10. Fortinet Getting Started v6.0. Support

10. Fortinet Getting Started v6.0. Support

Greetings! Welcome to the tenth, anniversary lesson of the course. Fortinet Getting Started. On previous lesson We covered the basic mechanisms of logging and reporting, as well as got acquainted with the solution. FortiAnalyzerTo conclude the practical lessons of this course, I want to introduce you to various technologies that may be useful in managing a firewall. FortiGateThe necessary theory, as well as the practical part, can be found below.

Suppose you have forgotten the password for your FortiGate account and cannot access the device. What should you do in this case? The built-in account will help you, through which you can change the administrator password. The login details for this account are shown in the image below.

10. Fortinet Getting Started v6.0. Support

However, in order to log in under this account, you must physically reboot the device. Executing the reboot command from the command line will not help. Also, you must be connected to the device through the console port during login. Since you can log into the account only about a minute after rebooting, I recommend writing down the password and copying it to the clipboard in advance.

Now let's talk about updates. Is it always necessary to update? In fact, no. My colleagues and I believe that updates are necessary in the following cases:

  1. When updating to a major version (for example, to 5.0 or 6.0) – if you need new functionality added in those versions.
  2. When updating to a minor version (for example, from 5.5 to 5.6) – if you need to fix a vulnerability in FortiOS or dependent devices. By the way, the list of such vulnerabilities can be viewed. here.
  3. It is necessary to fix errors that occur when working with the device.

In other cases, it is not advisable to update. It is important to remember that updating just for the sake of updating is not the best practice. This can create problems that did not previously exist.

If it is understood that an update is necessary, it should not be deployed to production immediately. It is essential to test it on a staging environment first. Additionally, before preparing for the update, it is crucial to thoroughly review the Release Notes – the changes in the new version. This is because some updates may significantly alter certain functionalities, rendering some of your configurations inaccessible. This document accompanies each update. Typically, they are found in the Fortinet documentation database.
After successful testing, a backup of the current configuration must be created, along with a fallback plan to revert to the previous configuration.

When updating, one must also consider the Upgrade Path (the sequence of updates). Only this way can risks during version upgrades be minimized. Acting contrary to the Upgrade Path can result in loss of some configuration information during the update.

And of course, one should not forget about the current service contract, which will help obtain qualified technical support in case it is impossible to resolve the issue independently.

Updating the operating system, restoring configuration using a backup, as well as utilizing administrator accounts, restricting administrator access, and creating a secure connection for administration - all these aspects are covered in the video lesson:

Play video

In the next lesson, we will cover issues related to licensing FortiGate and FortiAnalyzer devices. To ensure you do not miss it, follow updates on the following channels:

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster