- Видео 29
- Просмотров 132 598
Techy-World
США
Добавлен 25 сен 2022
My goal with Techy-World is to share my IT knowledge, experience, passion, and stay up to date with current IT technologies. Techy-World aims to help people with no IT background gain basic to advanced IT experience by showing the things needed to secure an IT position with little or no experience.
Setting Up Email Alerts with FortiGate Automation: A Step-by-Step Guide
FortiGate Automation Stitch, creating email notification using GMAIL SMTP server settings.
Просмотров: 1 062
Видео
FortiGate GMAIL Email Notification
Просмотров 1873 месяца назад
This video will show you how to receive email notification on your FortiGate firewall using GMAIL SMTP
How to remove interface for FortiGate VM trial version
Просмотров 524 месяца назад
How to remove interface for FortiGate VM trial version
How to remove Interface for FortiGate VM trial version
Просмотров 884 месяца назад
How to remove interface on FortiGate VM on EXSi Host John Stockton Slow Drag by Chris Zabriskie is licensed under a Creative Commons Attribution 4.0 license. creativecommons.org/licenses/by/4.0/
SSLVPN replaced by FortiGate with IPsec VPN
Просмотров 2,2 тыс.4 месяца назад
After upgrading to version 7.6.0, SSLVPN has been removed and remote users have lost VPN access. Here's how to resolve this issue: Fortinet has replaced SSLVPN with IPsec VPN in this version. In this video, I'll guide you through configuring both FortiGate and FortiClient VPN to restore remote access.
Creating A Secure Ipsec Vpn Tunnel With Cradlepoint And Fortigate
Просмотров 7806 месяцев назад
IPSec VPN tunnel between a Cradlepoint and a FortiGate firewall.
Steps to Hardening FortiGate SSL VPN
Просмотров 1,7 тыс.11 месяцев назад
This video go over the steps to Hardening FortiGate SSL VPN 1. Changing default ports or popular ports 2. Using MFA for Local user account 3. Limiting access to specific geography 4. Limit concurrent connection 5. Create NoAccess Portal 6. Block access to/from Tor Exit Node and Relays
FortiGate Mobile FortiToken Two Factor Authentication
Просмотров 601Год назад
FortiGate Mobile FortiToken Two Factor Authentication
FortiGate Mobile FortiToken Two-Factor Authentication
Просмотров 189Год назад
How to Setup FortiGate Mobile FortiToken Two-Factor Authentication
FortiGate email based Two Factor Authentication
Просмотров 6 тыс.Год назад
How to setup email two factor authentication on FortiGate firewall.
Getting Started with FortiGate HA Setup on GCP using SDN Connector Everything You Need to Know
Просмотров 1,5 тыс.Год назад
Getting Started with FortiGate HA Setup on GCP using SDN-Connector. In this comprehensive guide, we will walk you through everything you need to know to set up High Availability (HA) with FortiGate on Google Cloud Platform (GCP) using SDN-Connector. High Availability ensures your network is always up and running, even in the face of hardware or software failures. We'll cover the essential conce...
FortiGate on GCP Tutorial A Beginner's Guide to Securing Your Cloud Infrastructure
Просмотров 748Год назад
Learn How to Secure Your Cloud Infrastructure with FortiGate on Google Cloud Platform (GCP)! Welcome to this educational tutorial that will provide you with a comprehensive beginner's guide on securing your cloud infrastructure using FortiGate on GCP. Whether you're an individual looking to enhance your cloud security skills or a business owner wanting to protect valuable data, this tutorial is...
FortiGate SSL VPN Realms
Просмотров 1,2 тыс.Год назад
How To Securely Connect To Your Office Network From Anywhere - Fortigate SSL VPN
FortiGate SSL VPN for Remote Users
Просмотров 763Год назад
How To Securely Connect To Your Office Network From Anywhere - Fortigate SSL VPN
Publishing HTTPS Web App using FortiWeb Part III
Просмотров 4 тыс.Год назад
Publish HTTPS Web Application using FortiWeb. FortiWeb Web Application Firewall.
