Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Chris_k
New Contributor

fortigate register & management from a Fortimanager

How to register and manage a Fortigate Device behind a dsl router with dynamic ip address?

 

Fortimanager is in LAN private network of a Fortigate behind a dsl router with static public ip.

 

FMG(priv ip)-->FortiGate-->(NAT)-->dsl-router(static ip)-->internet 

and

FGT-->(NAT)-->dsl-router(dynamic ip)-->internet

 

 

1 Solution
AEK
SuperUser
SuperUser

I recommend to manage it over IPsec.

 

FGT --------------------- Dial-up IPsec -------------------- FGT --- FMG

AEK

View solution in original post

AEK
6 REPLIES 6
AEK
SuperUser
SuperUser

I recommend to manage it over IPsec.

 

FGT --------------------- Dial-up IPsec -------------------- FGT --- FMG

AEK
AEK
Chris_k
New Contributor

How secure is to forward tcp 541 to Fortimanger behind Fortigate ?

AEK

Please remind me what 541 TCP used for.

Can you provide more explanation on what you want to achieve?

AEK
AEK
Chris_k
New Contributor

the case is i want to replace about 60 branch routers with fortigate appliances.

everything is behind a nated dsl modem with isp's dynamic addresses.

The same for the headquarters Fortigate but with static ip's.

I try to find something as zero touch configuration of the branch devices, and also a safe management of them either through ipsec or fortimanager virtual ip

AEK

Please check this link.

https://docs.fortinet.com/document/fortimanager/7.4.3/administration-guide/227089/ipsec-tunnel-templ...

I didn't do it before but I'm sure it will help.

Regarding management, again I think it is safer to manage through IPsec.

AEK
AEK
sw2090
SuperUser
SuperUser

@AEK 541/TCP is used for/by the FGFM Protocol used for communication between FMG and FGT.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors