Techy-World
Techy-World
  • Видео 24
  • Просмотров 89 659

Видео

Steps to Hardening FortiGate SSL VPN
Просмотров 5336 месяцев назад
This video go over the steps to Hardening FortiGate SSL VPN 1. Changing default ports or popular ports 2. Using MFA for Local user account 3. Limiting access to specific geography 4. Limit concurrent connection 5. Create NoAccess Portal 6. Block access to/from Tor Exit Node and Relays
FortiGate Mobile FortiToken Two Factor Authentication
Просмотров 2726 месяцев назад
FortiGate Mobile FortiToken Two Factor Authentication
FortiGate Mobile FortiToken Two-Factor Authentication
Просмотров 666 месяцев назад
How to Setup FortiGate Mobile FortiToken Two-Factor Authentication
FortiGate email based Two Factor Authentication
Просмотров 2,7 тыс.6 месяцев назад
How to setup email two factor authentication on FortiGate firewall.
Getting Started with FortiGate HA Setup on GCP using SDN Connector Everything You Need to Know
Просмотров 6928 месяцев назад
Getting Started with FortiGate HA Setup on GCP using SDN-Connector. In this comprehensive guide, we will walk you through everything you need to know to set up High Availability (HA) with FortiGate on Google Cloud Platform (GCP) using SDN-Connector. High Availability ensures your network is always up and running, even in the face of hardware or software failures. We'll cover the essential conce...
FortiGate on GCP Tutorial A Beginner's Guide to Securing Your Cloud Infrastructure
Просмотров 3408 месяцев назад
Learn How to Secure Your Cloud Infrastructure with FortiGate on Google Cloud Platform (GCP)! Welcome to this educational tutorial that will provide you with a comprehensive beginner's guide on securing your cloud infrastructure using FortiGate on GCP. Whether you're an individual looking to enhance your cloud security skills or a business owner wanting to protect valuable data, this tutorial is...
FortiGate SSL VPN Realms
Просмотров 74410 месяцев назад
How To Securely Connect To Your Office Network From Anywhere - Fortigate SSL VPN
FortiGate SSL VPN for Remote Users
Просмотров 39410 месяцев назад
How To Securely Connect To Your Office Network From Anywhere - Fortigate SSL VPN
Publishing HTTPS Web App using FortiWeb Part III
Просмотров 2,7 тыс.11 месяцев назад
Publish HTTPS Web Application using FortiWeb. FortiWeb Web Application Firewall.
Installing IIS & Publishing Web Servers on FortiWeb - Part II
Просмотров 2,6 тыс.11 месяцев назад
This is a series video, am going to show you how to setup and manage webservers using FortiWeb and FortiGate. This will show you different ways to manage web server and prevent attacks on your web applications. I will demonstrate how to install IIS web server and publish web applications on FortiWeb.
Installing FortiGate & FortiWeb - Part I
Просмотров 4,7 тыс.Год назад
This is a series video, am going to show you how to setup and manage webservers using FortiWeb and FortiGate. This will show you different ways to manage web server and prevent attacks on your web applications.
Configuring ISP failover using SD WAN
Просмотров 3,6 тыс.Год назад
Configuring ISP failover using SD-WAN
Cisco Firepower 1120 DHCP Reservation
Просмотров 991Год назад
Configure DHCP Reservation on Cisco Firepower 1120 using FlexConfig Cisco Firepower Device Manager 1120 DHCP Reservation Syntax Template clear dhcpd binding all dhcpd reserve-address 172.16.19.200 93ab.00af.fc3d data-network dhcpd reserve-address 192.168.100.199 03cd.acd5.46b2 LAN Negate Template no dhcpd reserve-address 172.16.19.200 93ab.00af.fc3d data-network no dhcpd reserve-address 192.168...
FortiGate HA Setup
Просмотров 2,8 тыс.Год назад
FortiGate HA Cluster Configuration FortiGate HA Active/Passive configuration FortiGate High Availability Setup Watch Previous Videos How to Configure Site-to-Site VPN - ruclips.net/video/KK66ctBTxOY/видео.html FortiGate HA out-of-sync Troubleshooting - ruclips.net/video/bOoXN7f4mGk/видео.html Configuring VLAN Fortigate firewall - ruclips.net/video/2T8PPVAu1nM/видео.html FortiGate Firewall from ...
How to Configure Fortigate Site-to-Site VPN on gns3
Просмотров 10 тыс.Год назад
How to Configure Fortigate Site-to-Site VPN on gns3
Configuring VLAN and Inter-vlan routing on Fortigate firewall
Просмотров 27 тыс.Год назад
Configuring VLAN and Inter-vlan routing on Fortigate firewall
Installing FortiGate Firewall on ESXi Host from Scratch for Home Network
Просмотров 8 тыс.Год назад
Installing FortiGate Firewall on ESXi Host from Scratch for Home Network
FortiGate Firmware upgrade methods
Просмотров 897Год назад
FortiGate Firmware upgrade methods
FortiGate HA out of sync troubleshooting
Просмотров 9 тыс.Год назад
FortiGate HA out of sync troubleshooting
Home Assistant Text-to-Speech TTS using Random messages using Alexa
Просмотров 1,1 тыс.Год назад
Home Assistant Text-to-Speech TTS using Random messages using Alexa
Debian and Home Assistant Supervised Installation
Просмотров 2,7 тыс.Год назад
Debian and Home Assistant Supervised Installation
HOW TO INSTALL HOME ASSISTANT SUPERVISED - OFFICIALLY
Просмотров 6 тыс.Год назад
HOW TO INSTALL HOME ASSISTANT SUPERVISED - OFFICIALLY
How to install pfsense on ESXi Host
Просмотров 2,1 тыс.Год назад
How to install pfsense on ESXi Host

Комментарии

  • @victorjames6242
    @victorjames6242 5 часов назад

    Thank you for sharing. what is the possibility of using both links at the same time. or combining both links to increase the bandwidth size

    • @techy-world3716
      @techy-world3716 5 часов назад

      @victorjames6242 You can balance the traffic across both link, you can select both outgoing interface as your interface preferences. The short answer is YES you can use both link simultaneously

  • @myself-tp2my
    @myself-tp2my 5 часов назад

    best practice is to change the FGT management port also, not just the SSLVPN. Also hotels, motels and other such sites will probably block SSLVPN on a port other than 443.

  • @narfnn2111
    @narfnn2111 День назад

    tks a loot !!!!

  • @vicentegonzales369
    @vicentegonzales369 8 дней назад

    HI what is the default gateway of the Winserver 2016 ? plase it is 192.168.177.3? or 192.168.177.1/24 and what happen if i put the server behind the Fortiwe which will be the default gateway?

  • @AlwaysbeingLu
    @AlwaysbeingLu 13 дней назад

    thanks for this man.

  • @AlcidesFerreira2024
    @AlcidesFerreira2024 22 дня назад

    No need to setup smtp server and port first in settings?

  • @adrianmisischia1953
    @adrianmisischia1953 23 дня назад

    tkns

  • @maurofadda289
    @maurofadda289 27 дней назад

    the LAN 2 network is basically the management,right?Great video

    • @techy-world3716
      @techy-world3716 24 дня назад

      LAN 2 network has some management features, such as HTTPS or FMG. Once any of the Administrative Access is enabled on that interface that makes it a management interface.

  • @abdullahkuspnar5312
    @abdullahkuspnar5312 28 дней назад

    First of all, thank you for a very useful video. But how can you access GUI interfaces from your own Windows Machine by saying 192.168.177.3 or 192.168.177.1? There must be a setting here. In addition, how is it that you can ping 192.168.177.54 ip address from your own machine again? I think there is a configuration here that we have not seen in the previous video before?

    • @techy-world3716
      @techy-world3716 24 дня назад

      Please watch the Part I of this Video ruclips.net/video/aNHIQdwXbas/видео.htmlsi=0OUvlJpzNP0zxui3

  • @disconnected58
    @disconnected58 Месяц назад

    Hello, help, the token code does not arrive in my Gmail inbox, my question is if something additional has to be done in Gmail so that it receives the Fortigate token messages

    • @techy-world3716
      @techy-world3716 24 дня назад

      Check your SPAM inbox, FortiToken can be sent into your GMAIL inbox without issue.

  • @zinenhleDhludhlu-bf7ez
    @zinenhleDhludhlu-bf7ez Месяц назад

    Very informative , I've just solve my ticket with this knowledge , thank you

  • @livestronger1981
    @livestronger1981 Месяц назад

    Oh cool. What program did you use to draw the Topology?

