Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Larry_Dunn
New Contributor

Fortigate 500D and 1000D out of band

Hi - I've seen Out of band posts but my question are:

 

1) For the out of band management of Fortigate 500D and 1000D firewalls is the recommendation to configure a separate PSTN line (is it even possible to configure a connection via a PSTN line?),

or is the recommendation to configure a separate IP address on the 2nd RJ 45 management interface and to use this?

 

The reason I ask is that these appliances will be managed as part of a Firewall Management Service and need a OOB option.

 

2) Are there any issues we need to consider with OOB management (PSTN or the 2nd management interface) in a HA configuration (active/active or active/passive)?

Many thanks, Larry

 

 

1 Solution
Kenundrum

no- you cannot directly connect a PSTN (or POTS) line to the box. It only supports ethernet connections. You would need a router/bridge to make the jump. Some older and smaller models of Fortigates had built in modems but that was mostly for outbound backup access and seems to be much less common on newer hardware.

Your configuration will depend on how stringent your out of band needs may be. The "dedicated" management ports are typically used for management only and are out of band of normal traffic, but can be reconfigured to process traffic (either on purpose or by mistake). The management ports will also be used for internal system functions like sending syslogs or downloading IPS/AV updates unless configured otherwise.

For rock solid never going down no matter what OOB, you would need to attach a serial to ethernet/phone line/isdn/whatever bridge to the console port and you'll have command line access even in the event of unbootable firmware.

CISSP, NSE4

 

View solution in original post

CISSP, NSE4
3 REPLIES 3
MikePruett
Valued Contributor

I usually have clients setup a separate OOBM network and then configure the devices to have a secondary management interface that has an IP on those networks. You shouldn't have any issues doing this in your environments. In HA arrangements you can configure a dedicated management port per box.

Mike Pruett Fortinet GURU | Fortinet Training Videos
Larry_Dunn

Many thanks Mike (quick question - is it even possible to connect a PSTN line to the 500D & 1000D models ans I don't see a suitable port?)

Kenundrum

no- you cannot directly connect a PSTN (or POTS) line to the box. It only supports ethernet connections. You would need a router/bridge to make the jump. Some older and smaller models of Fortigates had built in modems but that was mostly for outbound backup access and seems to be much less common on newer hardware.

Your configuration will depend on how stringent your out of band needs may be. The "dedicated" management ports are typically used for management only and are out of band of normal traffic, but can be reconfigured to process traffic (either on purpose or by mistake). The management ports will also be used for internal system functions like sending syslogs or downloading IPS/AV updates unless configured otherwise.

For rock solid never going down no matter what OOB, you would need to attach a serial to ethernet/phone line/isdn/whatever bridge to the console port and you'll have command line access even in the event of unbootable firmware.

CISSP, NSE4

 

CISSP, NSE4
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors