Fortigate
Installation
- Connext with remote console
- Change the startup password
execute formatlogdisk
format the disk for logs (Init)
Admin port
config system interface
enter inside configuration menu for interfacesedit port6
enter in edit menu for admin portset ip x.x.x.x mask.mask.mask.mask
change ip adressset allowaccess ping http https ssh
allow network traficend
quit menu
Access to outside
config system interface
enter inside configuration menu for interfacesedit port1
enter in edit menu for admin portset ip x.x.x.x mask.mask.mask.mask
change ip adressset allowaccess ping
allow network traficend
quit menu
Default gateway
config router static
enter inside configuration menu for gatewayEdit 1
edit entry 1Set dst 0.0.0.0 0.0.0.0
edit destination adressSet device port1
edit portSet gateway x.x.x.x
edit gatewayEnd
quit menu
DNS server
Config system dns
enter inside configuration menu for DNSSet primary x.x.x.x
edit IP adressend
quit menu
Add licence
- Configure administration station to get access to fortigate
- Use web interface
https://$IP
- Follow setup installer
Reverse proxy
Reverse Proxy Policy&Objects~>Virtual Server~>Create New
* Type : HTTP * Interface : WAN * Virtual server IP : \
Policy&Objects~>Firewall Policy~>Create New
* Inspection mode : Proxy-based * Incoming interface : WAN * Outgoing interface : DMZ-WEB * Source : all * Destination : \
VPN
VPN => IPsec Wizzard Template type : Custom Network : * IP Address : IP du pare-feu distant * Interface : Interface de sortie (WAN) * NAT Traversal : Disable * Deed Peer Detection : On Idle
IKE : Version 2
Phase 1 Proposal : (NB : Supprimer les proposisions non conformes) * Encryption : AES256GCM| PRF : PRFSHA256 * Diffie-Hellman Groups : 19 * Key Lifetime : 21600
Phase 2 selectors : (NB : Supprimer les proposisions non conformes) New Phase 2 : * Local Address :
* Phase 2 Proposal : * Encryption : AES256GCM * Diffie-Hellman Groups : 19 * Key Lifetime : 3600 => Valider et si nécessaire, cliquer sur "Add" (dans Phase 2 Selectors), et configurer le prochain réseau en suivant la procédure ci-dessus.