    • @techy-world3716
      @techy-world3716 Месяц назад

      GNS3 is the application used to draw the topology

  • @livestronger1981
    @livestronger1981 Месяц назад

    I have a questions. Is there a difference between enabling NAT on the Policy? What does it do?

    • @techy-world3716
      @techy-world3716 Месяц назад

      When NAT is enabled on a policy you are stating that you need the private IP translated to the public and vice versa. This is mostly used when you intend for that policy to go to the internet. If the traffic is going to the LAN or VLANs only there is no need to enabled the NAT option on the policy.

  • @livestronger1981
    @livestronger1981 Месяц назад

    This is great. The only improvement I see is to setup the actual outgoing Destination in the Firewall policy rather then just selecting "ALL". This is a best practice so that the SDwan service is only dedicated to that one remote network. If you have two or 3 then maybe selecting ALL makes more sense. Right?

    • @techy-world3716
      @techy-world3716 Месяц назад

      I am not too sure I fully understand your point. Here is a pointer, if the traffic is destined for the internet selecting all as the destination is best since you don't want to create different policy for traffic going to teams, zoom, Facebook, outlook etc. But if you the destination is local, then selecting a single remote network is best practices.

  • @yvesneptune
    @yvesneptune Месяц назад

    Can I configure IP addresses on both the physical interface and VLAN interface as router on a stick. And reach the physical interface on a switch that has a port in Access mode???

    • @techy-world3716
      @techy-world3716 Месяц назад

      The answer is Yes. You can configure multiple physical and Virtual interfaces and even route between them. What you need is policy. To answer your question YES it is possible

  • @nshutifreddy9279
    @nshutifreddy9279 Месяц назад

    Thanks man! it was helpful

  • @1990punit
    @1990punit Месяц назад

    Amazing video, thank you for the explanation. Would you please create a video on how to setup True Transparent Proxy mode?

  • @andrenelson8188
    @andrenelson8188 2 месяца назад

    Great video. Thanks man

  • @nocsoc
    @nocsoc 2 месяца назад

    Hi can i add multiple public ip to fortigate interface in GCP. So that i can bind them with different Internal IP in VIP.

    • @techy-world3716
      @techy-world3716 2 месяца назад

      Yes the fortigate can use multiple public IP

  • @fahrul439
    @fahrul439 2 месяца назад

    sometime i'm having problem cannot connect to the vpn after received token code "Credential or SSLVPN configuration is wrong.(-7200)" any advise?

    • @techy-world3716
      @techy-world3716 2 месяца назад

      Try input the token faster. If you get the token via email it may sometime be delayed. Try to see if you get it faster on mobile phone or on desktop app.

  • @Wholnir
    @Wholnir 2 месяца назад

    How did you configurate ISP 1 and 2? Because I have 2 clouds connected to the same bridge adapter and in order to give internet access to both Firewalls I need to configure both with the same static route.

    • @techy-world3716
      @techy-world3716 2 месяца назад

      This article will help on how to configure ISP1 and ISP2 docs.gns3.com/docs/using-gns3/advanced/connect-gns3-internet/

    • @Wholnir
      @Wholnir 2 месяца назад

      @@techy-world3716 I manage to have internet with one cloud using NAT and the other with a bridge adapter, so both have different IP's and static routes. The problem right now It's that the phase 1 is down and the troubleshooting of fortigate are not very helpfull.

  • @vishnuk9523
    @vishnuk9523 2 месяца назад

    My eve-ng lab FortiGate vm firewall limit with 3 interface. It says trail vm license support 3 interface. How to use more interface.

  • @mitchellsmith4601
    @mitchellsmith4601 2 месяца назад

    I didn’t know you could set SMS for two-factor. Not great, but better than nothing.

  • @mrcraigaddison
    @mrcraigaddison 2 месяца назад

    Hi, is it possible to use a different alternative SSL certificate for each realm?

