configure SSL VPN:
-SSL VPN Portal
-Edit Full Access
-Disable Split Tunneling
-Source IP Pool
-Configure Bookmark to remote to local server
-SSL VPN Setting:
-Listen Interface: WAN
-Restrict Access : Allow access from any host
-Server Cerfiticate : Fortinet Factory
-Tunnel Mode Client Setting : SSL VPN IP Range
- Authentication/Portal Mapping: VPN User Group: Full Access
-Create Policy to allow VPN access to LAN
-Incoming interface - Outgoing Interface: VPN - LAN
-Source Address -Destination Address: VPN IP Range/Group: -LAN
-Service : ALL
-Create Policy to allow VPN access to Internet
-Incoming interface - outgoing interface: VPN _WAN
-Source Address : Destonation Address : VPN IP Range/Group -Internet
-Service: HTTP ,HTTPS,DNS
-Configure VPN Client
-Tunnel mode : Forticlient
-Web mode : https://203.1.2.3:10443 : Public IP
- It's secure tunnel connection by authentication & encrytion
- Type of VPN: IPSec & SSL
7.1 Configure IPSec VPN
- (Create VPN User)VPN-> User device-> create new -> user name : VPN1
- (Create VPN group) VPN->Group -> create New name - > group name : test -> add user VPN 1 to group test
- Create Policy to allow VPN user access to Internet
- Incoming Interface - Outgoing Interface : VPN -WAN មកពីក្រៅមកក្នុង Pre-share-key : password : Ex :12345
- Source Address -Destination Address : VPN IP Range - Internet
- Service: HTTP, HTTPS, DNS
- Configure IPSec VPN -> VPN->IPSec-wizard->name : IPSec VPN -> Temple Type: remoteAcess ->Fortigate VPN
- Configure VPN Client (FortiClient)
7.2 Configure SSL VPN
- Create VPN User & Group
- Configure SSL VPN:
-SSL VPN Portal
-Edit Full Access
-Disable Split Tunneling
-Source IP Pool
-Configure Bookmark to remote to local server
-SSL VPN Setting:
-Listen Interface: WAN
-Restrict Access : Allow access from any host
-Server Cerfiticate : Fortinet Factory
-Tunnel Mode Client Setting : SSL VPN IP Range
- Authentication/Portal Mapping: VPN User Group: Full Access
-Create Policy to allow VPN access to LAN
-Incoming interface - Outgoing Interface: VPN - LAN
-Source Address -Destination Address: VPN IP Range/Group: -LAN
-Service : ALL
-Create Policy to allow VPN access to Internet
-Incoming interface - outgoing interface: VPN _WAN
-Source Address : Destonation Address : VPN IP Range/Group -Internet
-Service: HTTP ,HTTPS,DNS
-Configure VPN Client
-Tunnel mode : Forticlient
-Web mode : https://203.1.2.3:10443 : Public IP
FortiGate Firewall/NGFW Configuration
- Firewall : filter incoming & outgiing traffic by using Security Policy to allow or deny traffic
- Firewall Policy Process:
1. Check which Incoming & Outgoing Interface to filter
2. Check which Source & Destination IP address to filter
3. Check what Service to filter
4. Check When the policy to run
5. Check Action to allow or deny
Note : - Incoming Interface : is the interface that receive packet from ( ពីក្រៅមកក្នុង )
- Outgoing Interface : is the interface that forward packet to ( ពីក្នុងទៅក្រៅ )
Default Policy
- Allow all network /Service + NAT
- Deny all Network /Service
- It search policy list from top to down for matching policy -> First match will apply first
Subscribe to:
Posts (Atom)



