Ana içeriğe atla

Kayıtlar

Fortigate etiketine sahip yayınlar gösteriliyor

Fortigate Parallel Redundancy Protocol

Parallel Redundancy Protocol  (PRP) Endüstriyel Ethernet için standart ağ protokolüdür. EC 62439-3’te ifade edilen Parallel Redundancy Protocol, Ağın herhangi bir bileşeninin arızalarına karşı, Tek bir kesinti noktasından sorunsuz yük devretme sağlar. STP/RTSP'den daha verimlidir, 0 kesinti süresi avantajına sahiptir. PRP aşağıdaki cihazlarda desteklenir. Fortigate Rugged 30D, Fortigate Rugged 35D ve Fortigate Rugged 90D.  Güvenlik duvarlarının Redundancy algoritması olarak PRP ile bir ağa entegre edilmesine izin vermek için aşağıdaki özelliği etkinleştirmemiz gerekir. config system setting set keep-prp-trailer [enable/*disable] end Entegrasyon şeması

Fortigate RPF kontrolünü devre dışı bırakma

RPF (Reverse Path Forwarding) IP Spoofing saldırılarına karşı korur ve  Input Interface  üzerinden Source IP'ye geri dönen aktif bir Route olup olmadığını kontrol eder. RPF, aşağıdaki şekillerde yapılması mümkün olmasına rağmen , devre dışı bırakılması önerilmeyen bir güvenlik mekanizmasıdır  Asymmetric Routing'e  izin verdiğimizde, bu sistemde RPF'nin doğrulanmasını engeller ve Fortigate Statefull yerine Stateless Firewall'a dönüştürür. asymmetric routing  izin verme komutu aşağıdaki gibidir. config system setting set asymroute enable end Firmware 5.6 sürümünden itibaren, aşağıdaki komutlarla arayüz seviyesinde RPF kontrolünü devre dışı bırakabiliriz. config system interface edit <interface> set src-check disable end

Fortigate Dynamic Routing değişikliğinin aktif oturumları nasıl etkilediğini kontrol etme

Fortigate üzerinde traffic aktif iken Dynamic Routing değişiklikleri gerçekleşebilir. Bu değişiklikler aktif Session’lar tarafından kullanılan rotaları etkileyebilir ve bu nedenle “Dirty-Sessions” olarak adlandırılabilir. Dinamik bir rota değişikliği öncesinde bu Session’ların davranışını kontrol edebiliriz. Etkin oturumlar için Orjinal yönlendirmeyi tutmayı seçebilir veya yeni hedeflerden geçmek için rota tablosundaki değişiklikleri bu oturumlar üzerinde uygulayabiliriz. Aşağıdaki CLI komutunun varsayılan değeri (Enable) etkin oturumların dinamik yönlendirme değişikliklerinden etkilenmeden bitirilmesine izin verir. config system interface edit <interface_name> set preserve-session-route {enable | disable} next

Fortigate Geliştirilmiş DNS filtering performansı

Fortigate 6.0.3 versiyonu ile beraber, DNS Filtering engine performansını iyileştirdi. Önceki sürümlerde, Tüm DNS Filtering isteklerini işleme almaktan sorumlu tek bir işlem vardı, şimdi dört adede kadar DNS Proxy yapılandırabilirsiniz. Bu DNS Proxy işlemi, DNS Filtering Engine’den geçen DNS isteklerini işlemekten sorumludur. Default olarak tüm trafiği işlemekten sorumlu tek bir işlem vardır. Kapasiteyi arttırmak için aşağıdaki komutla yapılandırılabilir. config system global set dnsproxy-worker-count 4 end

Fortigate-FortiAnalyzer veya Local Logging ile iletişim Testi

Bazen Fortigate-FortiAnalyzer veya Fortigate'in kendi Local Logging arasındaki iletişimini kanıtlamak gerekebilir. CLI ile, Fortigate'de her bir işlevi için bir Log girdisi oluşturabileceğimiz bir komut var, Bu şekilde Traffic, Antivirüs, Ips, vb. için sahte bir girdi oluşturulacak ve böylece Logging işlemi sağlanabilir.  Komut diagnose log test 1 CLI çıktısı generating a system event message with level - warning generating an infected virus message with level - warning generating a blocked virus message with level - warning generating a URL block message with level - warning generating a DLP message with level - warning generating an IPS log message generating an anomaly log message generating an application control IM message with level - information generating an IPv6 application control IM message with level - information generating deep application control logs with level - information generating an antispam message with level - notification generating an allo...

Fortigate IPSEC tünelleri için Flush/Reset komutları

Engellenen (Blocked) SA oturumları nasıl silinir? Flush Tünel Bir tüneli temizlemek için aşağıdaki komutu kullanabiliriz diag vpn tunnel flush <PhaseName1> Reset Tunel Tüneli sıfırlamak da mümkündür, Bu durumda Fortigate IPSec VPN'i tamamen yeniden müzakere (renegotiate) eder. diag vpn tunnel reset <PhaseName1> Not: Fortigate'de Reset of ALL Tunnels işlemi yapılması durumunda, phase1 adını belirtmek çok önemlidir.

Fortigate Script çalıştırma

FortiOS içinde belirli durumlarda çok yararlı olabilecek belirli programlama  ile küçük script'leri çalıştırmak mümkündür. Komutların sözdizimi (Syntax) https://docs.fortinet.com adresinde açıklanmıştır ve bunların içinde belirli FortiOS komutlarını (Backups, Diagnostics, Configuration vb.) uygulayabiliriz. Ayrıca farklı amaçlar için de çok yararlı olabilirler (Backups, Restarting Processes, Equipment, Monitoring Commands, Traffic Generation vb.) config system auto-script edit "backup" set interval 1 set repeat 0 set start auto set script "execute backup config ftp backup.conf 1.1.1.1 test test " next end config system auto-script  edit "backupvdom"  set interval 120  set repeat 0  set start auto  set script "  config global  execute backup config ftp backup.conf 10.10.10.2 test test"   next  end config system auto-script  edit “reiniciaproceso”  set interval 43200  set repeat 356  set start auto  set s...

Fortigate One-Click VPN (OCVPN)

A new service known as "Cloud-Assisted One-Click VPN" (Cloud-Assisted One-Click VPN) has been introduced since version 6.0. OCVPN is a Cloud-based solution that greatly simplifies the provisioning and configuration of IPsec VPNs. The Administrator activates OCVPN with one click, adds the required Subnets, and then the configuration is complete. The OCVPN solution automatically updates each FortiGate, creates VPNs on registered computers, and the service is automatically changed using a dynamic IP even if one of the computers changes its WAN IP. The service has the following limitations Fortigate Firewall must have a valid FortiCare Support license. Only Full-mesh VPN configurations using PSK encryption are supported. Public IP addresses must be used (Fortigate cannot join behind a NAT router) Non-root VDOMs and FortiGate VMs are not supported. Up to 16 nodes can be added to the OCVPN cloud, each consisting of up to 16 subnets. You can find the details of the configuration...

Modify FortiGate HA Link-Failed-Signal and MAC address tables

The "Link-Fail-Signal" command allows us to force switches next to the Cluster Fortigate unit to refresh their MAC tables, which will be useful if the Switches do not refresh their MAC tables correctly. Normally, after Link Failover, the new Primary sends Gratuitous ARP (GARP) packets to refresh the MAC forwarding tables of the switches connected to the Cluster. In some cases, Switches ignore GARP packets and continue to reference the MAC address of the port. So the transaction fails on the Fortigate side and continues to send packets. You can use the following command to prevent a Cluster unit with Monitored Interface connection from turning off all interfaces (except Heartbeat Interfaces and HA Mgmt Interfaces) after Link Failure occurs. config system ha set link-failed-signal enable end If cluster computers are managed with a Mgmt interface, it must be specified, otherwise the port on which it is managed is Down. config system ha set link-failed-signal enable en...

FortiGate EDNS Support

Extension mechanisms for DNS (EDNS) is a feature that expands the size of various DNS protocol parameters with size restrictions when it comes to increased protocol functionality. The first set of extensions was published by the IETF as RFC 2671 (also known as EDNS0) in 1999. EDNS0 means a DNS UDP message length greater than 512 bytes. Some Firewalls may block such a message, assuming the maximum size of the DNS message is 512 bytes. Since FortiGate Version 5.2 it supports EDSN0 and DNS messages greater than 512 bytes in length.

Automation rules for Fortigate Conserve Mode and High CPU

In version 6.0, Automation rules were introduced that allow automation of a series of actions before certain events. An example of this is the possibility to quarantine when the device is detected to be compromised or to initiate a Log via API (Webhook) when a particular Event Log is created. There are two types of actuators (Triggers-triggers) that cannot be configured via the graphical interface, but that we can configure with the CLI, and we will see that the configuration made on the CLI side is then reflected in the GUI. These methods take effect when the CPU is at very high values or enters Conserve mode with high memory. To configure them, we will launch the following commands from the CLI. high cpu low-memory first config system automation-trigger edit "cpu" set event-type high-cpu next edit "memoria" set event-type low-memory next end Once the trigger is configured, we will create a new Automation rule and associate it with the trigger configured in the ...