    • @techy-world3716
      @techy-world3716 2 месяца назад

      It maybe possible, I haven't had reason to use that myself. This article might help. docs.fortinet.com/document/fortigate/7.4.3/administration-guide/724772/ssl-vpn-multi-realm

  • @MiladMantashi
    @MiladMantashi 2 месяца назад

    thanks bro

  • @antoniocintora1157
    @antoniocintora1157 3 месяца назад

    Nice tutorials! Foreach public facing service do I need to have a public IP? Or it can be redirected in any way directly from de FortiGate?

    • @techy-world3716
      @techy-world3716 3 месяца назад

      No, you don't need a single public for each services, you could have multiple services on a single public IP

    • @antoniocintora1157
      @antoniocintora1157 3 месяца назад

      @@techy-world3716 When I try to create a second policy i always get the error "The same service port cannot be used for one Virtual IP twice." and I'm stuck with it :(

  • @mayankbisht3385
    @mayankbisht3385 4 месяца назад

    i didn't know that we can add email address under the user from the CLI. That's new to me. Thanks

  • @mayankbisht3385
    @mayankbisht3385 4 месяца назад

    Thanks for your video, this was very helpful.

  • @aushunter.82
    @aushunter.82 4 месяца назад

    Hi @Tech-World, Thanks for this video. It was really helpful.

  • @Danielcoouto
    @Danielcoouto 4 месяца назад

    Do you intend to take a course or publish a download link for this entire laboratory? that would be very useful

  • @Brunojlm
    @Brunojlm 5 месяцев назад

    Awesome! Thank you for the video!

  • @manoranjanmahanta1563
    @manoranjanmahanta1563 5 месяцев назад

    After doing this i am not able to access the firewall from lan zone. So how to get access it.

    • @techy-world3716
      @techy-world3716 5 месяцев назад

      The access will be applied to the LAN interface e.g port 1 if you are using physical port or the VLAN interface e.g Data VLAN. You can also apply it to multiple interface but not on the zone.

    • @manoranjanmahanta1563
      @manoranjanmahanta1563 5 месяцев назад

      Yes, I have created a data vlan 10 under port 1 and i am trying to access it from vlan 10 interface also https is enabled on that interface.

    • @techy-world3716
      @techy-world3716 5 месяцев назад

      Have you lost all access to the device or can you get in via console or ssh?

    • @techy-world3716
      @techy-world3716 5 месяцев назад

      The device you are accessing it from must be in VLAN 10 subnet as well. That is very important

    • @techy-world3716
      @techy-world3716 5 месяцев назад

      If you are still having issue, I can look at in over a remote session if you want.

  • @azeem20090
    @azeem20090 5 месяцев назад

    is there any need to have policy between one vlan in firewall?

    • @techy-world3716
      @techy-world3716 5 месяцев назад

      No there is no need to have policy between VLAN but there are reasons to why you may want someone to have access to a specific VLAN other than where they belong. For example if you have a Camera VLAN and you belong to Data VLAN you won't be able to view the camera from your network device in Data VLAN without having a policy to allow your device or the entire Data VLAN. I hope this helps

  • @chandanchauhan406
    @chandanchauhan406 6 месяцев назад

    Hello with this fortigate firewall deployment in VMware if we want to block any of the social sites on our home network does it will work or not plz reply

    • @techy-world3716
      @techy-world3716 6 месяцев назад

      Yes, it works perfectly. You have same functionality as what comes from a box. The VM version is very similar to the hardware.

    • @chandanchauhan406
      @chandanchauhan406 6 месяцев назад

      @@techy-world3716 thankyou so much But I have missed 1 questions which I have not mentioned if I don't have VMware hardware but I have installed VMware software in our computer does it work ? Plz reply

    • @techy-world3716
      @techy-world3716 6 месяцев назад

      It will work on your VMware without any problem.

    • @chandanchauhan406
      @chandanchauhan406 6 месяцев назад

      ​@@techy-world3716thankyou so much for helping us😊

  • @bayusangkaya5525
    @bayusangkaya5525 6 месяцев назад

    Thank you for this playlist, really help me to understand FG and FWB appliances. I have one question, can I set a transparent mode Fortiweb on this FWB VM?

