No video

Ultraviolet Networks - Use case explorer - Terminating SSLVPN to a loopback interface

  Рет қаралды 3,017

Matt Sherif

Matt Sherif

Күн бұрын

Пікірлер: 26
@bytes86
@bytes86 Жыл бұрын
Thanks Matt, love your videos, learning from you a lot!🙏
@blakman1984
@blakman1984 Жыл бұрын
Top tier as always! Thank you for the enlightening video!
@mattsherif9141
@mattsherif9141 Жыл бұрын
Thank you for watching! I hope you have a Happy New Year!
@scatpack1017
@scatpack1017 Жыл бұрын
Awesome video and super helpful. You can actually use external threat feeds with local-in policies. They can be used with a negate source option like any other address object.
@capricornnnn
@capricornnnn 10 ай бұрын
any implementation doc with some example?
@yawnyame981
@yawnyame981 6 ай бұрын
I have followed the process where but it is not working. Connecting stuck at 10% with vpn unreachable gateway
@ITGuyGary
@ITGuyGary 4 ай бұрын
FYI - at 10:46, your Public IP is visible at the bottom of the "Your connections is not private" page
@osmanardanan86
@osmanardanan86 Жыл бұрын
Hey Matt, aren't the security profiles on the vip policy useless? I mean the traffic is not inspected bei virtual server and is completely encrypted anyway, isn't it?
@mattsherif9141
@mattsherif9141 Жыл бұрын
Hey Osman, not necessarily. This is to mitigate against known SSL VPN attacks, it also allows you to specify more inspection types vs. local in policy.
@JustinHoMi
@JustinHoMi 6 ай бұрын
FYI, ya forgot to censor your public IP one time.
@user-iu2nc5pj3m
@user-iu2nc5pj3m Жыл бұрын
Hey Matt, I've had a go at setting this up... It's working and I'm getting lots of hit on the FW policy. But no logs are showing up when I look for matching logs? Any ideas?
@mattsherif9141
@mattsherif9141 Жыл бұрын
Yes - check under the local traffic logs instead of forward traffic logs. Despite the policy being for "forwarded traffic" FGT is smart enough to know this traffic will actually terminate on it.
@randada1
@randada1 Жыл бұрын
there's something we aint seeing here. this configuration doesnt work as the SSL Loopback interface is unreachable even after doing the VIPs and fw policies. i went thru the community forum and folks pointed out this video too but ultimately is missing a few configurations
@mattsherif9141
@mattsherif9141 Жыл бұрын
I can assure you that’s not the case. Where are you getting stuck?
@mattsherif9141
@mattsherif9141 Жыл бұрын
Hi @randada1 did you manage to find your answer?
@oinkersable
@oinkersable Жыл бұрын
Cheers Matt, any cpu performance concerns when using the virtual interface, does offloading still happen for loopbacks, sslvpn isnt offloadad afaik but in general like ipsec on a loopback?
@mattsherif9141
@mattsherif9141 Жыл бұрын
No, due to SSL VPN sessions not being offloaded, it makes very little difference. Fast Path requirements don’t state that you need a physical interface to originate the traffic for Fast Path to take place: docs.fortinet.com/document/fortigate/7.0.9/hardware-acceleration/149012/np6-session-fast-path-requirements
@oinkersable
@oinkersable Жыл бұрын
@@mattsherif9141 Thanks and happy new year, looking forward to more of your great content in 2023!
@mattsherif9141
@mattsherif9141 Жыл бұрын
@@oinkersable Happy New Year to you too! Thank you for watching! If there’s anything you want to see, let me know.
@capricornnnn
@capricornnnn 10 ай бұрын
Thanks. How do you deny the bad IP addresses from reaching to SSL VPN?
@mattsherif9141
@mattsherif9141 10 ай бұрын
Great question! You can pin the SSL vpn instance to a loopback. Allowing you to use threat feeds and other handy features. Thats explained here: kzbin.info/www/bejne/ipDPXpellNSWn5osi=eskibN__w7Wsp1zx
@capricornnnn
@capricornnnn 10 ай бұрын
@@mattsherif9141 Thanks. I think its the same video but I just heard you saying that you can use ISDB but not much explanation. Sorry if I have missed it. "You can pin the SSL vpn instance to a loopback": can you explain this more? I have followed your instruction and SSL VPN works on Loopback interface but If I try to use ISDB of malicious IP addresses and put a Deny that it doesn't work.
@mattsherif9141
@mattsherif9141 10 ай бұрын
@@capricornnnn You don't want the ISDB in this case, you want to either come up with your own threat feed and use that a source and deny anything coming from that. You could also use GEO IP adddress objects and block those as well. ISDB doesn't apply in this scenario.
@capricornnnn
@capricornnnn 10 ай бұрын
@@mattsherif9141 So what you are saying is that its not possible to use ISDB with SSL VPN terminating to loopback interface? I am testing because what my understanding is that in order to use ISDB then I have to use Loopback interface and its not possible to use ISDB with local in policy. Threat feed can be used with local in policy. If Threat feed is the only way then I am thinking to stick with my current setup and use threat feed using local in policy. Do you have some doc or youtube video how to setup external threat feed. I heard that Talos is free but not sure how to use it.
@mattsherif9141
@mattsherif9141 10 ай бұрын
@@capricornnnn I am not saying that, I am saying your best bet is a threat feed. Here's the doc on configuring a threat feed docs.fortinet.com/document/fortigate/7.2.6/administration-guide/379433/configuring-a-threat-feed
Steps to Hardening FortiGate SSL VPN
20:38
Techy-World
Рет қаралды 776
Kind Waiter's Gesture to Homeless Boy #shorts
00:32
I migliori trucchetti di Fabiosa
Рет қаралды 14 МЛН
UNO!
00:18
БРУНО
Рет қаралды 5 МЛН
SPONGEBOB POWER-UPS IN BRAWL STARS!!!
08:35
Brawl Stars
Рет қаралды 17 МЛН
FortiGate How To - MC-LAG with FortiGate Switch Controller
25:28
Matt Sherif
Рет қаралды 10 М.
FortiGate ZTNA and SSL VPN
20:35
CyberSec
Рет қаралды 2,7 М.
NVIDIA Needs to STOP - RTX 3050 & Misleading Branding
11:35
Linus Tech Tips
Рет қаралды 1,3 МЛН
i'm so tired of talking about this..
10:00
Low Level Learning
Рет қаралды 24 М.
This NEW AI Chip From Huawei DESTROYS NVIDIA
9:37
Tech Pulse Pro
Рет қаралды 22 М.
Ultraviolet Networks Showcase - FortiSASE
24:13
Matt Sherif
Рет қаралды 733
License to Kill: Malware Hunting with the Sysinternals Tools
1:18:10
Mark Russinovich
Рет қаралды 83 М.