Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nplljw
New Contributor II

Fortigate's Best Practices in Industrial Safety Environments

您好,客户的 foritgate 60f 防火墙已购买 ATP 和工业安全服务的许可证,并将在生产环境中以透明模式部署。我想了解一下在这个环境下如何完成防火墙部署,这个部署有哪些注意事项,以及如何使用工业安全服务特性库

5 REPLIES 5
ozkanaltas
Valued Contributor III

Hello @nplljw ,

 

In the beginning, you can use industrial signatures with application control and ips on monitor mode. I think this is a good start. After 1-2 weeks you can review logs and you can define for some signatures block mode. I know industrial networks are so strict and sensitive, and because of that firstly you should start with monitor mode. 

 

Also, you can review documents on the Operational Technology solution hub.

 

https://docs.fortinet.com/operational-technology

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
nplljw
New Contributor II

Hello, did the application control configuration file call the default during early deployment

ozkanaltas
Valued Contributor III

Hello @nplljw ,

 

If you didn't use industrial signatures before you should enable these signatures. After enabling, you can see industrial signatures on your FortiGate and you can use these signatures on your app control and ips profiles.

 

config ips global
set exclude-signatures none
end

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
AEK
SuperUser
SuperUser

First, FGT 60F is a small entry level model and I think you should check if it supports industrial DB if it is not already done.

In transparent mode you don't have gateways on your FortiGate so there is no need to change anything in your existing network topology.

Using monitor mode as mentioned by Ozkan is a good idea, this will avoid disturbing your production traffic.

On the other hand, OT security has its special practices and recommendations, so for better knowledge on OT security you may read the OTS study guide available on the Fortinet training portal.

AEK
AEK
dingjerry_FTNT

Hi @nplljw ,

 

Please use English in this Community if you need assistance from all users.  Otherwise, only those who can read your message may assist you.

Regards,

Jerry
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors