Actually this feature is a feature that I have never seen in Cisco ASA or in Checkpoint Firewall. And after reading the original documentation for that I have realised that it knows much more than I have ever expected! :-) The post contains useful notes from the original doc and my summary for the FCNSP […]
June 18, 2012
It is pretty easy to configure more firewalls on a Fortigate box and against Cisco ASA they can do VPN as well! And the virtual firewalls can work in transparent and routed mode independently from each other, this is not possible with Cisco. The missing feature would be what Cisco already has is the resource […]
June 18, 2012
Dead Gateway Detection is feature like the backup or reduntant ISP service. In case we have 2 ISP connections to internet – a backup line with smaller bandwith and another used normally – we can use one as a backup internet connection. The topology: 1.1.1.0/24 | | Firewall | | | 2.2.2.0/24 | | | […]
September 20, 2011
In this example I configured a Site-to-Site VPN between 2 Fortigate boxes. It was realised with route based VPN and not with policy based VPN. I route everything through the tunnel here. Topology: ntp server and syslog server 192.168.1.159/24 | 192.168.1.1/24 (internal) myfirewall3 3.3.3.1/24 (wan) | 3.3.3.2 router 2.2.2.2 | 2.2.2.1 (wan) myfirewall1 1.1 Upgrade […]
June 20, 2012
2