Fortinet Firewall - Base Configuration

Words
302
Reading
2 min
Listen
Play
8y

Hey Guys,

Today I want to share a tutorial on how to configure a Fortinet 60 C with a base configurataion to get things going and your users browsing with restrictions that we will implement.

Image Source

First thing we do is to get into the Fortinet gui and set the Lan ip address which we will later log into and manage the firewall(Using a Web Browser). I inherited this firewall therefore I logged in via the CLI and made the LAN IP 192.168.7.254/24. (This is a lab so I am sharing all the information)

Select > System > Network > Interfaces like the below:

Select Port 1 and Edit:

Label it as follows and fill in the information for the subnet and create a dhcp lease. I created a small lease of 10 users which is deliberate to control the amount of devices that are on the network.

We will then need to create a Wan interface which user traffic would leave to reach it's desired destination. In my scenario I have a router that uses LTE technology and I created a WAN port with the same ip range so that my Fortinet wan port can talk to my router.

Thereafter we will need to add a static route for the internet like below:

Once that is created we will need to create Internal to Wan policies which will allow users from the inside to access the internet on the outside. See below configuration.

In this example, the Web Access service group only has DNS,HTTP,HTTPS for now which later can be added onto.

This is a simple configuration just to get the basics going and also very high level explaination on how to navigate around a Fortinet firewall. Please feel free to comment should you like the tutorial.

Thanks and Take Care!

Fortinet Firewall - Base Configuration | Ecency