No video

FortiGate : 5 Admin Access Security Hardening Tips

  Рет қаралды 26,287

Fortinet Guru

Fortinet Guru

Күн бұрын

A lot of people access their FortiGates remotely without the proper precautions and consideration being executed. These five tips will assist you with making sure that the bad guys have to try a little harder to compromise your admin accounts when you are remote administering your FortiGates.
Buy Hardware: bit.ly/2QZVeqh
Get Consulting: bit.ly/36FinSU
My Other Projects:
Office Of The CISO: bit.ly/3HGMH1o
Packet Llama: bit.ly/3SEX3H4
###### SOCIAL LINKS ######
Twitter: bit.ly/2WXiRAv
Facebook: bit.ly/3eigz4D
Instagram: bit.ly/3cZneAz
######################

Пікірлер: 60
@FortinetGuru
@FortinetGuru 4 жыл бұрын
What tips and tricks about security hardening do you have? Post them below!
@PankajKumar-ky3ip
@PankajKumar-ky3ip Жыл бұрын
That was really a concise package of Fortigate security hardnening.. Your videos are really helpful for me.. Great work man.
@brandonhuggins1736
@brandonhuggins1736 2 жыл бұрын
Nice. I’m new to fortigate and this was great. Lead architect and customer will be happy with these simple hardening changes.
@battlement
@battlement 4 жыл бұрын
One tip that comes to mind is create and use geographical address objects. For example, if your company is based in the States, create a geo-usa address object and attach it to your incoming SSL-VPN connection policy so that only IP addresses from the geographical USA are allowed. This is also good for DMZ servers that should only be accessed from within a geographical region.
@FortinetGuru
@FortinetGuru 4 жыл бұрын
Absolutely. Wonderful tip
@DannyMaas
@DannyMaas 4 жыл бұрын
I have another tip for you: Change the self-signed certificate!!! Fortinet has the device serial number in it's certificate. If you have a partner-account with Fortinet, you'll be able to look up the status of it's support and licensing. If it expired 6 months ago, you'll have 6 months of zero-days the Fortinet-appliance will never detect. It's easy to do in 5 minutes. I used to give this to my students as an extra assignment if they had to wait for the rest of class to finish their other assignments. Better not to use the admin-port on the internet, but that's not always an option. Changing the certificate is.
@alejandroparrello6493
@alejandroparrello6493 Жыл бұрын
Hi Danny, could you explain how to do it? regards from Argentina 😉
@inevitable-joy
@inevitable-joy Ай бұрын
This doesn't make sense to me...
@ncasagrande1
@ncasagrande1 4 жыл бұрын
great info! i'm a sonicwall guy, but still watch all your videos as things such as this cross-over. luckily i was already doing everything you mentioned and constantly review my configs.
@FortinetGuru
@FortinetGuru 4 жыл бұрын
Awesome. I’ve been half tempted to make a channel about firewalls in general just to help educate and assist.
@lenders1164
@lenders1164 4 жыл бұрын
Excellent content as always Mike!
@FortinetGuru
@FortinetGuru 4 жыл бұрын
Thanks friend
@darkhsu
@darkhsu 4 жыл бұрын
The two built-in free FortiToken are very helpful.Thanks for the video.
@FortinetGuru
@FortinetGuru 4 жыл бұрын
No problem. Glad it was beneficial!
@DannyMaas
@DannyMaas 4 жыл бұрын
If you have more than 2 admins, just buy a few more. 5 extra tokens are only $300 list price (you'll get a discount). really cheap for tokens that never will expire.
@rockinron5113
@rockinron5113 Жыл бұрын
Nice one!
@izzywazzo8397
@izzywazzo8397 2 жыл бұрын
Love the videos Mike. You break the steps down into layman's terms and it's made understanding concepts much easier. In regard to port 541 for Fgm access, is there a way to restrict this to forticloud ips? I assume by editing local in policies via cli. Find it odd they would leave 541 unrestricted for the mgmt from forticloud
@RaviChinasamy
@RaviChinasamy 4 жыл бұрын
Great video!! Nice new improvements overall (tooltips) 👍
@FortinetGuru
