Hello,
I want to be sure, the fortimanager communicate with the fortigate ( TCP 541), but is the fortigate communicate with Fortimanager too? Or Can i put the Fortimanager in a DMZ that the public network can't reached? ( only the Fortimanager can reach the public network not the opposit)
Thanks,
JF
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Or Can i put the Fortimanager in a DMZ that the public network can't reached? ( only the Fortimanager can reach the public network not the opposit)
-- for your case, yes, you can do this and let FMG add FGT public IP. after FMG/FGT tunnel setup, later traffic is through tunnel
Thanks
Simon
Hi, JF, both FMG and FGT may use TCP 541 to connect, based on topology
When FMG is behind NAT and no VIP access, when FMG adding device, need to connect to FGT TCP 541 to setup tunnel
When FGT is behind NAT and no VIP access, then FMG can not directly add device by that IP and you need to config FMG IP in FGT admin settings page - "Central Management" to let FGT connect to FMG to setup tunnel, then you will see FGT in FMG unregistered device list and then you can promote/add FGT from unregistered device list to device manager
Thanks
Simon
Or Can i put the Fortimanager in a DMZ that the public network can't reached? ( only the Fortimanager can reach the public network not the opposit)
-- for your case, yes, you can do this and let FMG add FGT public IP. after FMG/FGT tunnel setup, later traffic is through tunnel
Thanks
Simon
Ok, thank you,
So i can let the FMG in a DMZ that public network can't reach and let the FMG connect to the Fortigates , who have a public IP adress
JF
So i can let the FMG in a DMZ that public network can't reach and let the FMG connect to the Fortigates , who have a public IP adress
-- yes
Thanks
Simon
forgot to say, this is for config management between FMG and FGT
if you want to use FGT to send log to FMG (for FMG side logging function), then you still need to let FMG IP be accessible by FGT
Thanks
Simon
scao_FTNT wrote:if you want to use FGT to send log to FMG (for FMG side logging function), then you still need to let FMG IP be accessible by FGT
Would you also need to open the logging ports if the FGM is in a DMZ? Or is the communication achieved by the management tunnel?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1558 | |
1033 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.