(I'm relatively new to all this, so please go easy on me...)
I need to upgrade our switch firmware as recommended by Fortinet Tech support. Most of the switches are easy, just using the FortiGate management functions, but the 108D is not so simple...
We have multiple sites, 3 of which have very similar setups :
/-> FortiGate A /-> Switch 1
ISP ---> FSW 108D -< || ----------->---> Switch 2 \-> FortiGate B \-> Switch 3
3 stacked FortiSwitches (224s and 248s) managed by 2 FortiGates (100E's or 200E's) in an HA grouping. Each of these setups is connected th the ISP switch through a FSW-108D switch.
Because of their logical location, the 108D's cannot be managed through the FortiGate GUI like the other switches can... So I get in with a laptop plugged directly into the switch. This is dead easy at locally our HQ, but the other two sites are remote and have no real IT staff on-site, and I'd like to be able to manage them remotely, if possible...
The current plan is to setup a laptop (via WiFi) inside the firewall, and hooking it up to the 108D with a cable when needed, and remoting in to the laptop to do whatever is necessary, but I was wondering if it was possible to make the 108D switches accessible through the LAN, without opening up any holes in our security... (I'm worried that because it has a direct link outside the firewall, I might be opening up a big can of worries...)
Any ideas or recommendations?
Thanks in advance,
Jamie
Jamie
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
If you still have a port free on the FS108D you could connect the FS directly to a port on the FGT (cluster) to be able to manage it. Same situation with a modem in front of a FGT - if it's only got one LAN port, no way to manage it. With at least 2 ports, just create a fancy intermediate LAN and a policy.
So there's no real vulnerability attaching the 108D to a port on out 248E or 224D switches, even though the 108D is upstream of the FG and the other switch(es) is downstrean of the FG?
Maybe I'm just being paranoid...
Jamie
Jamie
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.