    • @techy-world3716
      @techy-world3716 6 месяцев назад

      Yes, the VM version has transparent mode. The VM version has 4 modes: Reverse Proxy Mode, Offline Protection Mode, True Transparent Proxy Mode and Transparent Inspection mode

  • @user-im8zm8oe6j
    @user-im8zm8oe6j 6 месяцев назад

    Great work, please prepare a complete fortiweb configuration tutorial

    • @techy-world3716
      @techy-world3716 6 месяцев назад

      I will work on that soon. Watch out for new videos

  • @user-mh1gs8gp7i
    @user-mh1gs8gp7i 8 месяцев назад

    Fantastic! Thanks so much. I have a question, If I use a real ip of server Is it a problem?

    • @techy-world3716
      @techy-world3716 8 месяцев назад

      No!, using the server's real IP address shouldn't be an issue, but following the steps in this video is recommended.

  • @mostofakalam3994
    @mostofakalam3994 8 месяцев назад

    Very insightful. When the part 4 coming along? Can you please cover how to configure FortiWeb for multiple server hosting public-facing services?

    • @techy-world3716
      @techy-world3716 8 месяцев назад

      Very soon, I will be making that video

  • @Nicolasjelincic1520
    @Nicolasjelincic1520 8 месяцев назад

    Very good video and deployment. We are waiting to see this solution with load balancer sandwich!

  • @Nicolasjelincic1520
    @Nicolasjelincic1520 8 месяцев назад

    Good video!!!

  • @tamoorali9065
    @tamoorali9065 8 месяцев назад

    where is the live testing you did not connect anything and test anything or live anything

    • @techy-world3716
      @techy-world3716 5 месяцев назад

      Point taken, I will ensure that I show more testing in my next videos. But be assured that these steps are what is required on the FortiGate.

  • @antoniocamacho3931
    @antoniocamacho3931 8 месяцев назад

    Great video!

  • @mohamedeladl6273
    @mohamedeladl6273 8 месяцев назад

    how the internal networks reached to each others while no routing between them??

    • @techy-world3716
      @techy-world3716 8 месяцев назад

      Internal network can reach each other using the layer 2 switch, it doesn't get to the firewall. Once the data frame is sent to the switch the switch will forward the data frame to the other device using the MAC address table.

  • @rage2k6
    @rage2k6 9 месяцев назад

    Great video. I'm New with Fortinet and in my new job I have to manage several branch offices with Forti 40F. today I performed the firmware upgrade from 7.2.2 to 7.2.4 and lost the HA sync (out of sync). so, with the diag sys ha checksum recalculate command it should bring back up the HA? I already check the checksum and is different in both the FW. Thanks in advance. Regards

    • @techy-world3716
      @techy-world3716 9 месяцев назад

      Yes that should fix it, but ensure that the firmware is same on both device. The most common issue is when there is a different configuration on the firewall that is not configured on the other that will cause the out-of-sync issue not to be resolved.

    • @rage2k6
      @rage2k6 8 месяцев назад

      @@techy-world3716 thanks. Righ now the secundary is with the 7.2.4 and the primary with the 7.2.2. Should I upgrade the primary first? Regards

    • @techy-world3716
      @techy-world3716 8 месяцев назад

      As long as both of them are on same version you should be fine, it doesn't matter which is upgrade first. But I will upgrade the lower version first to match the higher version. Either way it should work once they are on same version.

  • @piotrkotowski1361
    @piotrkotowski1361 9 месяцев назад

    I'm doing the same steps at Cisco Firepower 1010 Threat Defense (FTD) using Firepower Device Manager (FDM) but I'm having the same type of errors. This is the 1st one: "Blacklisted cli error: clear dhcpd binding all". Any ideas?

  • @2010blankspace
    @2010blankspace 9 месяцев назад

    I like your videos and I need a mentor to configure the FortiGate/nse4 part (if you have any other contact, I would appreciate it if you share ). I am already using GNS3 to learn.

    • @techy-world3716
      @techy-world3716 9 месяцев назад

      Am glad you love them, I can be of help with your NSE4. Here is my email accessteckworld@gmail.com

  • @glenntembo2693
    @glenntembo2693 9 месяцев назад

    Thanks buddy

  • @techy-world3716
    @techy-world3716 9 месяцев назад

    This video is a continuation of the previous video. Fortigate SSL VPN for Remote User ruclips.net/video/j8kiN2tvp0M/видео.htmlsi=w1aFwH_k76cioiec

  • @glenntembo2693
    @glenntembo2693 9 месяцев назад

    Thanks boetie