img00

Configuring the LAN interface, including DHCP server

Network > Interfaces > doble-click on port5 img01

Alias: LAN-HQ Role: LAN IP/Netmask 172.16.10.1/24 img02

Administrative Access IPV4 : HTTPS, PING, SSH after Enable DHCP Server img03

Address range: 172.16.10.21-172.16.10.256 img04

Comments: Lan port connected to HQ and click OK img05

Double-click on port6 img06

Alias: WAN-ISP Role: WAN img07

IP/Netmask: 172.16.20.1/30 and IPV4: SSH img08

Comments: WAN port connected to ISP and click OK img09

Configuration of the LAN and WAN interfaces is complete.

   

   

Configure and monitor the default route

Network > Static Routes > click create New img10

Destination Subnet : 0.0.0.0/0 Gateway Address: 172.16.20.2 Interface: WAN-ISP (port6) and OK img11

Dashboard > Network > Click to expand img12

img13

   

   

   

   

Create a firewall address of the internal subnet

Policy & Objects > Addresses > Click Create New img14

Name: Internal Network IP/Network: 10.0.1.0/24 img15

Interface: port3 and press OK img16

The firewall address of the internal subnet is created.

   

   

Configure the firewall policy

Policy & Objects > Firewall Policy > Click Create New img17

Name: Internal Access Incoming Interface: port3 Outgoing Interface: port1 img18

Click Source + > Select Internal Network > Click Close img19

Destination + > Select all > Click Close img20

Service + > Select HTTP HTTPS DNS > Click Close img21

Enable NAT img22

This is an outgoing traffic policy, and NAT is enabled. This allows FortiGate to translate the private address of the network device to the public IP address of the port1 interface.

Log allowed traffic: All sessions and Click OK img23

img24

Firewall configuration complete!

   

   

Verify the firewall policy configuration

  1. for test open https://www.fortinet.com

  2. Policy & Objects > Firewall Policy > Right-click the policy img25

  3. Click Show Matching Logs img26

img27

The Forward Traffic logs for all traffic matching this policy appears on the screen, verifying that FortiGate is applying the policy.

  1. for test open cmd > telnet www.fortinet.com (its 23 port)

  2. Policy & Objects > Firewall Policy > Right Click Implicit Deny policy > Click Show Matching Logs > img29

Because Telnet traffic doesn’t match the Internet Access policy, it is processed and blocked by the Implicit Deny policy.

   

   

   

   

Create a user account

User & Authentication > User Definition > Create New img30

img31

Username: fatima Password: password > Next img32

Click Next img33

img34

img35

   

   

Configure remote authentication

User & Authentication > LDAP Servers > Create New img36

Name: RemoteAuthServer Server IP/Name: 10.0.1.150 Server Port: 389 Common Name Indentifier: uid Distinguished Name: ou=Training,dc=TrainingAD,dc=training,dc=lab. img37 Bind Type: Regular Username: uid=aduser1,ou=Training,dc=TrainingAD,dc=training,dc=lab img38

Password: Training! and Press Test Connectivity and OK img39

img40

Remote authentication is configured

   

   

Create a user group

User & Authentication > Users Groups > Create New img41

Name: sales Type: Firewall members: fatima img42

Remote Groups + Add > Remote Server: RemoteAuthServer > OK img43

img44

A user group created img45

Click OK img46

   

   

Add authentication to the firewall policy

Policy & Objects > Firewall Policy > Internal Network > Edit img47 Open User/group: sales > close
img48 Click OK img49

img50

The sales group is now part of the firewall policy source.

   

   

Verify and monitor firewall authentication

open website > Open network login page img51

Username: fatima Password: password > Continue img52

img53

img54 Dashboard > Status > Firewall Users img55 The user fatima shows as authenticated and connected. img56

   

   

   

   

Apply SSL inspection

Securtity Profiles > SSL/SSH Inspection > Click on custom-deep-inspection > Click Edit img57

Invalid SSL certificates > Allow img58

Click OK img59

Policy & Objects > Firewall Policy > Internal Network > Edit img60

Web filter: default     SSL inspection: custom-deep-inspection > OK > Warning OK img61

img62

The security profiles are now applied to the firewall policy

in browser, go to https://google.com > Advanced > Aceept the Risk and Continue img63

The lock with the warning indicates that you added a security exception. img64

   

   

Install the CA certificate to avoid certificate warnings

Securtity Profiles > SSL/SSH Inspection > Click on custom-deep-inspection > Click Edit img57

CA certificate Download Fortinet_CA_SSL img65

and install it

   

   

   

   

Create an antivirus profile

Security Profiles > AntiVirus > default > Edit img66

Use FortiGuard outberak prevention database [X] > OK img67

img69

The default antivirus profile edit is complete.

