Friday, December 23, 2016

Fortigate - How to configure Policy Routing using for HO to Branch communication

Policy routing enables you to redirect traffic away from a static route. This can be useful if you want to route certain types of network traffic differently. You can use incoming traffic’s protocol, source address or interface, destination address, or port number to determine where to send the traffic. For example, generally network traffic would go to the router of a subnet, but you might want to direct SMTP or POP3 traffic directly to the mail server on that subnet.

If you have configured the FortiGate unit with routing policies and a packet arrives at the FortiGate unit, the FortiGate unit starts at the top of the Policy Route list and attempts to match the packet with a policy. If a match is found and the policy contains enough information to route the packet (a minimum of the IP address of the next-hop router and the FortiGate interface for forwarding packets to it), the FortiGate unit routes the packet using the information in the policy. If no policy route matches the packet, the FortiGate unit routes the packet using the routing table.


Step 1 - To create a new policy route, Click on "Create New".
Step 2 - Configure the Policy route, check the below example. Port1(Internal) to h2(VPN).

        Protocol => We can define which is we want to route.
        Incoming Interface => Local / Internal network port
        Source Address => Local / Internal network IP
        Destination Address => Remote IP or which network we want access.
        Outgoing Interface => Remote network accessing through this port. 
        Gateway Address => Outgoing interface Gateway, we can specify or not.
Step 3 - Configure the Policy route for reverse.  h2(VPN) to Port1(Internal).


Step 4 - After creating Policy route, check it is working by using ping command.

That's it...

Fortigate - Internet access for specifed Members or Group


Step 1 - Go to Policy & Object and create an address for Internet access members using IP address.

Step 2 - Then create group and add user to this group.

Step 3 - To create a policy for Internet access members only.


Thats it...

How to install Fortigate Client in windows

FortiClient provides SSL and IPSec VPN, a personal firewall, antivirus/antispyware scanning, Intrusion Prevention and web filtering. FortiClient’s Antivirus and Antispyware engine prevents virus attacks. It’s Heuristics and Antispyware engine helps in analyzing Pre- and Post-Execution Behavioral Analysis. The free antivirus tool also provides you with Real-Time Poisoned Webpage Protection, Personal Firewall protection, Anti-Rootkit Protection, WAN Optimization and many more.

VPN – It allows secure access to enterprise applications from remote locations.

Anti-Spam – The Detects, quarantines, and blocks spam messages and malicious attachments.

WAN Optimization –  FortiClient works with FortiGate units to accelerate network access.

App Detection – Works with FortiGate units to monitor and control which applications can run on an endpoint computer.

Antivirus – Protects you from malicious software.

Firewall – Blocks outsiders from hacking into your computer.

Web Filtering – Blocks malicious websites and enforces parental controls.


Step 1 - First check the system architecture.
Step 2 - Download the foticlient form the fortinet site as per your requirement.

Step 3 - Start the installation process.


Disable the real-time protection because we need only VPN options.




Step 4 - After the installation complete, we can see the additionally added  fortissl interface.

Step 5 - Now open the forticlient and disable the Antivirus & Parental Control.

Step 6 - Choose the Remote Access and configure VPN. Then connect the VPN server using IPsec or SSL.

Select the VPN authentication type and enter the remote static IP, Pre-Shared keys.






Step 7 - Finally check the VPN connectivity, Here I am using RDP for accessing Remote computer through VPN Tunnel.

That's it...

How to Basic Configure iomega StorCenter ix2 - (NAS Storage)



Step 1 - First we need to install Omega Store manager software on our local system. After that, open the software and connect NAS on LAN System. At that time, we can see that it is automatically detected.


Step 2 - After detecting, we can see the storage partition. Backup is default partition.

Step 3 - If you want, you can map the default Backup drive on your computer.

Step 4 - Next, we need to configure the NAS storage. For that, go to settings, it will automatically redirect to browser.

Step 5 - First we want to configure the Network.

Step 6 - After that, configure the Date & Time.

Step 7 - Configure the Security option for Authentication purpose. Here, we can create new user and password. Default Username and Password may be ADMIN.

Step 8 - When we access next time, it will ask for authentication. If you want to change any settings you should know the username & password.

Step 9 - We can create additional users for login.

Step 10 - The below step is, we can configure and link to Active directory and access the storage using AD user level authentication.


If we need to sync Active Directory, go through this step.

Step 11 - We can create email notification, if any trouble on NAS we will get the notification through mail.

Step 12 - Create Users & Group. In my case, I have linked to AD, so that I can select  users from AD. First we need to sync the NAS to AD and then we can see the user & group listed from AD.


Step 13 - Now we can create new share folder. Also add the users from the AD, for example, Department or branch wise.


Step 14 - The below tab, we can see all the features of Iomega Storage.

That's it...