@FortinetGuru 4 жыл бұрын
Thanks Ravi!
@jefflambert7513
@jefflambert7513 3 жыл бұрын
Good stuff...thanks !!
@amitpatil6178
@amitpatil6178 3 жыл бұрын
Nice bro
@keonedwards4619
@keonedwards4619 4 жыл бұрын
Great videos, will you do a troubleshooting video using the fortinet tools in the future? Like the packet capture, debug flow and packet sniffer... Others may not know how easy it is to troubleshoot from there own device.
@FortinetGuru
@FortinetGuru 4 жыл бұрын
Absolutely.
@HC19200
@HC19200 3 жыл бұрын
Good suggestion
@Vishalbhosekar659
@Vishalbhosekar659 Жыл бұрын
you are awesome
@FortinetGuru
@FortinetGuru Жыл бұрын
Much appreciated!
@slimgaus
@slimgaus 4 жыл бұрын
Great video Can you make a video about policy setup on fortinet when domain member PC is required in DMZ zone. How do you set it up and which traffic do you pass from DMZ ->INSIDE
@FortinetGuru
@FortinetGuru 4 жыл бұрын
Will add it to the list
@slimgaus
@slimgaus 4 жыл бұрын
Thanks Keep up the good work
@JoSmuckatelly
@JoSmuckatelly 3 жыл бұрын
I try to use Geolocation objects to scope access to 1) Internet facing websites (i.e. the ticketing system for a regional business doesn't need access from IP addresses sourced from Asia), 2) the remote access VPN, 3) HTTPS/SSH access if it must be available on the WAN interface. While an attacker could easily proxy through a US VPN to get around this, no sense in making it too easy for them.
@NateC556
@NateC556 Жыл бұрын
Is there a way to add an address object to trusted hosts? I have done this on other firewalls, Sonicwalls recently, and it makes it much easier for "future proofing"
@tomwaterloo
@tomwaterloo 2 жыл бұрын
Is it possible to configuring the maximum log in attempts and lockout period from the gui? 6.4.9 ?
@TheKamaladmire1
@TheKamaladmire1 2 жыл бұрын
Hi Guru, urgently need help. I have convert config from McAfee to fortifate used by forticonvertor however not able to export config. I don't have licence for forticonvertor. Is there another way to do it.
@Pniesiek
@Pniesiek 2 жыл бұрын
Hey, I have problem with fortigate... Its brand new and when I just add security profile to my policy whole company cant acces office 365 :( they have certificate error for office things. Pls help
@prashanthnayak6904
@prashanthnayak6904 3 жыл бұрын
hello... i need one help please..... i have 1 ill with 5 static ip's provided by isp... how do i utilize all the ips as redundant... 2nd question is if we have 2 different isp's then we want to use both the isp in sdwan / isp groupings with one single virtual ip as fail over(means ISP "A" goes down traffic should flow with ISP "B" with minimal disruption to link) please advice as i'm new to this form.. thank you
@FortinetGuru
@FortinetGuru 3 жыл бұрын
If you want the same IP space between multiple providers you are normally looking at BGP.
@Darkk6969
@Darkk6969 2 жыл бұрын
I generally don't delete admin or root accounts. If you can''t rename it give it a very long password and then disable the account. I always create a new admin account using a completely different name so hackers can't guess it. On Linux servers make sure root don't have the ability to log into ssh.
@FortinetGuru
@FortinetGuru 2 жыл бұрын
Some best practice standards / regulatory requirements (I hate saying that because best practice is dependent on the risk apatite of the organization) recommend or require the deletion or renaming of the default admin account.
@ovi6192
@ovi6192 2 жыл бұрын
(7:55) why not just rename admin in first place? why create new_account + use new_account and delete orig_admin?
@danbrisson8159
@danbrisson8159 4 жыл бұрын
How about setting up a VIP and port on the WAN interface for the LAN interface, then you can create a policy that allows specific IPs to hit the VIP ports for ssh and https access? Then you can disable all management protocols on the WAM interface. Thoughts?
@FortinetGuru
@FortinetGuru 4 жыл бұрын
