Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

DeniSuda
New Contributor

Source-IP Dillema on Fortimanager

Hi everyone,

I have and suggestion to make for add a new option on FortiManager and firewalls. Today in Fortinet environment, to connect in centralized services (as FSSO, RADIUS, LDAP and so on...) we have to set the SOURCE-IP in each firewall and in a big scale, do per-device mapping for each one is not applicable, source-ip change for each managed environment. To improve for better management, is better to set the SOURCE INTERFACE that this service will run to.

I'm open to dialog and show this suggestion. 

Kind Regards
1 REPLY 1
RobertEvans
New Contributor III

Hi Dennis,

The superior method here is to have services (logging, routing, mgmt connections, etc) sourced from a management loopback as opposed to an interface address or interface.
This will make said services work properly and consistent on interface failover, interface IP changes, etc. 

Every firewall should get a management loopback IP, that is routed throughout your network. When possible it should be used as the source of mgmt traffic (syslog, FortiManager, FortiAnalyzer, etc). If WAN failover occurs, the FAZ or FM doesn't see any change in IP address only that connectivity from device was briefly lost. Same for syslog traffic has a consistent source IP no matter which link the traffic traverses.

As for mass deployment, many providers maintain config templating tools to facilitate tracking site local subnets and auto populating standard template configs for a given sites subnets. Outside of IPAM and automation tools, not much you can do to get around needing to manually config many parts of the Firewall on initial deploy.

-Rob
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.