Hello to all,
I would like to get some best practices for securing web server that we are exposing to internet.
I will use Interface with DMZ role, disable everything (ping, http, https...).
Will create VIP object and map it to our external IP address.
From inside network I will allow only ssh to the server and for external access to the server I will leave only https and dns.
Will use default Web Application Firewall security profile.
Now the question is what else could I do to secure it more, to add some other Security Profiles like IPS etc?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
You can use the other profile and other way is you can use virtual server option which will give additional certificate inspection layer to add more security posture
Hello,
This is not so clear for me at the moment so I will skip this part.
We need it today so I will consider this a little bit later when I grasp it.
Thank you
Hello
In addition to @msolanki post I'd add the following.
Hello,
1. I created web-server profile with next config:
2. Web Application Firewall Profile with default settings
3. Certificate Inspection
Disabled NAT, All Sesions, Inspection mode set to Proxy.
Service: HTTPS, DNS
To be honest for DNS I'm not sure, what would be the best case for that?
Hi
You don't need to open DNS access from external unless you have a DNS server to publish.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.