Installing IIS & Publishing Web Servers on FortiWeb - Part II
Просмотров 3,7 тыс.Год назад
Installing IIS & Publishing Web Servers on FortiWeb - Part II
Installing FortiGate & FortiWeb - Part I
Просмотров 7 тыс.Год назад
Installing FortiGate & FortiWeb - Part I
Configuring ISP failover using SD WAN
Просмотров 8 тыс.Год назад
Configuring ISP failover using SD WAN
Cisco Firepower 1120 DHCP Reservation
Просмотров 1,4 тыс.Год назад
Cisco Firepower 1120 DHCP Reservation
How to Configure Fortigate Site-to-Site VPN on gns3
Просмотров 11 тыс.Год назад
How to Configure Fortigate Site-to-Site VPN on gns3
Configuring VLAN and Inter-vlan routing on Fortigate firewall
Просмотров 40 тыс.Год назад
Configuring VLAN and Inter-vlan routing on Fortigate firewall
Installing FortiGate Firewall on ESXi Host from Scratch for Home Network
Просмотров 9 тыс.Год назад
Installing FortiGate Firewall on ESXi Host from Scratch for Home Network
FortiGate HA out of sync troubleshooting
Просмотров 13 тыс.2 года назад
FortiGate HA out of sync troubleshooting
Home Assistant Text-to-Speech TTS using Random messages using Alexa
Просмотров 1,4 тыс.2 года назад
Home Assistant Text-to-Speech TTS using Random messages using Alexa
Debian and Home Assistant Supervised Installation
Просмотров 3,1 тыс.2 года назад
Debian and Home Assistant Supervised Installation
HOW TO INSTALL HOME ASSISTANT SUPERVISED - OFFICIALLY
Просмотров 7 тыс.2 года назад
HOW TO INSTALL HOME ASSISTANT SUPERVISED - OFFICIALLY
How to install pfsense on ESXi Host
Просмотров 2,3 тыс.2 года назад
How to install pfsense on ESXi Host
Please make a route based video, VTI.
Thanks 🙏❤
Why you gave the sdn route? if i deploy fortigate with external ip at ExterneL nic and mgmt nic, will i be able to get acces via both ip? i am able to get access with externl subnet public ip but not with mgmt subnet public ip?
@castle4757 a VIP should help you get into your management IP from outside your network, but your should be able to access your management interface on the same subnet. You can also add a policy to enable you do that
@techy-world3716 I have created ingress and egress rule for mgmt subnet at Gcp allowing everything. Are u saying I need to configure a vip on Fortigate to get access from management external ip?
Thank you so much for this video :)
Thank you sir vey nice
Hey! Did you have to create two vSwitches one for Wan and one For your Lan?
Really amazing video, what if i need to remove the 2FA by email after enabled ? What is the cli command?
the same command but with "disable" option
Great video!! thanks!!
love your video my vpn works however i got one problem i can seems to aacess an erp system via the vpn any clue why?
@@jacobkuma924 Go to SSL VPN Portal and disable Split Tunneling if you want to use Full Tunnel. If you want to use Split Tunneling, ensure that you define the ERP subnet inside the routing address under the Split Tunnel options in your SSL VPN Portal
It's done but still
@@jacobkuma924 Question: Are you using full tunnel or Split Tunneling?
@@techy-world3716 full tunnel
Please make sure you have a firewall policy to route your traffic from SSLVPN to your ERP subnets
Thank you! Is there a way to use azure ad connect, as it is possible with ssl vpn?
Absolutely you can you SAML SSO
@@techy-world3716 Can you make a video on how to connect IPSEC to MFA 365 (saml sso)
great video thanks :)
This help me a lot. Im doing a lab with fortiAnalyzer and fortigate in the fortiAnalyzer this work good, but in the fortigate doesnt seems to work. But thanks for the video. Keep going!
Great works! Thanks. I looked at good guide how to enable ipsec for end users and your video is clear and smooth.
Thanks ❤. This worked
Great!
Precious! Thanks!
THANK YOU!
Very good
Hi. Thank you for video. I am not able to make ito work yet but there are the concept. I keep trying on my 60F ando managed Zyxel switch...
@@xlv600tr Tell me exactly where you need support. I can give you some pointers
@@techy-world3716 thank you so much! I made 2 VLAN on FortiGate 60F (VLAN 10 and VLAN 25) using a a Zyxel GS1900 managed switch in testing enviroment. If I configure clients with fixed IP it works, but they aren't able to get IP from DHCP server ( configured on eachFortigate vlan, 192.168.10.1/24 and 192.168.25.1/24). I don't understand if the problem is the switch that is stopping DHCP service or if there is other configuration to do on firewall.
@xlv600tr If you scroll down on your VLAN 10 and VLAN 20 interfaces there, you will see the option to enable DHCP. The DHCP can be configured on your firewall, or you can configure it on your Zyxel GS1900 switch. If DHCP is configured on your switch, you will need to enable DHCP relay under the advance option below the DHCP on the fortigate 60F firewall.
@@techy-world3716 Thank you again. In switch menu I find only if switch receive ip from dhcp or if it has to fixed (for management). On fw it is active on both VLANS
why do this path traversal attack blocking mechanism works while you do not have any active licenses?
Can you add a new ISP to wAN2, while users are currently using WAN1 for internet access ? Will active users notice anything, if I create a SDWAN while they are using WAN1 ? WAN2 is new and nobody is using it yet.
@@619Hiker You can add a new ISP to WAN 2 without losing WAN internet access. As long as the Administrative Distance on WAN 1 is not higher than WAN 2. It should continue to work
Thanks you for valuable support
It's my pleasure
my check sums are different if i run the command the it will re sync ? i need to confirm because it is my production environment
Yes it show resync
@@techy-world3716 hello sir, i have some technical questions about this ? could you able to help me ?
Please like and share this videos to encourage more training videos. Thanks
Please like and share this videos to encourage more training videos. Thanks
Please like and share this videos to encourage more training videos. Thanks
Please like, Share this videos to encourage more training videos. Thanks
Please like, Share this videos to encourage more training videos. Thanks
Please like, Share this videos to encourage more training videos. Thanks
Please like, Share this videos to encourage more training videos. Thanks
Maximum number of entries has been reached. Object set operator error, -4 discard the setting. This error comming,plz support
This error is due to a trial license you are using which only allow 4 interfaces. What you can do is to use 2 interface (1 for WAN and the other for LAN which will include VLAN sub interfaces)
This video will show you how to remove interfaces ruclips.net/video/jCJLwmfP0uM/видео.html
Sir I am unable to sub interface
Watch between 2mins - 5mins of this video that shows how to create VLAN which is the sub interfaces you are trying to create
Iam unable to create sub interface in fortigate firewall, below error is coming Maximum number of entries has been reached. Object set operator error, -4 discard the setting.
@@psksuresh8800 Delete 2 of your physical interfaces. You are using a trial license. You will be allowed 4 interfaces on a trial version. So best is to delete 2 physical interfaces and use 1 for WAN and the other interfaces for your sub interfaces
Sir, how to delete interface port3
Kindly support sir,we suffer last two weeks for this issue
Very good, Is there any configuration for beginners?
I recommend you watch this video ruclips.net/video/ac1L9ApwLlk/видео.html
very good video Sir.
Thank you for sharing. what is the possibility of using both links at the same time. or combining both links to increase the bandwidth size
@victorjames6242 You can balance the traffic across both link, you can select both outgoing interface as your interface preferences. The short answer is YES you can use both link simultaneously
best practice is to change the FGT management port also, not just the SSLVPN. Also hotels, motels and other such sites will probably block SSLVPN on a port other than 443.
You are absolutely correct about hotels and motels blocking port 443. I recommend people use their own personal Hotspot if possible. Public WiFi is not the best.
@@techy-world3716 I have seen here that cell hotspots also block non typical ports so 443 is also the best there
@@techy-world3716 Agree that public wifi is not best if you have using split tunnel then user can use ssl vpn and then all their traffic will be encrypted. Personal hotspot doesnt work well for sales or other guys if you are in different region due to cost.
tks a loot !!!!
HI what is the default gateway of the Winserver 2016 ? plase it is 192.168.177.3? or 192.168.177.1/24 and what happen if i put the server behind the Fortiwe which will be the default gateway?
thanks for this man.
No need to setup smtp server and port first in settings?
Yes, there is no need to setup smtp server and port.
@@techy-world3716 Thanks
@@techy-world3716 But if I have my smtp server in cloud or local, how to specify?
tkns
the LAN 2 network is basically the management,right?Great video
LAN 2 network has some management features, such as HTTPS or FMG. Once any of the Administrative Access is enabled on that interface that makes it a management interface.
First of all, thank you for a very useful video. But how can you access GUI interfaces from your own Windows Machine by saying 192.168.177.3 or 192.168.177.1? There must be a setting here. In addition, how is it that you can ping 192.168.177.54 ip address from your own machine again? I think there is a configuration here that we have not seen in the previous video before?
Please watch the Part I of this Video ruclips.net/video/aNHIQdwXbas/видео.htmlsi=0OUvlJpzNP0zxui3
Hello, help, the token code does not arrive in my Gmail inbox, my question is if something additional has to be done in Gmail so that it receives the Fortigate token messages
Check your SPAM inbox, FortiToken can be sent into your GMAIL inbox without issue.
Very informative , I've just solve my ticket with this knowledge , thank you
Oh cool. What program did you use to draw the Topology?
GNS3 is the application used to draw the topology
I have a questions. Is there a difference between enabling NAT on the Policy? What does it do?
When NAT is enabled on a policy you are stating that you need the private IP translated to the public and vice versa. This is mostly used when you intend for that policy to go to the internet. If the traffic is going to the LAN or VLANs only there is no need to enabled the NAT option on the policy.
This is great. The only improvement I see is to setup the actual outgoing Destination in the Firewall policy rather then just selecting "ALL". This is a best practice so that the SDwan service is only dedicated to that one remote network. If you have two or 3 then maybe selecting ALL makes more sense. Right?
I am not too sure I fully understand your point. Here is a pointer, if the traffic is destined for the internet selecting all as the destination is best since you don't want to create different policy for traffic going to teams, zoom, Facebook, outlook etc. But if you the destination is local, then selecting a single remote network is best practices.
Can I configure IP addresses on both the physical interface and VLAN interface as router on a stick. And reach the physical interface on a switch that has a port in Access mode???
The answer is Yes. You can configure multiple physical and Virtual interfaces and even route between them. What you need is policy. To answer your question YES it is possible
Thanks man! it was helpful
Amazing video, thank you for the explanation. Would you please create a video on how to setup True Transparent Proxy mode?
Great suggestion!