   

   

Apply antivirus to a firewall policy

Policy & Objects > Firewall Policy > Internal Network > Edit img70

Policy & Objects > Firewall Policy > Internet Access > Edit img71

Antivirus[V] default > SSL Inspection deep-inspection > OK
img72

img73

The security profile is now applied to the firewall policy

   

   

Verify antivirus

Type https://www.eicar.org/download-anti-malware-testfile

download Com-file img74

img75

Log & Report > Security Events > AntiVirus img76

One or more EICAR_TEST_FILE entries appear, with the Action show as Blocked. img77

Antivirus inspection is verified.

   

   

   

   

Configure Web Filter on FortiGate

Ensure that FortiGate has valid FortiGuard security subscription license

Status > Webfilter [see status]

Identify how the FortiGuard service categorizes specific websites

www.fortiguard.com/webfilter img111

Configure a web filtering profile to use FortiGuard category-based filters

Security Profiles > Web filter > default > edit

Social Networking: block > OK img112

Apply the web filter security profile to a firewall policy

  1. Policy & Objects > Firewall Policy > Full Access > edit

  2. Web filter: default , SSL Inspection custom-deep-inspection, Log allowed traffic [Security events] > OK

Test the configured actions for FortiGuard category-based filters and examine logs

  1. type site img113

  2. Log & Report > Security Events > Web Filter > logs
    img114

Configure Authenticate cation for a FortiGuard Category Filter

  1. Security Profiles > Web Filter > default > edit

  2. FortiGuard Category Based Filter > Authenticate > Warning Interval : 5 minute(s) Selected User Groups: Ovveride_Permissions > OK > OK

  3. User & Authentication > User Definition > + Create New > Local User > Next > Username student Password password> Next > Next > User Group [x] Overide_Permissions > Submit

Test the Authenticate action and examine logs

type in browser img115

username & password img116

img117

   

   

   

   

Create a Custom IPS sensor

Security Profiles > Intrusion Prevention > Create New img78

Name: Radius_Signatures_Sensor > + Create New img79

Type: Signature > Action: Block > Type Radius > Search Icon img80

Add All Results > Edit IP Exemptions img81

Click Create New img82

Click Source IP/Netmask img83

Type 10.0.0.0/24 > Apply > OK img84

Click OK img85

Click OK img86

img87

This sensor is ready to be applied to a firewall policy

   

   

   

   

Configure application control

Security Profiles > Application Control > Create New img88

Name:Block_Video img89

Video/Audio: Block img90

Click OK img91

Policy & Objects > Firewall Policy > Internet Access > Edit img92

Application control: [x] Block_Video img93

Click OK img94

img95

The application control profile is configured.

   

   

Monitor application control

Type: www.youtube.com img96

Log & Report > Security Events > Double-Click Application Control

img97

img98

img99

   

   

   

   

Comfigure and test a site-to-site IPsec VPN

Create the IPSec VPN using the VPN wizard

  1. VPN > VPN Wizard > Tunnel name: HQ-to-Branch Select a Template [x][Site to Site] > Begin

  2. Remote Site, IP/FQDN 10.200.3.1 Remote site subnet can acess VPN 10.0.2.0/24> img118

  3. VPN Tunnel, Pre-shared key: password, Next >

  4. Outgoing interface that binds to tunnel port1 local interface port3 local subnets that can access VPN 10.0.1.0/24, Next > img119

  5. Submit img120

img121

   

  1. VPN > VPN Wizard > Tunnel name: Branch-to-HQ Select a Template [x][Site to Site] > Begin img122

  2. Remote Site, IP/FQDN 10.200.1.1 Remote site subnet can acess VPN 10.0.1.0/24>

  3. VPN Tunnel, Pre-shared key: password, Next >

  4. Outgoing interface that binds to tunnel port4, local interface port6, local subnets that can access VPN 10.0.1.0/24, Next >

  5. Submit

img123

Test the site-to site IPsec VPN

  1. cmd > ping 10.0.2.10

VPN > VPN Tunnels >

   

   

Configure Fortigate for remote access IPsec VPN

VPN > VPN Wizard > Click Remote Access img100

Tunnel Name: RemoteVPN > Click Begin img101

IP Range for connected endpoints 10.0.0.70-10.0.0.80 Subnet 255.255.255.0 > Next img102

Pre-shared key password User group Sales > Next
img103

Incoming Interface that binds to tunnel port1 Local Interface port3 Local Address InternalNetwork > Next img104

Click Submit img105

img106

VPN has been set up

Network > Interfaces > + img107

img108

Policy & Objects > Firewall Policy img109

Examine the entry with the name containing the string RemoteVPN

Policy & Objects > Addresses > Search: romotevpn img110

   

   

   

   

Configure and Test SSL VPN with FortiGate

VPN > SSL-VPN Portals > Double-Click full-access > img124

img125 Click OK img126

Configure VPN SSL settings

  1. SSL-VPN status Enable Listen on Port 443 Service Certificate: Fortinet_Factory > + Create New img127

  2. + Create New > UserGroups RemoteVpnUsers Portal Full-access

  3. Apply img128

Configure Policy Firewall

  1. Policy & Objects > Firewall Policy > Create New

Name: `SSLVPNACCESS` 
Incoming interface: `SSLVPN tunnel Interface (ssl root)` 
Outgoing interface: `port3` 
Source:  `SSLVPN_TUNNEL_ADDR1`
Usergroup: `RemoteVPNUsers`
Destination: `LOCAL_SUBNET`
Service: `ALL`

OK > img129

img130

   

   

   

   

Backup up the configuration and performing a filmwware upgrade

Click Admin > Configuration > Backup > OK img131

Now that you have a configuration backup, you can safely upgrade your FortiGate firmware. It is a best practice to backup your configuration before you start an upgrade, or you can do it during the upgrade. This simulation shows you how to do both.