Fortigate SSL mirroring explicit proxy/SSL inspected traffic

SSL inspection on Fortigate is a mechanism that can be used to protect and inspect the content of encrypted sessions, find and block threats. SSL inspection not only protects against attacks using HTTPS, but also against other commonly used encrypted protocols such as SMTPS, POP3S, IMAPS, and FTPS. A full SSL inspection (Deep Inspection) should be used to ensure that all encrypted content is inspected. When SSL inspection is used, Fortigate acts as the receiver of the source SSL session and decrypts and inspects its content, Then the content is encrypted again, a new SSL session is established between Fortigate and the receiver by impersonating the sender, and the content is freed from threats. It is possible to "Mirror" or send a copy of the traffic Decrypted by SSL inspection to one or more Fortigate interfaces so that the traffic can be collected by the Raw Packet Capture tool for archiving or analysis. Mirroring occurs after it is processed by the SSL Decoder and at the s...

Fortigate HA Sync troubleshooting

When there is a problem with HA (High Availability) synchronization, there is a command that can tell us which part of the configuration is not synchronized correctly. HA checksums are organized into sections and subsections. With the "diagnose sys ha checksum show" command, we can view the Hash values of the global Configuration and Root Vdom configuration. While running this command on Cluster Nodes, if we notice a difference in any of them, we can tell that something is out of sync. CLI diagnose sys ha checksum [global | root | all] [element name] For example, if we have seen different Hash or Checksums in the Global, we can verify that the items in the global are not synchronized by executing the command "diagnose sys ha checksum show global" on all Nodes. If we verify that the hash system.global differs between Nodes, we can continue to examine with the command "diagnose sys ha checksum show global system.global" , we can see the general settings...

Association between Fortigate NAT IPPool and SD-WAN

SD-WAN functionality enables Fortigate to choose the best Wan output to an application, perform other QoS and security applications. Also at the level of security policies it is very simple to manage because as the target interface it is only necessary to put “SD-WAN” which will contain all the WAN interfaces that make it up (for practical purposes it works like a Zone) It is common for these SD-WAN supported security policies to activate NAT output, and Fortigate gives us the option to exit with the IP of the exit interface or exit with an IPPool. However, if you don't associate each IPPool with an interface, connection errors will occur, as Fortigate will assign that IPPool without ordering. The way to solve this is to associate IPPools objects with a wan interface, this way, Fortigate knows which one to use at any given moment and for each WAN interface of SD-WAN. This Example will be done via the CLI. config firewall ippool edit "IPPOOL-WAN1" set startip 1.1.1.1 se...

Fortigate SD-WAN and snat-route-change parameter

It is recommended to enable the snat-route-change command in security policies where Source-Nat is implemented (common on Internet access and SD-WAN), because when enabled the routing information is deleted from the table. When SNAT is not valid for a session, it means that SD-WAN sessions can be 100% stabilized and redirected if an SD-WAN rule is changed  without waiting for the session to expire. (for example, by increasing the latency on one of the SD-WAN lines)  With this configuration disabled (by default) after a routing change, sessions created with SNAT will continue to use the same exit interface, provided the previous route is still active or has expired (although the route is no longer optimal) config system global set snat-route-change enable end

Troubleshoot Fortigate SSL VPN

You can use the diagnose commands below to identify SSL VPN problems. diagnose debug application sslvpn -1 This command will enable the debug level of SSL VPN with debug level -1. Debug level -1 gives detailed results. Verify the debug configuration diagnose debug info debug output: disable console timestamp: disable console no user log message: disable sslvpn debug level: -1 (0xffffffff) CLI debug level: 3 This output verifies that SSL VPN debugging is enabled at debug level -1 and shows which filters are in place. The above output shows that debug output is disabled, so debug messages are not displayed. The output also indicates that debugging is not enabled for any software system. Use the following command to enable the display of Debug Messages. diagnose debug enable To view the debug messages, login to the SSL VPN portal and the CLI displays debug output similar to the one below. FGT90E3G10002814 # [282:root]SSL state:before/accept initialization (172.20.130.12) [282:root]SSL sta...

Fortigate Route ve Spoofing–Reverse path check

The AntiSpoofing mechanism (reverse path check or reverse path forward) in Fortigate allows you to check that the properties of a packet in other paths are received at one level in the correct interface. It includes mechanisms to prevent IP Spoofing attacks that involve changing the source IP address of a packet that the Fortigate firewall receives from one of the interfaces that the source IP address would not expect. reverse path forward <span style="text-decoration: underline;">Interfaces :</span>   LAN : 192.168.1.254/24 DMZ : 192.168.2.254/24   <span style="text-decoration: underline;">Routage statique en place :</span>   Route : 192.168.100.0/24 gw 192.168.1.254 Route : 0.0.0.0 gw defaut wan gateway This protection mechanism ensures that a packet with the source 192.168.100.0/24 cannot be reached by the LAN interface. The only interface authorized to receive the Flows of this network is the DMZ (see the routing). If a pac...