FortiGate SSL VPN Realms
39:52
10 ай бұрын
FortiGate SSL VPN for Remote Users
48:59
FortiGate HA Setup
33:55
Жыл бұрын
FortiGate Firmware upgrade methods
11:08
Пікірлер
@mayarmalongmajokamaach5853
@mayarmalongmajokamaach5853 5 күн бұрын
very good video Sir.
@jonathanwinnick1909
@jonathanwinnick1909 6 күн бұрын
how were you able to delete the port 3? it seems to be complicated in Fortigates.
@techy-world3716
@techy-world3716 6 күн бұрын
The Fortigate firewall was deployed on a VM, and it is easy to remove the interfaces on the VM.
@jonathanwinnick1909
@jonathanwinnick1909 6 күн бұрын
@@techy-world3716 i saw, sorry i didnt watch far enough, your video is very good and well explained, thank for for the quality content!
@jonathanwinnick1909
@jonathanwinnick1909 6 күн бұрын
@@techy-world3716 one more quick question, when i tried to move the ip scheme i had on the physical port 2 "10.0.0.1/24" to the VLAN (VLAN 10) the VM is saying "conflicts with "port2" Subnet" do you know why it would say that when i try to move the ip address to the vlan when the physical port , port 2 doesn't have an ip anymore (0.0.0.0/0) ?
@techy-world3716
@techy-world3716 6 күн бұрын
@@jonathanwinnick1909 Change the IP on port 2 to something else like 192.168.10.1/24, then move the 10.0.0.1/24 to the VLAN.
@jonathanwinnick1909
@jonathanwinnick1909 6 күн бұрын
@@techy-world3716 so basically the physical port needs to have an IP no matter what?
@victorjames6242
@victorjames6242 14 күн бұрын
Thank you for sharing. what is the possibility of using both links at the same time. or combining both links to increase the bandwidth size
@techy-world3716
@techy-world3716 14 күн бұрын
@victorjames6242 You can balance the traffic across both link, you can select both outgoing interface as your interface preferences. The short answer is YES you can use both link simultaneously
@myself-tp2my
@myself-tp2my 14 күн бұрын
best practice is to change the FGT management port also, not just the SSLVPN. Also hotels, motels and other such sites will probably block SSLVPN on a port other than 443.
@techy-world3716
@techy-world3716 6 күн бұрын
You are absolutely correct about hotels and motels blocking port 443. I recommend people use their own personal Hotspot if possible. Public WiFi is not the best.
@myself-tp2my
@myself-tp2my 6 күн бұрын
@@techy-world3716 I have seen here that cell hotspots also block non typical ports so 443 is also the best there
@narfnn2111
@narfnn2111 15 күн бұрын
tks a loot !!!!
@vicentegonzales369
@vicentegonzales369 22 күн бұрын
HI what is the default gateway of the Winserver 2016 ? plase it is 192.168.177.3? or 192.168.177.1/24 and what happen if i put the server behind the Fortiwe which will be the default gateway?
@AlwaysbeingLu
@AlwaysbeingLu 27 күн бұрын
thanks for this man.
@AlcidesFerreira2024
@AlcidesFerreira2024 Ай бұрын
No need to setup smtp server and port first in settings?
@techy-world3716
@techy-world3716 Ай бұрын
Yes, there is no need to setup smtp server and port.
@AlcidesFerreira2024
@AlcidesFerreira2024 Ай бұрын
@@techy-world3716 Thanks
@AlcidesFerreira2024
@AlcidesFerreira2024 Ай бұрын
@@techy-world3716 But if I have my smtp server in cloud or local, how to specify?
@adrianmisischia1953
@adrianmisischia1953 Ай бұрын
tkns
@maurofadda289
@maurofadda289 Ай бұрын
the LAN 2 network is basically the management,right?Great video
@techy-world3716
@techy-world3716 Ай бұрын
LAN 2 network has some management features, such as HTTPS or FMG. Once any of the Administrative Access is enabled on that interface that makes it a management interface.
@abdullahkuspnar5312
@abdullahkuspnar5312 Ай бұрын
First of all, thank you for a very useful video. But how can you access GUI interfaces from your own Windows Machine by saying 192.168.177.3 or 192.168.177.1? There must be a setting here. In addition, how is it that you can ping 192.168.177.54 ip address from your own machine again? I think there is a configuration here that we have not seen in the previous video before?
