Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Michael_McDonnell
New Contributor III

Is FCT-Access on the WAN interface safe?

Is it safe to enable FCT-Access (FortiHeartBeat in FortiOS 5.4) on the WAN interface?

 

I would like my FortiClient's to be able to receive configuration updates when they are off-net. By default they register to the IP of an internal interface which is only accessible when on-net or using VPN (not all of the FortiClient's have VPN access).

 

I have not found any information suggesting that enabling FCT-Access is safe or unsafe. I am wondering if there is any source of information to guide me. I would hate to be opening myself up to a vulnerability if this is considered bad or if there is a hardening procedure I do not know about.

1 REPLY 1
kolawale_FTNT

FortiHeartbeat uses SSL connection to the FortiGate. You can enable on the WAN interface. It is recommended though to use VPN to reach internal interfaces as you mentioned.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors