From: Turritopsis Dohrnii Teo En Ming <tdtemccnp@gmail.com>
To: netdev@vger.kernel.org
Cc: ceo@teo-en-ming-corp.com
Subject: Fortigate Firewall Setup SOP Draft 13 Mar 2023
Date: Mon, 13 Mar 2023 21:40:57 +0800 [thread overview]
Message-ID: <CAD3upLsLPF3nYdD1HHhqiweXt8zzOLKWpdPwuUKrccc1x33XBQ@mail.gmail.com> (raw)
Subject: Fortigate Firewall Setup SOP Draft 13 Mar 2023
Collated by: Mr. Turritopsis Dohrnii Teo En Ming
Country: Singapore
Date: 13 Mar 2023 Monday
Time: 9:21 PM GMT+8 Singapore
01. Register the brand new Fortigate firewall at https://support.fortinet.com
02. Key in the Contract Registration Code. This is very important.
03. Upgrade firewall firmware to the latest version.
04. Set hostname.
XXX-FWXX
05. Set regional date/time. Time zone is important.
06. Enable admin disclaimer page.
config system global
set pre-login-banner enable
07. Create firewall super-admin accounts.
a. admin
b. xx-admin
c. si-company
d. abctech
08. Configure WAN1 interface.
Most business broadband plans are using DHCP.
09. Enable FTM / SNMP / SSH / HTTPS for WAN1 interface.
10. Configure default static route.
11. Configure LAN interface.
Optional: DHCP Server
12. Set DHCP lease time to 14400.
13. Configure HTTPS port for firewall web admin to 64444.
14. Configure SSL port for VPN to 443.
15. Configure LDAP Server.
16. Create Address Objects.
17. Create Address Groups.
18. Configure firewall policies for LAN to WAN (outgoing internet access).
19. Configure and apply security profiles to above firewall policies.
20. Create Virtual IPs.
21. Create custom services.
22. Create service groups.
23. Create firewall policies for port forwarding (WAN to LAN).
24. Configure other firewall policies.
25. Disable FortiCloud auto-join.
config system fortiguard
set auto-join-forticloud disable
end
26. Configure FTM Push.
config system ftm-push
set server-port 4433
set server x.x.x.x (WAN1 public address)
set status enable
27. Remove existing firewall/router and connect brand new Fortigate
firewall to the internet.
28. Configure FortiGuard DDNS.
xxx-fw.fortiddns.com
29. Configure DNS.
30. Activate FortiToken.
31. Create SSL VPN Group.
32. Create SSL VPN Users (local or LDAP).
33. Configure 2FA for SSL VPN Users.
34. Create SSL-VPN Portals.
35. Configure SSL VPN Settings (split or full tunneling).
36. Configure firewall policies for SSL VPN to LAN.
Optionally configure firewall policies for SSL VPN to WAN (if full tunneling).
37. Configure C-NetMOS Network Monitoring Service.
configure log syslogd setting
set status enable
set server "a.b.c.d"
set mode legacy-reliable
set port 601
set facility auth
end
38. Apply hardening steps (Systems Integrator's Internal Document).
39. Convert SOHO wireless router to access point mode.
40. Configure and apply security profiles (REMINDER).
Testing
=======
1. Internet access for all users.
2. VPN connection using FortiToken.
Documentation
==============
Firewall documentation for administrator (settings / policies / VPN).
User Training
==============
A. For Administrator
====================
1. How to access Fortigate firewall URL.
2. How to add/remove/reassign FortiToken.
3. How to add/remove VPN users.
4. How to generate usage report for Government PSG Grant.
B. For End User
================
1. How to connect to VPN.
2. How to use FortiToken.
3. How to connect company laptop to VPN.
===EOF===
REFERENCES
===========
[1] https://pastebin.com/raw/yg0QUcv6
[2] https://controlc.com/85e667fb
next reply other threads:[~2023-03-13 13:41 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-03-13 13:40 Turritopsis Dohrnii Teo En Ming [this message]
2023-06-06 14:03 ` Fortigate Firewall Setup SOP Draft 13 Mar 2023 Bagas Sanjaya
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=CAD3upLsLPF3nYdD1HHhqiweXt8zzOLKWpdPwuUKrccc1x33XBQ@mail.gmail.com \
--to=tdtemccnp@gmail.com \
--cc=ceo@teo-en-ming-corp.com \
--cc=netdev@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).