Fortinet FortiGate FortiGate-300 Administration Manual page 56

Fortinet fortigate fortigate-300: user guide
Hide thumbs Also See for FortiGate FortiGate-300:
Table of Contents

Advertisement

Interface
56
To add a secondary IP address
You can use the CLI to add a secondary IP address to any FortiGate interface. The
secondary IP address cannot be the same as the primary IP address but it can be on
the same subnet.
From the FortiGate CLI, enter the following commands:
config system interface
edit <intf_str>
config secondaryip
edit 0
set ip <second_ip> <netmask_ip>
Optionally, you can also configure management access and add a ping server to the
secondary IP address:
set allowaccess ping https ssh snmp http telnet
set gwdetect enable
Save the changes:
end
To add a ping server to an interface
1
Go to System > Network > Interface.
2
Choose an interface and select Edit.
3
Set Ping Server to the IP address of the next hop router on the network connected to
the interface.
4
Select the Enable check box.
5
Select OK to save the changes.
To control administrative access to an interface
For a FortiGate unit running in NAT/Route mode, you can control administrative
access to an interface to control how administrators access the FortiGate unit and the
FortiGate interfaces to which administrators can connect.
Controlling administrative access for an interface connected to the Internet allows
remote administration of the FortiGate unit from any location on the Internet. However,
allowing remote administration from the Internet could compromise the security of
your FortiGate unit. You should avoid allowing administrative access for an interface
connected to the Internet unless this is required for your configuration. To improve the
security of a FortiGate unit that allows remote administration from the Internet:
Use secure administrative user passwords,
Change these passwords regularly,
Enable secure administrative access to this interface using only HTTPS or SSH,
Do not change the system idle timeout from the default value of 5 minutes (see
set the system idle timeout" on page
01-28006-0005-20041105
83).
System network
"To
Fortinet Inc.

Advertisement

Table of Contents
loading

Table of Contents