Fortigate VPN SSL Hardening Guide

Table of Contents Introduction Change the default SSL VPN port 10443/443 to anything else Do not use local users for authentication, and if using - keep passwords elsewhere or/and enable MFA Enable Multi-Factor Authentication for VPN users Limit access to VPN SSL portal to specific IP addresses Move VPN …



Fortigate Firewalls Hardware - CPU model and number, Memory (RAM) and hard disk size datasheet table

Note The data is gathered via get hardware stat command. Note If you have access to the Fortigate model not listed here, please consider sending me output of get hardware stat to be included in the table to yuri@yurisk.info for the benefit of all of us. Note It …



Fortigate BGP cookbook of example configuration and debug commands

Last updated: August 2020 PDF version of this post: Fortigate BGP cookbook of example configuration and debug commands.pdf BGP with two ISPs for multi-homing, each advertising default gateway and full routing table. Uses route-map, prefix list, weight Prevent our Fortigate from becoming a transit AS, do not advertise learned …



Fortigate - switch from NAT to transparent mode error fix

When trying to switch a Fortigate from NAT mode to the Transparent one, we get an error about Fortilink interface being used. The official docs just say to delete Fortilink from all used settings, but not how. This article shows where and how. The error: config sys settings set opmode …



Fortinet-related blogs to read

Blogs and other resources to read on Fortinet products - Fortigate, Fortianalyzers, Fortimanager and such Here are some Fortinet-related technical blogs I read. If you have additional blogs/sites to recommend - send me to add. https://www.ultraviolet.network/blog Matt Sherif’s blog. Matt is a System Engineer at Fortinet …



Send logs from non-Fortinet devices to Fortianalyzer via Syslog

Can we send logs from non-Fortinet devices to the Fortianalyzer? This question pops up from time to time and the short answer is yes, for sure - any device that can send its logs in syslog format (read any device of Enterprise level today), can also send the logs to Fortianalyzer …



Collection of Fortigate Automation Stitches

Table of Contents Collection Important facts All about email alerts Debug Automation Stitches Collection Collection I collected some Fortigate automation stitches I use in production systems to either alert me in real time on outstanding events, or run debug/maintenance action without manual intervention. The collection is here https://github …



My networks talk to a prisoner, help.

Help, my networks talk to a prisoner. This was a funny one - client saw lots of DNS queries passing the Fortigate addressed at the prisoner.iana.org and was worried what this was about. No worry - it just means (misconfigured) clients in the LAN are trying to get PTR records …



sFlow in Fortigate disables Hardware Acceleration

Do not use sFlow in Fortigate - use Netflow instead I was approached last month by 2 unrelated Fortigate admins with the same problem - slow performance of otherwise very beafy Fortigate models. After some digging in the configuration the culprit was found - there was enabled on WAN interface sFlow. sflow collects …



Fortinet products Fortigate Fortiweb Fortimail and others online demo access details

Be it to learn the interface or preparing for NSE 5, 6, 7 exams, having the access to the real device is the best way to retain the information. Fortinet make available online access to all of their products for demo purposes, all for free. If not mentioned otherwise, the …