This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| network_stuff:fortinet [2023/10/11 17:47] – jotasandoku | network_stuff:fortinet [2024/11/19 15:23] (current) – jotasandoku | ||
|---|---|---|---|
| Line 4: | Line 4: | ||
| * FortiAuthenticator | * FortiAuthenticator | ||
| * FortiGuard (TODO) | * FortiGuard (TODO) | ||
| + | * FortiAnalyzer (logging) | ||
| + | ---- | ||
| + | Deploying FortiX: | ||
| + | To identify the hardware: | ||
| + | get system status | ||
| + | |||
| + | * {{: | ||
| + | * console | ||
| + | * admin (no password) > '' | ||
| + | * '' | ||
| + | |||
| + | |||
| + | FortiGate 60F ( FortiOS 7.0 ) | ||
| + | * Fortilink ports and DMZ (labelled) ports | ||
| + | * For console, we can use just the blue flat cable (usb to RJ45) and the MobaXterm > Serial conn. option | ||
| + | |||
| + | show system interface | ||
| + | |||
| + | |||
| + | |||
| + | * For the FortiNet, we want bring up the console from the UI itseld (top right) | ||
| + | * example : '' | ||
| + | * There' | ||
| + | * Zones (TODO) | ||
| + | * concept of sd-wan zone | ||
| + | * Firewall policy& | ||
| + | |||
| + | |||
| + | ---- | ||
| + | ==== Security Fabric ==== | ||
| + | * One FG acts as '' | ||
| + | * Logging is required for the security fabric (in forti analyser or cloud) | ||
| + | * '' | ||
| + | |||
| + | diagnose sys csf auzorisation pending-list | ||
| + | | ||
| + | ---- | ||
| + | ==== Security Features in the Firewalls explained ==== | ||
| + | - Threat Protection performance is measured with :Firewall, IPS, Application Control and Malware Protection enabled. | ||
| + | - NGFW performance is measured with : Firewall, IPS and Application Control enabled. | ||
| + | - IPS (Enterprise Mix), Application Control, NGFW and Threat Protection are measured with Logging enabled. | ||