- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Intra vlan security profiles
Hi
I want to secure vlans to vlans traffic with my 200f fgt. Which security profiles can i enable between vlans?
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @rezafathi ,
In my opinion, IPS and AV are enough for these traffics. You can configure it with the default profile on your policy or you can customize the profile according to your preferences.
NSE 4-5-6-7 OT Sec - ENT FW
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks. Should i use deep ssl profile or not?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @rezafathi ,
This is generally not recommended for internal traffic. If you do a deep inspection, many applications may not work and you will need to install a certificate on each client.
NSE 4-5-6-7 OT Sec - ENT FW
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If i dont use deep inspection av would not work
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is partly true. If the protocol used is not secure, it will detect viruses. However, many protocols are sensitive. If you do deep inspection it won't work. That's why deep inspection is often used for web traffic.
NSE 4-5-6-7 OT Sec - ENT FW
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So can i disable ssl inspection?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
My advice is, yes you can close.
NSE 4-5-6-7 OT Sec - ENT FW
