martes, 15 de abril de 2014

FORTINET::config user ldap



Configuring the LDAP server

The important parts of this configuration are the username and group lines. The username is the domain administrator account. The group binding allows only the group with the name GRP to access.
The dn used here is as an example only. On your network use your own domain name.
To configure LDAP server - CLI
config user ldap
edit "ldap_server"
set server "192.168.201.3"
set cnid "sAMAccountName"
set dn "DC=example,DC=com,DC=au"
set type regular
set username "CN=Administrator,CN=Users,DC=example,DC=COM”
set password *
set group “CN=GRP,OU=training,DC=example,DC=COM”
set filter ""
next


Fortinet Technologies Inc. Page 31 FortiOS™ Handbook - Authentication for FortiOS 5.0

viernes, 11 de abril de 2014

fortinet - Backup



 Copia del archivo de configuracion de un Fortigate a un servidor tftp.


**** execute backup config tftp fgt_col.cfg 10.1.1.1 ***



 Copia del archivo de configuracion de un Fortianalizar a un servidor ftp.


 *** execute backup all-settings ftp 1.1.1.1 faz.cfg userftp passftp ***

martes, 8 de abril de 2014

PORT MIRROR


SWITCH CISCO

monitor session 1 source interface Gi1/0/24
monitor session 1 destination interface Gi1/0/23

SWITCH DELL
monitor session 1 destination interface 1/g37                   

monitor session 1 source interface 1/g6
monitor session 1 mode

Una diferencia es que en dell solo permite una sesion.
SWTCH CISCO
Configuracion de un Port-Channel



interface GigabitEthernet1/27

 switchport mode trunk
 channel-group 1 mode active

interface GigabitEthernet1/28

 switchport mode trunk
 channel-group 1 mode active

interface Port-channel1
 switchport mode trunk
SWITCH CISCO

Configuracion para respaldar en un ftp el archivo de configuracion del equipo.

kron occurrence SafeConfig at 19:00 recurring
 policy-list SafeConfig
kron occurrence Backup at 23:30 recurring
 policy-list Backup
kron policy-list SafeConfig
 cli write
kron policy-list Backup
 cli write
 cli show run | redirect ftp://userftp:C1sC0@195.165.5.190/SW.cfg


Tiene dos secciones, una para guardar la configuracion en caso que tenga algun cambio y una segunda para enviarla al servidor ftp.


SWTICH DELL

Configuracion de interface con vlan de datosa y vlan de voz,  adicional restringir el acceso de la vlan 1.

switchport mode general
switchport general pvid xxx
switchport general allowed vlan add xxx
switchport general allowed vlan add yyy tagged
switchport general allowed vlan remove 1
FORTIGATE


Filtros para monitoreo y diagnostico


diagnose debug flow filter saddr X.X.X.X
diagnose debug flow show console enable
diagnose debug flow trace start 1000
diagnose debug enable

_____________________________________________


diagnose sys session filter src X.X.X.X
diagnose sys session clear