I would rather use a hardened device (fortigate) vs punching a hole straight into the network and having to secure the policy AND the end device that is being used as a jump box. That’s just me though.
@danbrisson8159
@danbrisson8159 4 жыл бұрын
Fortinet Guru Sorry, I wasn’t clear. The VIP maps to the LAN address of the Fortigate. So in effect, from the Internet you are hitting the LAN mgmt interfaces directly, restricted by source IP using an IPv4 policy.
@FortinetGuru
@FortinetGuru 4 жыл бұрын
Oh, well in that case it is kinda redundant right? You could just use local in policy to whitelist who can talk on the outside interface and achieve the same thing without potentially providing internal access.
@danbrisson8159
@danbrisson8159 4 жыл бұрын
Fortinet Guru Local in, for sure. I just wish Fortinet made it easier to modify the Local in policy. Don’t get me wrong, I’m not afraid of cli, but man, this shouldn’t be that hard. By the way, thx for the great videos. I’m still draining my system of years of Cisco Pix/ASA.
@FortinetGuru
@FortinetGuru 4 жыл бұрын
No problem at all. I’m all for Cisco routers and switches. I despise ASAs though and the newer gear just ain’t up to Palo fortinet caliber.
@mdabdulmoiz
@mdabdulmoiz 3 жыл бұрын
I see 2 IP addresses that are hitting my firewall from outside that I want to block how will I do that?
@FortinetGuru
@FortinetGuru 3 жыл бұрын
You mean they are just hitting the outside address of the firewall? If that is the case you can just disable ping https http etc on the outside interface.
@mdabdulmoiz
@mdabdulmoiz 3 жыл бұрын
@@FortinetGuru yes, i see the brute force with those IP's, we also have admins accessing management on WAN and we cannot set trusted hosts, is there a way we could block access for such IP's and is there a way we could set IPS policy which could block or stop them?
@techlover1
@techlover1 3 жыл бұрын
@@mdabdulmoiz The best solution would be turn off external management and setup vpn for your admins
@mdabdulmoiz
@mdabdulmoiz 3 жыл бұрын
@@techlover1 what i did was added trusted hosts for mangement users, that solved the problem now i don't see random hits from WAN
@mitchellsmith4601
@mitchellsmith4601 3 жыл бұрын
I never administer using SSH or HTTPS, those are disabled. If I want to administer, I first connect via VPN.
@FortinetGuru
@FortinetGuru 3 жыл бұрын
You are using ssh or https, just via a different interface unless you are vpn connecting and using a serial console device.
@mitchellsmith4601
@mitchellsmith4601 3 жыл бұрын
@@FortinetGuru Not to be argumentative, but we use IPSec, not SSL.
@FortinetGuru
@FortinetGuru 3 жыл бұрын
I didn’t define which type of VPN. Also, not being argumentative. You are administering the box through some means you just have layers of security on top of it before you can hit that.
@cdfaulk
@cdfaulk 4 жыл бұрын
Obscurity is not security
Steps to Hardening FortiGate SSL VPN
20:38
Techy-World
Рет қаралды 654
FortiPAM Demo | Privileged Access Management
16:47
Fortinet
Рет қаралды 10 М.
I'm Excited To see If Kelly Can Meet This Challenge!
00:16
Mini Katana
Рет қаралды 31 МЛН
ТЫ С ДРУГОМ В ДЕТСТВЕ😂#shorts
01:00
BATEK_OFFICIAL
Рет қаралды 7 МЛН
لقد سرقت حلوى القطن بشكل خفي لأصنع مصاصة🤫😎
00:33
Cool Tool SHORTS Arabic
Рет қаралды 29 МЛН
FortiGate FortiOS 7.2.4 Walk Through
34:10
Fortinet Guru
Рет қаралды 18 М.
FortiGate to FortiGate IPSEC Configuration (FortiOS 6.4.0)
19:30
Fortinet Guru
Рет қаралды 53 М.
FortiGate Hardening Guide: Secure Your Network
9:40
IT Superhero
Рет қаралды 429
SSL Decryption On A FortiGate
13:47
Fortinet Guru
Рет қаралды 17 М.
Bruteforce protection - MikroTik firewall rules
5:35
MikroTik
Рет қаралды 29 М.
Transport Layer Security (TLS) - Computerphile
15:33
Computerphile
Рет қаралды 474 М.
My FortiGate SDWAN Configuration and Some Use Cases
16:25
Fortinet Guru
Рет қаралды 51 М.
I'm Excited To see If Kelly Can Meet This Challenge!
00:16
Mini Katana
Рет қаралды 31 МЛН