ក្រុមការងារយើងខ្ញុំនិងខិតខំសិក្សារស្រាវជ្រាវចំនេះដឹងបន្ថែមទៀតសំរាប់លោកអ្នក សូមអរគុណសំរាប់ការគាំទ្រ !
Showing posts with label FortiGate. Show all posts
Showing posts with label FortiGate. Show all posts

Fortigate Monitor/Log/Resport

-ForiView is moniitor &logging tool made up of a number of dashboards that show real time and historical logs.




-Configure Log/Report
-Enable Logging in Security Policy that you want to monitor
-Monitor using FortiView


Fortigate Port Forwarding

- port Forwarding is used to remote from outside to inside network without using VPN but not secure



Configure Port Forwarding :
-Configure Virtual IP
-Create Security Policy to allow outside access to local VIP
-incoming Interface -outgoing interface : WAN - LAN
-Source Address - Destination Address : Internet -VIP (local Web server)
-Service : HTTP,HTTPS

Fortigate IPSec/SSL VPN Configuration

- It's used to remote from public to private network to access local resource: Service & DATA
- It's secure tunnel connection by authentication & encrytion
- Type of VPN: IPSec & SSL



7.1 Configure IPSec VPN
- (Create VPN User)VPN-> User device-> create new -> user name : VPN1
- (Create VPN group) VPN->Group -> create New name - > group name : test -> add user VPN 1 to group test
- Create Policy to allow VPN user access to Internet
- Incoming Interface - Outgoing Interface : VPN -WAN មកពីក្រៅមកក្នុង Pre-share-key : password : Ex :12345
- Source Address  -Destination Address : VPN IP Range - Internet
- Service: HTTP, HTTPS, DNS
- Configure IPSec VPN -> VPN->IPSec-wizard->name : IPSec VPN -> Temple Type: remoteAcess ->Fortigate VPN

- Configure VPN Client (FortiClient)

7.2 Configure SSL VPN
- Create VPN User & Group
- Configure SSL VPN:
-SSL VPN Portal
-Edit Full Access
-Disable Split Tunneling
-Source IP Pool
-Configure Bookmark to remote to local server
-SSL VPN Setting:
-Listen Interface: WAN
-Restrict Access : Allow access from any host
-Server Cerfiticate : Fortinet Factory
-Tunnel Mode Client Setting : SSL VPN IP Range
- Authentication/Portal Mapping: VPN User Group: Full Access
-Create Policy to allow VPN access to LAN
-Incoming interface - Outgoing Interface: VPN - LAN
-Source Address -Destination Address: VPN IP Range/Group: -LAN
-Service : ALL
-Create Policy to allow VPN access to Internet
-Incoming interface - outgoing interface: VPN _WAN
-Source Address : Destonation Address : VPN IP Range/Group -Internet
-Service: HTTP ,HTTPS,DNS
-Configure VPN Client
-Tunnel mode : Forticlient
-Web mode : https://203.1.2.3:10443 : Public IP

FortiGate Firewall/NGFW Configuration


- Firewall : filter incoming & outgiing traffic by using Security Policy to allow or deny traffic

- Firewall Policy Process:
1. Check which Incoming & Outgoing Interface to filter
2. Check which Source & Destination IP address to filter
3. Check what Service to filter
4. Check When the policy to run
5. Check Action to allow or deny
Note : - Incoming Interface : is the interface that receive packet from ( ពីក្រៅមកក្នុង )
- Outgoing Interface :  is the interface that forward packet to  ( ពីក្នុងទៅក្រៅ )
Default Policy
  - Allow all network /Service + NAT
- Deny all Network /Service
- It search policy list from top to down for matching policy -> First match will apply first