Click Admin > System > Firmware & Registration > local-FortiGate > Upgrade img132

[x] FortiGate Only > Next > img133

File Upload > Upload File > Select file > Next
img134

Click Next img135

Click Confirm and Backup config > System will reboot upon proceeding Are you sure you want to continue? > Yes img136

The system will be restart with the new firmware installed.

   

   

Examining traffic logs

Log & Report > Forward Traffic > Click on log img137

Scroll down the Log Details window to view the Action section.

Hover your mouse over the value next to Policy ID to see details about the firewall policy that generated this log.

Right Click on Destination img138

Configure and Test Fortinet Security Fabric

Verify the FortiAnalyzer configuration

Device Manager > img139

Status Down

Configure Logging on Local-FortiGate

Security Fabric > Fabric Connectors > Double-Click Logging & Analytics > Edit img140

Status: Enabled Server: 10.0.1.210 Upload option [Real Time] > OK > Accept img141

img142

Configure Local-FortiGate for the Security Fabric and make it Root firewall

Security Fabric > Fabric Connectors > Double-Click > Secure Fabric Setup > Select Server as Fabric Root img143

Allow other Security Fabric device to join > + > port3 > edit > img144

Security Fabric [x] Device detection [x] > OK > OK > Close img145

Fabric Name: FGT Operator Demo Fabric global obkect [x] img146

img147

Add Task ISFW to the Security Fabric

Security Fabric > Fabric Connectors > Double-Click > Secure Fabric Setup > img148

Join Existing Fabric > Allow other Security Fabric devices to join [x] > [+] img149

port1 > edit > img150

Security Fabric [x] Device detection [x] > OK > OK > Close 151

Upsteam FortiGate IP/FQDN 10.0.1.254 Management IP/FQDN [Specify] 10.0.1.200 Default admin profile super_admin > OK 152

153

Authorize ISFW in the Security Fabric

System > Formware Regestration > FGVM01000000077464> Authorize > After Refresh Webpage 154

img155

img156

Explore the Security Fabric

Security Fabric > Physical Topology > Update Now img157

Security Fabric > Logical Topology img158

Policy & Objects > Addresses > Create New

Name: MyDemoSubnet IP/Network: 192.168.100.0/24 Fabric global-object [v]

OK> img159

Now MyDemoSubnet on 2 devices img160

img161

   

   

   

   

Examine current Security Fabric rating and apply recomendations

Security Fabric > Security Rating > img162 img163

img164 img165

img166

Admin Idle Timeout The timeout for idle administrator sessions is currently set to 10 minutes. This is one of the parameters that does not meet industry best practices, which is why it is marked as Failed. As indicated in the GUI, this parameter should be set to 10 minutes or less.

System > Settings img167

Scroll down the System Settings page to find the ldle timeout type 10 > Apple img168

Click [x] remove the two filters img169

Note that the current number of Passed and Failed parameters was updated by increasing and reducing each one respectively by 1. You can repeat the same process to fix other parameters, making your device more secure.

   

   

   

   

Fortigate Hight Availability (HA)

img170

Configure HA on the primary unit

System > HA > Mode: Active-Passive

Device priority 200, Group ID 5, Group Name HA-DEMO, Password password, Session pickup [x], Heartbeat inteface port7, > OK img171

Refresh webpage img172

Configure HA on the secondary unit

System > HA > Mode: Active-Passive

Device priority 128, Group ID 5, Group Name HA-DEMO, Password password, Session pickup [x], Heartbeat inteface port7, > OK img173

Refresh webpage img174

Verify the HA cluster

Refresh webpage > Status can be Synchronized img175

   

   

   

   

Verify the initial configuration of the three FortiSwitch devices

img176

System > Feature Visibility > Switch Controller img177

Open CLI Console img178

System > Feature Visibility > Switch Controller on [x] > Apply img179

Wifi & Switch Controller > FortiLink Interface > Create FortiLink Inerface

Name: Fortilink Alies FortiLink, Inteface members port3, IP/Netmask 10.0.13.254/24 Automatically authorize devices [x] Address range 10.0.13.2-10.0.13.253 img180

Verify and test the management of the FortiSwitch devices form FortiGate

Refresh webpage img181

Wifi & Switch Controller > Managed FortiSwitches > img182

Rename switches img183

img184

img185

Wifi & Switch Controller > FortiSwitch VLANs > + Create > Name: DEMOVLAN VLAN ID 200 > OK img186

img187