Fortinet Fortigate Firewall - SSL Inspection - Certificate Inspection and Deep (Full) Inspection
1. echo -n | openssl s_client -showcerts -connect registry.example.com:port 2>/dev/null | sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p' > xxca.crt
Replace the "registry.example.com:port" to your SSL VPN gateway URL and port.
2. Go to the file "xxca.crt", use a editor like "notepadqq" to open the file
3. Copy all the text in the xxca.crt
4. sudo vi /usr/local/share/ca-certificates/xxca.crt
5. Paste all text into this file and :wq (To save those text)
6. sudo update-ca-certificates
7. Reboot your machine
8. Then you can use the Forticlient to connect your VPN gateway.
Reference:
https://blog.keepchen.com/a/configure-forticlient-vpn-on-deepin-25.html
Install Fortinet Forticlient VPN on Deepin 23.1 (For SSL cert is self-signed cert)
Receive OpenSSL error from one IP and another one IP is normal
Identifying and preventing unwanted DNS queries from FortiGate's FQDN Address ObjectYES
Fortigate DNS and Server DNS different case connection rejected on firewall
Go to VPN > SSL > Settings > and un-check Require Client Certificate.
Fortinet SSL VPN - SSL Certificate expired and you need to bypass tempoarilty
Tencent Cloud using 3rd parties firewall for Internet edge firewall solution - Fortinet
FG-IR-24-029 (Affected version: 7.x) (CVE-2024-23113) - (CVSS 9.8) - Fortinet Fortigate
FG-IR-24-015 (CVE-2024-21762) (CVSS 9.6) - Fortinet Fortigate firewall
Fortinet Fortigate enable virtual patch to protect the firewall itself
Fortinet Fortigate Trusted host 10 entry limitation
Fortinet Firewall Feature - Security Rating
Fortinet Fortigate Firewall on Public Cloud
Under global vdom, security fabric, external connectors:
Fortinet Fortigate add external Threat Feed
Fortinet Fortigate - Virtual patching on the local-in management interface
A very good security feature on Fortinet Fortigate you should enable to protect your firewall against vulnerability
FortiOS with External Threat Feed with NSFocus. The Build – 6.4.9 build 8978 beta buildis already support NsFocus Threat Feeds Integration by External Connectors.
FortiOS with External Threat Feed with Cisco Talos. https://opendbl.net/lists/talos.list
FortiOS did not support AlienVault TI. Since the AlienVault TI API is unsupported.
But FortiSOAR is support AlienVault's for TI integration.
There are several free Open Dynamic Block Lists able to enhance your security:
FortiOS with External Threat Feed
1. Add the “Dashboard” –> “Status”
2. Click “Widget”, then you will see a pop up like the following:
Click on the module you want to put on the dashboard.
It’s done.
Fortigate firewall add some bulid-in network monitor module to Dashboard
Web Filtering – FortiGuard Center for URL/IP Rating and Information Lookup
http://www.fortiguard.com/webfiltering/webfiltering.html
If the website have been blocked by FortiGuard Web Filtering, you will see the screen like the following:
You can also submit request to remove/re-category from the vendor DB if you think the website is mis-category.
http://url.fortinet.net/rate/submit.php
If the website have been blocked by URL filtering (which is defined by administrator), you will receive a screen like the following:
FortiGate – FortiGuard Web Filtering and URL Filtering