@techy-world3716
@techy-world3716 Ай бұрын
Please watch the Part I of this Video kzfaq.info/get/bejne/l7R4fLSV3L7Gkac.htmlsi=0OUvlJpzNP0zxui3
@disconnected58
@disconnected58 2 ай бұрын
Hello, help, the token code does not arrive in my Gmail inbox, my question is if something additional has to be done in Gmail so that it receives the Fortigate token messages
@techy-world3716
@techy-world3716 Ай бұрын
Check your SPAM inbox, FortiToken can be sent into your GMAIL inbox without issue.
@zinenhleDhludhlu-bf7ez
@zinenhleDhludhlu-bf7ez 2 ай бұрын
Very informative , I've just solve my ticket with this knowledge , thank you
@livestronger1981
@livestronger1981 2 ай бұрын
Oh cool. What program did you use to draw the Topology?
@techy-world3716
@techy-world3716 2 ай бұрын
GNS3 is the application used to draw the topology
@livestronger1981
@livestronger1981 2 ай бұрын
I have a questions. Is there a difference between enabling NAT on the Policy? What does it do?
@techy-world3716
@techy-world3716 2 ай бұрын
When NAT is enabled on a policy you are stating that you need the private IP translated to the public and vice versa. This is mostly used when you intend for that policy to go to the internet. If the traffic is going to the LAN or VLANs only there is no need to enabled the NAT option on the policy.
@livestronger1981
@livestronger1981 2 ай бұрын
This is great. The only improvement I see is to setup the actual outgoing Destination in the Firewall policy rather then just selecting "ALL". This is a best practice so that the SDwan service is only dedicated to that one remote network. If you have two or 3 then maybe selecting ALL makes more sense. Right?
@techy-world3716
@techy-world3716 2 ай бұрын
I am not too sure I fully understand your point. Here is a pointer, if the traffic is destined for the internet selecting all as the destination is best since you don't want to create different policy for traffic going to teams, zoom, Facebook, outlook etc. But if you the destination is local, then selecting a single remote network is best practices.
@yvesneptune
@yvesneptune 2 ай бұрын
Can I configure IP addresses on both the physical interface and VLAN interface as router on a stick. And reach the physical interface on a switch that has a port in Access mode???
@techy-world3716
@techy-world3716 2 ай бұрын
The answer is Yes. You can configure multiple physical and Virtual interfaces and even route between them. What you need is policy. To answer your question YES it is possible
@nshutifreddy9279
@nshutifreddy9279 2 ай бұрын
Thanks man! it was helpful
@1990punit
@1990punit 2 ай бұрын
Amazing video, thank you for the explanation. Would you please create a video on how to setup True Transparent Proxy mode?
@techy-world3716
@techy-world3716 2 ай бұрын
Great suggestion!
@andrenelson8188
@andrenelson8188 2 ай бұрын
Great video. Thanks man
@techy-world3716
@techy-world3716 2 ай бұрын
Glad you liked it!
@nocsoc
@nocsoc 2 ай бұрын
Hi can i add multiple public ip to fortigate interface in GCP. So that i can bind them with different Internal IP in VIP.
@techy-world3716
@techy-world3716 2 ай бұрын
Yes the fortigate can use multiple public IP
@fahrul439
@fahrul439 2 ай бұрын
sometime i'm having problem cannot connect to the vpn after received token code "Credential or SSLVPN configuration is wrong.(-7200)" any advise?
@techy-world3716
@techy-world3716 2 ай бұрын
Try input the token faster. If you get the token via email it may sometime be delayed. Try to see if you get it faster on mobile phone or on desktop app.
@Wholnir
@Wholnir 2 ай бұрын
How did you configurate ISP 1 and 2? Because I have 2 clouds connected to the same bridge adapter and in order to give internet access to both Firewalls I need to configure both with the same static route.
@techy-world3716
@techy-world3716 2 ай бұрын
This article will help on how to configure ISP1 and ISP2 docs.gns3.com/docs/using-gns3/advanced/connect-gns3-internet/
@Wholnir
@Wholnir 2 ай бұрын
@@techy-world3716 I manage to have internet with one cloud using NAT and the other with a bridge adapter, so both have different IP's and static routes. The problem right now It's that the phase 1 is down and the troubleshooting of fortigate are not very helpfull.
