Hi - I've seen Out of band posts but my question are:
1) For the out of band management of Fortigate 500D and 1000D firewalls is the recommendation to configure a separate PSTN line (is it even possible to configure a connection via a PSTN line?),
or is the recommendation to configure a separate IP address on the 2nd RJ 45 management interface and to use this?
The reason I ask is that these appliances will be managed as part of a Firewall Management Service and need a OOB option.
2) Are there any issues we need to consider with OOB management (PSTN or the 2nd management interface) in a HA configuration (active/active or active/passive)?
Many thanks, Larry
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
no- you cannot directly connect a PSTN (or POTS) line to the box. It only supports ethernet connections. You would need a router/bridge to make the jump. Some older and smaller models of Fortigates had built in modems but that was mostly for outbound backup access and seems to be much less common on newer hardware.
Your configuration will depend on how stringent your out of band needs may be. The "dedicated" management ports are typically used for management only and are out of band of normal traffic, but can be reconfigured to process traffic (either on purpose or by mistake). The management ports will also be used for internal system functions like sending syslogs or downloading IPS/AV updates unless configured otherwise.
For rock solid never going down no matter what OOB, you would need to attach a serial to ethernet/phone line/isdn/whatever bridge to the console port and you'll have command line access even in the event of unbootable firmware.
CISSP, NSE4
I usually have clients setup a separate OOBM network and then configure the devices to have a secondary management interface that has an IP on those networks. You shouldn't have any issues doing this in your environments. In HA arrangements you can configure a dedicated management port per box.
Mike Pruett
Many thanks Mike (quick question - is it even possible to connect a PSTN line to the 500D & 1000D models ans I don't see a suitable port?)
no- you cannot directly connect a PSTN (or POTS) line to the box. It only supports ethernet connections. You would need a router/bridge to make the jump. Some older and smaller models of Fortigates had built in modems but that was mostly for outbound backup access and seems to be much less common on newer hardware.
Your configuration will depend on how stringent your out of band needs may be. The "dedicated" management ports are typically used for management only and are out of band of normal traffic, but can be reconfigured to process traffic (either on purpose or by mistake). The management ports will also be used for internal system functions like sending syslogs or downloading IPS/AV updates unless configured otherwise.
For rock solid never going down no matter what OOB, you would need to attach a serial to ethernet/phone line/isdn/whatever bridge to the console port and you'll have command line access even in the event of unbootable firmware.
CISSP, NSE4
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.