Skip to main content
Sleiman
New Member
July 22, 2019
Question

Mgmt Access to 500D

  • July 22, 2019
  • 4 replies
  • 4382 views

Hello, I'm setting up a new pair of 500Ds. I first tried to setup mgmt access through the mgmt interface but I couldn't find where to set the default gateway for the mgmt port. I was able to access the Fortigate from the the same subnet but not from anywhere else.

 

I then assigned an interface to the inside interface and put it on a vlan on my distribution. I also added a static route for the 192.168.0.0/16 through the inside interface (port4). I still wasn't able to access the fortigate from a different subnet. I tried to debug but nothing showed up. I added a permit any on top and I still wasn't able to access. Can someone point me in the right direction to what I could be missing here?

 

Thanks

    4 replies

    hubertzw
    New Member
    July 22, 2019
    You need https enabled on the interface which belongs to the network segment you initiate the connection from.
    Toshi_Esumi
    SuperUser
    SuperUser
    July 22, 2019

    Are you setting up two 500Ds in HA? Then the GW for "dedicated-to management" port is configured in HA config. Because the network is separated from the regular user ("root") network.

    https://docs.fortinet.com/document/fortigate/6.0.6/handbook/234765/out-of-band-management

     

    Sleiman
    SleimanAuthor
    New Member
    July 22, 2019

    Hello, https is actually enabled on the firewall. I'm thinking this is purely routing or access. This will be configure in HA but I haven't done the HA config. Do you recommend doing the HA config and configuring the mgmt gateway from there? 

     

    Thanks 

    Toshi_Esumi
    SuperUser
    SuperUser
    July 22, 2019

    I think,... when you configure HA you have to use HA config to set the GW for management network, although there is a config section "config system dedicated-mgmt" as below:

    https://help.fortinet.com/cli/fos60hlp/60/Content/FortiOS/fortiOS-cli-ref/config/system/dedicated-mgmt.htm

    This doc has cryptic message "not recommended". But I'm assuming it's only "specifying interface" in this config section is not recommended.

    If you don't configure HA, you probably need to specify the GW in this config section after doing "set status ena". I haven't done without HA before so not 100% sure.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.