- 35
- 71 463
CyberSec
Canada
เข้าร่วมเมื่อ 21 ก.ค. 2021
Free Hands on Lab content on Fortinet Products and Cybersecurity.
Secure Access Service Edge FortiSASE Overview
Hands-On Lab Video Courses
*****************Hands-on lab courses****************
tkcybersec.net/
******************Learning proxy with fortiproxy hands-on lab*************
tkcybersec.net/courses/learning-proxy-with-fortinet-fortiproxy-hands-on-labs/
******************Learning zero trust access hands-on lab***************
tkcybersec.net/courses/learn-fortigate-zero-trust-network-access-hands-on-labs
Watch this video for an overview of Secure Access Service Edge (FortiSASE).
00:00 Introduction
00:25 What is FortiSASE
01:05 FortiSASE Security Technologies
01:53 Challenges that introduced SASE
03:30 FortiSASE Architecture
*****************Hands-on lab courses****************
tkcybersec.net/
******************Learning proxy with fortiproxy hands-on lab*************
tkcybersec.net/courses/learning-proxy-with-fortinet-fortiproxy-hands-on-labs/
******************Learning zero trust access hands-on lab***************
tkcybersec.net/courses/learn-fortigate-zero-trust-network-access-hands-on-labs
Watch this video for an overview of Secure Access Service Edge (FortiSASE).
00:00 Introduction
00:25 What is FortiSASE
01:05 FortiSASE Security Technologies
01:53 Challenges that introduced SASE
03:30 FortiSASE Architecture
มุมมอง: 59
วีดีโอ
FortiOS 7.6.0 ZTNA New Features
มุมมอง 3002 หลายเดือนก่อน
Hands-On Lab Video Courses Hands-on lab courses tkcybersec.net/ Learning proxy with fortiproxy hands-on lab tkcybersec.net/courses/learning-proxy-with-fortinet-fortiproxy-hands-on-labs/ Learning zero trust access hands-on lab tkcybersec.net/courses/learn-fortigate-zero-trust-network-access-hands-on-labs Watch this video to learn about the new FortiGate ZTNA 7.6.0 Features. 00:15 Introduction 00...
FortiGate ZTNA and FortiProxy Hands On Labs Video Courses
มุมมอง 12K3 หลายเดือนก่อน
Check out my website for FortiGate Zero Trust Network Access and FortiProxy Hands-On Labs video courses www.tkcybersec.net
ZTNA vs VPN
มุมมอง 2.6K4 หลายเดือนก่อน
Check out My hands-on lab courses tkcybersec.net/ Learning proxy with fortiproxy hands-on lab tkcybersec.net/courses/learning-proxy-with-fortinet-fortiproxy-hands-on-labs/ Learning zero trust access hands-on lab tkcybersec.net/courses/learn-fortigate-zero-trust-network-access-hands-on-labs/ In this video you will learn the difference between Zero Trust Network Access and Virtual Private Network...
Security Farbic FortiGate Root and Downstream Setup
มุมมอง 5135 หลายเดือนก่อน
Check out My hands-on lab courses tkcybersec.net/ Learning proxy with fortiproxy hands-on lab tkcybersec.net/courses/learning-proxy-with-fortinet-fortiproxy-hands-on-labs/ Learning zero trust access hands-on lab tkcybersec.net/courses/learn-fortigate-zero-trust-network-access-hands-on-labs Watch this hands-on lab video to learn how to setup security fabric for root and downstream fortigates 00:...
Why FortiGuard Web Page Blocked Not Showing
มุมมอง 1.7K5 หลายเดือนก่อน
Check out My hands-on lab courses tkcybersec.net/ Learning proxy with fortiproxy hands-on lab tkcybersec.net/courses/learning-proxy-with-fortinet-fortiproxy-hands-on-labs/ Learning zero trust access hands-on lab tkcybersec.net/courses/learn-fortigate-zero-trust-network-access-hands-on-labs/ Watch this hands-on lab video to learn how to fix FortiGuard web page blocked page not showing up on the ...
Learn FortiGate FortiGuard Web Filter Categories
มุมมอง 8926 หลายเดือนก่อน
Check out My hands-on lab courses tkcybersec.net/ Learning proxy with fortiproxy hands-on lab tkcybersec.net/courses/learning-proxy-with-fortinet-fortiproxy-hands-on-labs/ Learning zero trust access hands-on lab tkcybersec.net/courses/learn-fortigate-zero-trust-network-access-hands-on-labs/ Watch this hands-on lab video to learn how FortiGate Web Filter works, specifically the FortiGuard Web Fi...
FortiGate Dial-Up VPN Configuration
มุมมอง 1.7K6 หลายเดือนก่อน
Check out My hands-on lab courses tkcybersec.net/ Learning proxy with fortiproxy hands-on lab tkcybersec.net/courses/learning-proxy-with-fortinet-fortiproxy-hands-on-labs/ Learning zero trust access hands-on lab tkcybersec.net/courses/learn-fortigate-zero-trust-network-access-hands-on-labs/ Watch this hands on lab video to learn how to configure FortiGate dial up VPN, Push Remote VPN profile to...
FortiGate ZTNA and SSL VPN
มุมมอง 5K10 หลายเดือนก่อน
Check out My hands-on lab courses tkcybersec.net/ Learning proxy with fortiproxy hands-on lab tkcybersec.net/courses/learning-proxy-with-fortinet-fortiproxy-hands-on-labs/ Learning zero trust access hands-on lab tkcybersec.net/courses/learn-fortigate-zero-trust-network-access-hands-on-labs/ Watch this hands on lab video to learn how FortiGate Zero Trust Network Access (ZTNA) works with SSL VPN ...
FortiGate Zero Trust Network Access (ZTNA) For Remote Users Part 2
มุมมอง 3.5K11 หลายเดือนก่อน
Check out My hands-on lab courses tkcybersec.net/ Learning proxy with fortiproxy hands-on lab tkcybersec.net/courses/learning-proxy-with-fortinet-fortiproxy-hands-on-labs/ Learning zero trust access hands-on lab tkcybersec.net/courses/learn-fortigate-zero-trust-network-access-hands-on-labs/ Watch this hands on lab video to learn how FortiGate Zero Trust Network Access (ZTNA) works for remote us...
FortiGate Zero Trust Network Access (ZTNA) For Remote Users Part 1
มุมมอง 10K11 หลายเดือนก่อน
Check out My hands-on lab courses tkcybersec.net/ Learning proxy with fortiproxy hands-on lab tkcybersec.net/courses/learning-proxy-with-fortinet-fortiproxy-hands-on-labs/ Learning zero trust access hands-on lab tkcybersec.net/courses/learn-fortigate-zero-trust-network-access-hands-on-labs/ Watch this hands on lab video to learn how Fortinet Zero Trust Network Access (ZTNA) works for remote use...
FortiGate Zero Trust Network Access (ZTNA) Lab for On-Network or Internal Users
มุมมอง 3.6Kปีที่แล้ว
Check out My hands-on lab courses tkcybersec.net/ Learning proxy with fortiproxy hands-on lab tkcybersec.net/courses/learning-proxy-with-fortinet-fortiproxy-hands-on-labs/ Learning zero trust access hands-on lab tkcybersec.net/courses/learn-fortigate-zero-trust-network-access-hands-on-labs/ Watch this hands on lab video to learn how Fortinet Zero Trust Network Access (ZTNA) works for On-Network...
FortiGate and EMS Fabric Integration
มุมมอง 2.4Kปีที่แล้ว
Check out My hands-on lab courses tkcybersec.net/ Learning proxy with fortiproxy hands-on lab tkcybersec.net/courses/learning-proxy-with-fortinet-fortiproxy-hands-on-labs/ Learning zero trust access hands-on lab tkcybersec.net/courses/learn-fortigate-zero-trust-network-access-hands-on-labs/ Watch this video to have an overview of FortiGate and FortiClient EMS fabric integration 00:00. Introduct...
FortiGate 7.4 MAC Address Threat Feed
มุมมอง 501ปีที่แล้ว
Check out My hands-on lab courses tkcybersec.net/ Learning proxy with fortiproxy hands-on lab tkcybersec.net/courses/learning-proxy-with-fortinet-fortiproxy-hands-on-labs/ Learning zero trust access hands-on lab tkcybersec.net/courses/learn-fortigate-zero-trust-network-access-hands-on-labs/ Watch this video to have an overview of FortiGate MAC address threat feed for FortiOS 7.4 00:00. Introduc...
FortiGate Asset Identity and OT view
มุมมอง 950ปีที่แล้ว
Check out My hands-on lab courses tkcybersec.net/ Learning proxy with fortiproxy hands-on lab tkcybersec.net/courses/learning-proxy-with-fortinet-fortiproxy-hands-on-labs/ Learning zero trust access hands-on lab tkcybersec.net/courses/learn-fortigate-zero-trust-network-access-hands-on-labs/ Watch this video to have an overview of FortiGate asset identity and OT view for FortiOS 7.4.1 00:00. Int...
How to sign CSR using FortiAuthenticator
มุมมอง 1.8Kปีที่แล้ว
How to sign CSR using FortiAuthenticator
Things to know about digital certificate
มุมมอง 512ปีที่แล้ว
Things to know about digital certificate
Identity & Access Management with FortiAuthenticator
มุมมอง 1K2 ปีที่แล้ว
Identity & Access Management with FortiAuthenticator
Identity and Access Management (IAM) Overview
มุมมอง 7042 ปีที่แล้ว
Identity and Access Management (IAM) Overview
How to Configure Networking and design VMware ESXI with FortiProxy and FortiGate topology.
มุมมอง 2.5K3 ปีที่แล้ว
How to Configure Networking and design VMware ESXI with FortiProxy and FortiGate topology.
Ubuntu Installtion on VMware ESXI & Disk Partitioning sawp/root/home,
มุมมอง 6933 ปีที่แล้ว
Ubuntu Installtion on VMware ESXI & Disk Partitioning sawp/root/home,
SSL/TLS overview and detailed handshake
มุมมอง 1933 ปีที่แล้ว
SSL/TLS overview and detailed handshake
What is hashing and examples of hashing used cases
มุมมอง 1223 ปีที่แล้ว
What is hashing and examples of hashing used cases
if i have multiple internal web servers behind fortinet firewall but only one public ip, how can i use the single public ip for access all web servers from outside?
great, just pointing to you, 12:02, you should say open a putty session and enter 192.168.1.60 port 822, not 192.168.20.111 port 22, as per my understanding. Many thanks
@abdallahrukab you're right, my bad. Thanks for the feedback. If you're interested in ZTNA course check out tkcybersec.net
watch your audio levels...
Ya thanks I'm trying to keep close attention to the audio
Really appreciated to your video...
@metaphal4389 Thanks, if you're interested in courses I have a promotion on my ZTNA course on tkcybersec.net
Hi I have a scenario I'm deploying fortiproxy in an environment where they are already using another proxy now I need go get internet to my fortiproxy only with the help of another proxy what needs to be configured hear in my fortiproxy share me the steps
I feel this might answer your question, proxy chaining so setting up your FPX to forward HTTP.HTTPS to another proxy
Great work!
@@colinarmstrong5970 Thanks
@colinarmstrong5970 Thanks if you're interested in ZTNA course check out tkcybersec.net
Great work!!! Can you share FortiProxy VM image for VMware.
where can i download Forti client EMS Server sir?
I believe if you create forticare account at support.fortinet.com you can download the EMS exe checkout my courses at tkcybersec.net
Hello , i have Forticlient EMS server behind my Fortigate but when some one connect to some other network it loose connectivity , am i need to forward ports or need this source ip address
Hi, I'm not sure about the setup in your environments, IP addresses, firewall rules, routing, where the user is located, and where the EMS is located, so it's hard for me to tell. But to connect to EMS, you'd need routing set up to EMS, a Firewall Policy allowed to the EMS, or port forwarding if the user is outside your network coming from the public. check out my video course on ZTNA tkcybersec.net/courses/learn-fortigate-zero-trust-network-access-hands-on-labs/
Hlw sir after8 october my forticard was blocked
sorry not sure why? this issue can be checked with Fortinet Support
Trying to purchase this, however it requires a shipping address. After I input my US address it doesn’t let me proceed.
@Nabiisco89 Hi, let me check about this and get back to you
Shipping address not required anymore, please try again after removing cache and make sure billing address is correct 👍, thanks and let me know if u have any questions.
@@cybersec3306awesome I was able to purchase it now, thank you!
we have a single server with several applications and we want to configure the ztna fortigate to authorize an ssl vpn user to access only one application is this possible?
Using ZTNA you can configure use access to one application only. checkout my courses at tkcybersec.net
I would rename this video. Great information but I thought this was going to tell me about different digital career fields you know like Web and Software Development or Data and Analytics.
thanks for the feedback, i'm not sure what you're refering to about digital carrer fields
Hi. If i following this logic i can have server mappings only if the port is not used in FG. Can i have one proxy on port 10443 for example which have server mapping on whole net 10.0.0.0/8 for example on tcp forwarding on all ports? How can i add whole net in ztna destinations? Thanks!
Hi, if port number 10443 is not being used by any other service you can use it, and as far as i know you can map one IP to multiple HTTP/HTTPS server you can check out this article community.fortinet.com/t5/FortiGate/Technical-Tip-Accessing-multiple-web-servers-hosted-via-single/ta-p/259586 Also wanted to share my recent website and video courses currently on great promotion tkcybersec.net/
Hello. Do you know if I can do the connection with Trial license?
sorry for late replay i was away but check out this article community.fortinet.com/t5/Support-Forum/fortinet-ZTNA-licensing/m-p/289970#:~:text=You%20don't%20need%20an,the%20license%20best%20for%20you. Also wanted to share my recent website and video courses currently on great promotion tkcybersec.net/
ZTNA is just another marketing buzz word. VPN does almost all of these "new" features with host checks, and can also do mfa and certificate authentication.
VPN doesn't do endpoint security posture check or generate certificate for every endpoint connects to it.
Hi! Thank you for this video! on my Fortigate 60F i have not the cake graphics.... I don't understand why. Any idea?
@xlv600tr sorry missed your comment. Make sure under System > Features Visibility You enable Purdue Level
@@cybersec3306 Thanks a lot for answering. I activated "Purdue level" in Features Visibility ( it was inactive) but graphics didn't appear.
@@xlv600tr Not sure why i wouldn't show up check your firmware version this is feature that was released in 7.2 docs.fortinet.com/document/fortigate/7.2.0/new-features/498242/add-ot-asset-visibility-and-network-topology-to-asset-identity-center-page
@@cybersec3306 I have 7.6.0 . There is not that option in contestual menu. Maybe it depends from hardware-level appliance
Thank you!! Very nice tutorial. I need a rdp-connection to a windows-server. Is this also possible?
@TheMeteorra89 no problem, happy it helped. Yes, you can use TCP Forwarding for RDP. If you're interested in full ZTNA course check out tkcybersec.thinkific.com/courses/ZTNA
please make a video about the best practices of security profiles in inbound and outbound traffic .i.e. IPS , certificates.. thank you
I will do my best to make a video like this thanks for the feedback, if you can give me more details about the video you'd like that would help Also wanted to share my recent website and video courses currently on great promotion tkcybersec.net/
nice
how do you allow users to connect to other VPNs while maintain connection to fortiems?
@aliabdulrazaq3852 you can keep the route connecting to EMS separate from VPN so you'll have constant connection to EMS whether you are connecting to VPN or not . Hope that answers your question
Why are you using ESXi over Proxmox?
💯
Can you make a video on FortiGate/EMS integration for remote users that are off-fabric?
@KamiRedJJJ Sure, are you looking to integrate remote Forticlient with EMS? or integrate EMS with FGT in different locations?
it looks Terraform cannot do this configuration, I cannot find any related resource.
I struggled for minutes because I didn't enable the "Explicit Web Proxy" settings in the Interface. It worked, thanks!
Glad it helped Wanted to share my recent website and video courses currently on great promotion tkcybersec.net/
Really helpful video bro. Appreciated <3
Excellent expalanation. I will have to watch it gagian and again and then apply it on my environment
on the john PC did you do "anything" bar point to the firewall as a gateway, I ask as redoing this here, i dont get the nice "blocked" screen i cant get to a site ive blocked but its a horrible SSL error... wheras you get the Fortigate blocked page.... any ideas ? thanks !
@mgstu I am planning to post a video for this upcoming weekend, hopefully. I believe the reason Blocked page is not showing up because the browser does not have an SSL certificate FGT is using.
@@cybersec3306 yes this was where I got to, but for people that come on site you dont cotnrol youll never install a cert, would having a "valid real" cert on the FG overcome this ? thanks !
Yes, this should work having a publicly signed cert.
Thanks for sharing. Well explained and very clear.
Wonderful explanation. Thanks! Quick question, in 14:30, you did not specify 8013, i.e 192.168.1.60:8013 why ? Because this is by default ?
Thanks and yes 8013 is the default port used for FortiTele communication
can MFA be applied on above use cases like RDP/SSH?
Hi apology for late reply -> you could do form-based authentication (basic does not support two-factor authentication) -> you might have to enable two-factor authentication in the proxy authentication rule (via CLI) For example: docs.fortinet.com/document/fortigate/7.0.0/new-features/591056/ztna-session-based-form-authentication-7-0-4 docs.fortinet.com/document/fortigate/7.0.0/new-features/461532/ztna-proxy-access-with-saml-authentication-example Also wanted to share my recent website and video courses currently on great promotion tkcybersec.net/
hey, for some reason i cant fid SSL VPN when i want to create the VPN tunnel. I tried before in another lab i got both options but this time i only find the IPsec VPN option.
I believe you need to enable the SSL VPN feature visibility Go to System > Feature Visibility and enable SSL VPN
@@cybersec3306 sorry i forget to mention that i can't find SSL VPN on the EMS Server not on Fortigate. On 14:18 you got both options.
@@cybersec3306 Thank you!..i was wondering the same..
Great tutorial btw, just pointing out, you should never use ports below 1024 (822 for example is reserved for Mac OS X RPC-based services).
Thanks for pointing this out
Is it possible to do SMB through the ZTNA? So far I've been unsuccessful in getting it to work.
I haven't tried this scenario but came across this document docs.fortinet.com/document/fortigate/7.4.1/administration-guide/553746/ztna-access-proxy-with-kdc-to-access-shared-drives
Hi ,we are using the same kind of Setup in these case we are using Azure SAML for SSO ,how we can connect to internal servers ,how the Azure SAML SSO will take the tags
Hi, sorry i haven't worked on this scenario i would recommend looking through Fortinet documentations. docs.fortinet.com/ztna/7.4
HI, Thanks for thé vidéo . Should the end user be connected mandatory to EMS for RDP use case ? CAN RDP scénario without forticlient in end user side ?😊
In order for ZTNA tags to be received by FortiClient it need to be connected to EMS. RDP without FortiClient still possible if you have DNAT setup on FortiGate but it's recommended to use FortiClient with ZTNA or have VPN with ZTNA
Hi, thank you for all your videos on ZTNA. They helped me a lot to understand. Do you have notes on the steps you performed? Like a documentation overview? It would help me big time!
Unfortunately, I don't have this documented, but thanks for bringing it up. This is something I can work on documenting.
Do the remote user have to give external ip always in order to access internal resources or its just for 1 time for installing certificate?
You will need to have a remote user be able to reach the EMS on port, i believe 8013. As far as i know, remote users to access internal resources they need to hit a publicly accessible IP address not just for 1 time
@@cybersec3306correct 💪🏻
Hi. Thanks for sharing. I did the same way but getting internal connection error when doing rdp. Forti tech suggested to use proxy policy instead of normal firewall policy with ztna enabled.
I didn't know Shia LaBeouf was in IT! 🤔
😆😆😆
thanks , great video
Hi I need to integrate ZTNA using 2FA with FortiToken 400 do you have any idea?
Found this article that might help community.fortinet.com/t5/Support-Forum/ZTNA-with-2FA/td-p/215662
@@cybersec3306 tks man
Thanks buddy
ZTNA topic was not clear for me. Awesome tutorial! Thanks and grettings! Mateusz
Appreciate the feedback. Let me know if you have any questions.
Thank you for this video.
Excellent
Thanks for the video, keep it up Budd,
This is helpful.. thanks
You welcome ❤️