@vishnuk9523
@vishnuk9523 2 ай бұрын
My eve-ng lab FortiGate vm firewall limit with 3 interface. It says trail vm license support 3 interface. How to use more interface.
@mitchellsmith4601
@mitchellsmith4601 2 ай бұрын
I didn’t know you could set SMS for two-factor. Not great, but better than nothing.
@mrcraigaddison
@mrcraigaddison 3 ай бұрын
Hi, is it possible to use a different alternative SSL certificate for each realm?
@techy-world3716
@techy-world3716 2 ай бұрын
It maybe possible, I haven't had reason to use that myself. This article might help. docs.fortinet.com/document/fortigate/7.4.3/administration-guide/724772/ssl-vpn-multi-realm
@MiladMantashi
@MiladMantashi 3 ай бұрын
thanks bro
@antoniocintora1157
@antoniocintora1157 4 ай бұрын
Nice tutorials! Foreach public facing service do I need to have a public IP? Or it can be redirected in any way directly from de FortiGate?
@techy-world3716
@techy-world3716 4 ай бұрын
No, you don't need a single public for each services, you could have multiple services on a single public IP
@antoniocintora1157
@antoniocintora1157 4 ай бұрын
@@techy-world3716 When I try to create a second policy i always get the error "The same service port cannot be used for one Virtual IP twice." and I'm stuck with it :(
@mayankbisht3385
@mayankbisht3385 4 ай бұрын
i didn't know that we can add email address under the user from the CLI. That's new to me. Thanks
@mayankbisht3385
@mayankbisht3385 4 ай бұрын
Thanks for your video, this was very helpful.
@techy-world3716
@techy-world3716 2 ай бұрын
Glad it was helpful!
@aushunter.82
@aushunter.82 5 ай бұрын
Hi @Tech-World, Thanks for this video. It was really helpful.
@Danielcoouto
@Danielcoouto 5 ай бұрын
Do you intend to take a course or publish a download link for this entire laboratory? that would be very useful
@techy-world3716
@techy-world3716 5 ай бұрын
I will consider that
@Brunojlm
@Brunojlm 6 ай бұрын
Awesome! Thank you for the video!
@techy-world3716
@techy-world3716 6 ай бұрын
Am happy it was helpful
@manoranjanmahanta1563
@manoranjanmahanta1563 6 ай бұрын
After doing this i am not able to access the firewall from lan zone. So how to get access it.
@techy-world3716
@techy-world3716 6 ай бұрын
The access will be applied to the LAN interface e.g port 1 if you are using physical port or the VLAN interface e.g Data VLAN. You can also apply it to multiple interface but not on the zone.
@manoranjanmahanta1563
@manoranjanmahanta1563 6 ай бұрын
Yes, I have created a data vlan 10 under port 1 and i am trying to access it from vlan 10 interface also https is enabled on that interface.
@techy-world3716
@techy-world3716 6 ай бұрын
Have you lost all access to the device or can you get in via console or ssh?
@techy-world3716
@techy-world3716 6 ай бұрын
The device you are accessing it from must be in VLAN 10 subnet as well. That is very important
@techy-world3716
@techy-world3716 6 ай бұрын
If you are still having issue, I can look at in over a remote session if you want.
@azeem20090
@azeem20090 6 ай бұрын
is there any need to have policy between one vlan in firewall?
@techy-world3716
@techy-world3716 6 ай бұрын
No there is no need to have policy between VLAN but there are reasons to why you may want someone to have access to a specific VLAN other than where they belong. For example if you have a Camera VLAN and you belong to Data VLAN you won't be able to view the camera from your network device in Data VLAN without having a policy to allow your device or the entire Data VLAN. I hope this helps
@chandanchauhan406
@chandanchauhan406 6 ай бұрын
Hello with this fortigate firewall deployment in VMware if we want to block any of the social sites on our home network does it will work or not plz reply
@techy-world3716
@techy-world3716 6 ай бұрын
Yes, it works perfectly. You have same functionality as what comes from a box. The VM version is very similar to the hardware.
@chandanchauhan406
@chandanchauhan406 6 ай бұрын
@@techy-world3716 thankyou so much But I have missed 1 questions which I have not mentioned if I don't have VMware hardware but I have installed VMware software in our computer does it work ? Plz reply
@techy-world3716
@techy-world3716 6 ай бұрын
It will work on your VMware without any problem.
