Showing posts with label Firewall. Show all posts
Showing posts with label Firewall. Show all posts

Saturday, February 3, 2018

Resetting a lost admin password - FortiNet

Resetting a lost admin password

Periodically a situation arises where the FortiGate needs to be accessed or the
admin account’s password needs to be changed but no one with the existing
password is available. If you have physical access to the device and a few other
tools the password can be reset.

Warning:
This procedure will require the reboot of the FortiGate unit.
You will need:
• Console cable
• Terminal software such as Putty.exe (Windows) or Terminal (MacOS)
• Serial number of the FortiGate device

Step 1. Connect the computer to the firewall via the Console port on the
back of the unit.
In most units this is done either by a Serial cable or a RJ-45 to
Serial cable. There are some units that use a USB cable and
Forti Explorer to connect to the console port.
Virtual instances will not have any physical port to connect to so
you will have to use the supplied VM Hosts’ console connection
utility.

Step 2. Start your terminal software.

Step 3. Connect to the firewall using the following:
Setting Value
Speed Baud 9600
Data Bits 8Bit
Parity None
Stop Bits 1
Flow Control No Hardware Flow Control
Com Port The correct com-port

Step 4. The firewall should then respond with its name or hostname. (If it
doesn't try pressing "enter")

Step 5. Reboot the firewall. If there is no power button, disconnect the
power adapter and reconnect it after 10 seconds. Plugging in the
power too soon after unplugging it can cause corruption in the
memory in some units.

Step 6. Wait for the Firewall name and login prompt to appear. The
terminal window should display something similar to the following:
FortiGate-60C (18:52-06.18.2010)
Ver:04000010
Serial number: FGT60C3G10016011
CPU(00): 525MHz
Total RAM: 512 MB
NAND init... 128 MB
MAC Init... nplite#0

Press any key to display configuration menu...
......
reading boot image 1163092 bytes.
Initializing firewall...
System is started.
<name of Fortinet Device> login:

Step 7. Type in the username: maintainer

Step 8. The password is bcpb + the serial number of the firewall (letters of
the serial number are in UPPERCASE format)
Example: bcpbFGT60C3G10016011
Note: On some devices, after the device boots, you have
only 14 seconds or less to type in the username and
password. It might, therefore, be necessary to have the
credentials ready in a text editor, and then copy and paste
them into the login screen. There is no indicator of when
your time runs out so it is possible that it might take more
than one attempt to succeed.

Step 9. Now you should be connected to the firewall. To change the admin
password you type the following…
In a unit where vdoms are not enabled:
config system admin
edit admin
set password <psswrd>
end
In a unit where vdoms are enabled:
config global
config system admin
edit admin
set password <psswrd>
end

Warning
Good news and bad news. Some might be worried that there is a backdoor into
the system. The maintainer feature/account is enabled by default, but the good
news is, if you wish, there is an option to disable this feature. The bad news is
that if you disable the feature and lose the password without having someone
else that can log in as a superadmin profile user you will be out of options.

If you attempt to use the maintainer account and see the message on the
console, “PASSWORD RECOVERY FUNCTIONALITY IS DISABLED”, this
means that the maintainer account has been disabled.
Disabling the maintainer feature/account
Use the following command in the CLI to change the status of the maintainer
account
To disable
config system global
set admin-maintainer disable
end
To enable
config system global
set admin-maintainer enable
end

Saturday, May 21, 2016

Configure DHCP on a Cisco ASA 5505

Wikipedia.org defines Dynamic Host Configuration Protocol (DHCP) as a network application protocol used by devices (DHCP clients) to obtain configuration information for operation in an Internet Protocol network. This protocol reduces system administration workload, allowing devices to be added to the network with little or no manual intervention.



The diagram has the network topology. In this network the firewall is the gateway of the 10.16.74.0/24 network. Firewall and Servers will be excluded from the DHCP pool.

First step is to configure the inside (LAN) interface on the 10.16.74.0/24 network

FIREWALL(config)#interface Vlan1
FIREWALL(config-if)#nameif inside
FIREWALL(config-if)#security-level 100
FIREWALL(config-if)#ip address 10.16.74.1 255.255.255.0


Next assign the LAN ports for the correct VLAN in this case port 1 of firewall will be on VLAN 1

FIREWALL(config)#interface Ethernet0/1
FIREWALL(config-if)#switchport access vlan 1
FIREWALL(config-if)#no shut



Lastly, configure the dhcp range and assign it to an interface. Configure DNS servers, one internal and one external in case the internal fails. Enable DHCP on the inside interface

FIREWALL(config)#dhcpd address 10.16.74.15-10.16.74.35 inside
FIREWALL(config)#dhcpd dns 10.16.74.10 4.2.2.2
FIREWALL(config)#dhcpd enable inside


In order to see which devices are receiving DHCP from the firewall run the following command

FIREWALL(config)#sh dhcpd binding

IP address Hardware address Lease expiration Type




Cisco article on configuring dhcp

http://www.cisco.com/en/US/docs/security/asa/asa71/configuration/gu...

Thursday, May 19, 2016

Enable Port Forwarding in Fortinet Firewall.

Port Forwarding in fortinet is very simple. Follow the below steps and you are good to go.

Step-1

Open your fortinet and go to Policies and objects -> Virtual IPs

















Step-2

Configure as shown below, Keep external ip empty if you are using any DynDNS service.
If you have static ip then you can enter the ip in there.











Step-3

Create one Virtual IP group and add the newly created ports in that as shown below.











Step-4

Now go to Policies and create one policy for port forwarding as shown below. In the destination address add the "port forward"  group.






















Port forwarding is configured now in the Fortinet. You can now connect from outside on the ports forwarded.




Tuesday, May 17, 2016

Configuring DynDNS on Fortigate FortiOS 5.0 and 5.2 in CLI Mode

The only way available to configure DynDNS or other providers in Fortigate 5 and 5.2 OS is by command line.
1) Connect to the device by telnet or SSH or GUI terminal and type the following command.

config system ddns  
edit 1      
set monitor-interface "wan1"        
set ddns-server dyndns.org        
set ddns-domain "hostname"        
set ddns-username "username"        
set ddns-password password
 
* edit 1 – 1 is the index number of DDNS settings. Start with 1 if its the first DDNS settings on the Fortigate box. This index number should be used later to modify anything related to this settings if required.
* wan1– is the port you need to configure DDNS and obviously connected to internet.
* ddns-server – dyndns.org is the server of DynDNS service provider. For other providers, see more detail below.
* hostname – is the one you have registered at dynamic DNS provider.
* username – user name of corresponding hostname at the provider.
* password – for the username and hostname from the provider.
The following DDNS servers can be used to configure Dynamic DNS in FortiOS 5 and later.
dhs.org — supports members.dhs.org and dnsalias.com.
dipdns.net — supports dipdnsserver.dipdns.com.
dyndns.org — supports members.dyndns.org.
dyns.net — supports www.dyns.net.
easydns.com — supports members.easydns.com.
FortiGuardDDNS — supports FortiGuard DDNS service.
genericDDNS — supports DDNS server (RFC 2136) defined in ddns-server-ip.
now.net.cn — supports ip.todayisp.com.
ods.org — supports ods.org.
tzo.com — supports rh.tzo.com.
vavic.com — supports ph001.oray.net.
Once you have configured DynDNS service as shown above, the WAN port of the device will be monitored and changed accordingly with the name and IP.

2) Typing,
show system ddns
will shows the ddns settings of the Fortigate device in CLI which can’t be seen in GUI mode.

3) To edit the same ddns entry, you can use
config system ddns  
edit 1
Make sure to enter correct index number ( eg 1) to modify.

It is recommended to take backup of the device configuration, so you can use it in future or while replacing the existing device. By using backup you do not need to configure dyndns again via CLI.