FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
alwis
Staff
Staff
Article Id 343728
Description This article describes which destination addresses and services need to be allowed on Upstream devices.
Scope Fortigate, Fortitoken, 2FA
Solution

Suppose there is a downstream FortiGate which having limited connectivity to the internet but want to implement SSL VPN with FortiToken 2FA on the downstream Firewall.

 

Topology:

WAN ---- FW1 [Upstream] <------->  FW2 [Downstream]

 

  1. Open SMTP port on Upstream FireWall (In this case port 587, change according to the setup on Downstream firewall SMTP setting).

 

email1.pngemail.png

  1. Create FQDN Object to 'globalftm.fortinet.net' and allow DNS request:

 

email3.png

 

  1. Firewall policy on Upstream:

 

email2.png

 

The 1st setup requires points 1 (to send an email to the user) and 2 (to communicate with the FortiToken server) is required. 

SSL VPN connection should works after this.

Contributors