FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
bmedikonda
Staff
Staff
Article Id 339472
Description This article describes how to prevent unknown user's access to the network.
Scope FortiGate.
Solution
  1. Change the port numbers for HTTPS (443) and SSH (22) from the default ones: How to change the default ports  
  2. Configure the maximum log-in attempts and lockout period: Configuring the maximum log in attempts and lockout period 
  3. Consider configuring trusted hosts to limit access to the FortiGate: Configuring Administrator access to a FortiGate unit using Trusted Hosts 
  4. Configure local-in policy to restrict unauthorized login attempts to administrative access of FortiGate: Use local-in policy to restrict unauthorized login attempts to administrative access of FortiGate 
  5.  Use geolocation address object on the source address to allow/block specific countries: How to block by country or geolocation
Contributors