I have figured out how to configure SD-WAN, Link Aggregation, Virtual IPs and IP Pools on Fortigate 200F and 201F Firewalls
Subject: I have figured out how to configure SD-WAN, Link Aggregation, Virtual IPs and IP Pools on Fortigate 200F and 201F Firewalls
Good day from Singapore,
I have figured out how to configure SD-WAN, Link Aggregation, Virtual IPs and IP Pools on Fortigate 200F and 201F Firewalls, today, 30 Mar 2023 Thursday Singapore Time.
I have reviewed the existing configuration of Fortigate 200D firewall for a wine company today. Subsequently I have also reviewed the existing configuration of Fortigate 201F firewall for an investment company today. The Fortigate 201F firewall has SD-WAN configured. I am reviewing the configuration of existing Fortigate firewalls in preparation for setting up brand new Fortigate 200F firewall in April 2023, if I have the opportunity to do so.
This is the reference guide on how to configure SD-WAN in Fortigate firewalls.
Article: Configuring the SD-WAN interface
This is the reference guide on how to configure Link aggregation (IEEE 802.3ad) in Fortigate firewalls.
Article: Aggregation and redundancy
Regarding firewall policies (aka firewall rules)
================================================
A. Virtual IPs
Virtual IPs are needed for port forwarding.
If the direction of the traffic is from WAN to any other physical interface, you are configuring port forwarding. Before you can configure port forwarding, you must configure Virtual IPs. After configuring Virtual IPs, you can proceed to configure firewall policies (firewall rules) for port forwarding.
B. IP Pools
If your company/business/organization has many public static IPv4 addresses, you can force a server in your internal network to take on a specific public static IPv4 address. This is known as masquerading. IP Pool is applied in firewall policies for the direction of the traffic from LAN to WAN, for example, from your mail server to the internet. This direction of the traffic is known as outgoing internet access.
I have become reasonably seasoned in configuring Fortigate firewalls, after having configured Fortigate firewalls of various sizes for 8 different companies/organizations in Singapore. I have also configured SSL VPN in Cisco ASA 5506-X firewall for an investment company in Singapore previously (I think 2-3 years ago).
That's all folks. Please feel free to correct me if I am wrong. Hehe.
Regards,
Mr. Turritopsis Dohrnii Teo En Ming
Targeted Individual in Singapore
Blogs:
https://tdtemcerts.blogspot.com
https://tdtemcerts.wordpress.com
GIMP also stands for Government-Induced Medical Problems.
REFERENCES
===========
[1] https://mailarchive.ietf.org/arch/msg/sdwan-sec/8wnrdSpz4OcLKiFzWcCiHKSsNzY/
[2] https://sourceforge.net/p/net-snmp/mailman/message/37797887/
[3] https://www.mail-archive.com/net-snmp-users@lists.sourceforge.net/msg33443.html
[4] https://marc.info/?l=net-snmp-users&m=168019013930772&w=2
Comments
Post a Comment