Preventing The Public Fortigate Interface From Responding To Ping Requests - Fortinet FortiGate FortiGate-3000 Install Manual

Fortios 3.0mr4
Hide thumbs Also See for FortiGate FortiGate-3000:
Table of Contents

Advertisement

Preventing the public FortiGate interface from responding to ping requests

Preventing the public FortiGate interface from responding to
ping requests
34
The factory default configuration of your FortiGate unit allows the default public
interface to respond to ping requests. The default public interface is also called the
default external interface, and is the interface of the FortiGate unit that is usually
connected to the Internet.
For the most secure operation, you should change the configuration of the
external interface so that it does not respond to ping requests. Not responding to
ping requests makes it more difficult for a potential attacker to detect your
FortiGate unit from the Internet.
The default public interface for the FortiGate-3000 and FortiGate-3600 is the
external interface.
A FortiGate unit responds to ping requests if ping administrative access is enabled
for that interface. You can use the following procedures to disable ping access for
the external interface of a FortiGate unit. You can use the same procedure for any
FortiGate interface. You can also use the same procedure in NAT/Route or
Transparent mode.
To disable ping administrative access from the web-based manager
1
Log into the FortiGate web-based manager.
2
Go to System > Network > Interface.
3
Choose the external interface and select Edit.
4
Clear the Ping Administrative Access check box.
5
Select OK to save the changes.
To disable ping administrative access from the FortiGate CLI
1
Log into the FortiGate CLI.
2
Disable administrative access to the external interface. Enter:
config system interface
edit external
unset allowaccess
end
FortiGate-3000 and FortiGate-3600 FortiOS 3.0MR4 Install Guide
Configuring the FortiGate unit
01-30004-0270-20070215

Advertisement

Table of Contents
loading

This manual is also suitable for:

Fortigate-3600Fortios 3.0mr4

Table of Contents