@chandanchauhan406
@chandanchauhan406 6 ай бұрын
​@@techy-world3716thankyou so much for helping us😊
@bayusangkaya5525
@bayusangkaya5525 6 ай бұрын
Thank you for this playlist, really help me to understand FG and FWB appliances. I have one question, can I set a transparent mode Fortiweb on this FWB VM?
@techy-world3716
@techy-world3716 6 ай бұрын
Yes, the VM version has transparent mode. The VM version has 4 modes: Reverse Proxy Mode, Offline Protection Mode, True Transparent Proxy Mode and Transparent Inspection mode
@user-im8zm8oe6j
@user-im8zm8oe6j 7 ай бұрын
Great work, please prepare a complete fortiweb configuration tutorial
@techy-world3716
@techy-world3716 7 ай бұрын
I will work on that soon. Watch out for new videos
@user-mh1gs8gp7i
@user-mh1gs8gp7i 8 ай бұрын
Fantastic! Thanks so much. I have a question, If I use a real ip of server Is it a problem?
@techy-world3716
@techy-world3716 8 ай бұрын
No!, using the server's real IP address shouldn't be an issue, but following the steps in this video is recommended.
@mostofakalam3994
@mostofakalam3994 8 ай бұрын
Very insightful. When the part 4 coming along? Can you please cover how to configure FortiWeb for multiple server hosting public-facing services?
@techy-world3716
@techy-world3716 8 ай бұрын
Very soon, I will be making that video
@Nicolasjelincic1520
@Nicolasjelincic1520 9 ай бұрын
Very good video and deployment. We are waiting to see this solution with load balancer sandwich!
@Nicolasjelincic1520
@Nicolasjelincic1520 9 ай бұрын
Good video!!!
@tamoorali9065
@tamoorali9065 9 ай бұрын
where is the live testing you did not connect anything and test anything or live anything
@techy-world3716
@techy-world3716 6 ай бұрын
Point taken, I will ensure that I show more testing in my next videos. But be assured that these steps are what is required on the FortiGate.
@antoniocamacho3931
@antoniocamacho3931 9 ай бұрын
Great video!
@mohamedeladl6273
@mohamedeladl6273 9 ай бұрын
how the internal networks reached to each others while no routing between them??
@techy-world3716
@techy-world3716 9 ай бұрын
Internal network can reach each other using the layer 2 switch, it doesn't get to the firewall. Once the data frame is sent to the switch the switch will forward the data frame to the other device using the MAC address table.
@rage2k6
@rage2k6 9 ай бұрын
Great video. I'm New with Fortinet and in my new job I have to manage several branch offices with Forti 40F. today I performed the firmware upgrade from 7.2.2 to 7.2.4 and lost the HA sync (out of sync). so, with the diag sys ha checksum recalculate command it should bring back up the HA? I already check the checksum and is different in both the FW. Thanks in advance. Regards
@techy-world3716
@techy-world3716 9 ай бұрын
Yes that should fix it, but ensure that the firmware is same on both device. The most common issue is when there is a different configuration on the firewall that is not configured on the other that will cause the out-of-sync issue not to be resolved.
@rage2k6
@rage2k6 9 ай бұрын
@@techy-world3716 thanks. Righ now the secundary is with the 7.2.4 and the primary with the 7.2.2. Should I upgrade the primary first? Regards
@techy-world3716
@techy-world3716 9 ай бұрын
As long as both of them are on same version you should be fine, it doesn't matter which is upgrade first. But I will upgrade the lower version first to match the higher version. Either way it should work once they are on same version.
@piotrkotowski1361
@piotrkotowski1361 9 ай бұрын
I'm doing the same steps at Cisco Firepower 1010 Threat Defense (FTD) using Firepower Device Manager (FDM) but I'm having the same type of errors. This is the 1st one: "Blacklisted cli error: clear dhcpd binding all". Any ideas?
@2010blankspace
@2010blankspace 9 ай бұрын
I like your videos and I need a mentor to configure the FortiGate/nse4 part (if you have any other contact, I would appreciate it if you share ). I am already using GNS3 to learn.
@techy-world3716
@techy-world3716 9 ай бұрын
Am glad you love them, I can be of help with your NSE4. Here is my email [email protected]
@glenntembo2693
@glenntembo2693 9 ай бұрын
Thanks buddy