Administration and Management Flashcards

1
Q

What to do if you forget admin password

A

execute migrate
Allows to load a backup of the config

Or format the flash and reload the image(from BIOS config menu), which erases the system settings, including the administrative accounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

External Authentication of Administrators

A

Can use external servers: LDAP, RADIUS, TACACS+, and PKI
Must configure server entries for each authentication server in your network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Wildcard Admin

A

Allows you to authenticate users from one or more groups

Supports LDAP, RADIUS, TACACS+, GROUP: Group supports multiple auth server types(configured in CLI)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

SAML Admin Authentication

A

SAML can be enabled across all Security Fabric devices
Allows smooth movement between devices for the admin (SSO)
FAZ can be the identity provider (IdP) or the service provider (SP)

There is also an option to use SSO with a FortiCloud account or its identity and access management (IAM) users. FAZ must be registered under that account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Wildcard admin for SAML

A

A wildcard SSO admin can be created that will match multiple users with an IdP. If the IdP uses a remote server, such as LDAP, this drastically reduces config requirements. If you don’t enable the Match All users on remote server wildcard option, then you must create all those users in FAZ

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Viewing Admin Event Logs

A

FAZ audits admin activity. System Settings > Event Logs will show event logs(config changes and logins), including administrator activity.

By default, only available to Super User access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Monitoring Tasks

A

The Task Monitor page allows you to view admin tasks, as well as the progress and status of those tasks.

By default, only available to Super User access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Monitor FortiGate Admin Logins

A

Under the System page on FAZ

The Failed Authentication Attempts page shows failed login attempts, and includes the source IP of the login, the login type, interface, protocol used, and number of failed attempts.

The admin logins page shows logins, failed logins, login duration, and configuration changes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Admin Profiles

A

Super_User - All system and device privileges enabled
Standard_User - No system and read-write access for devices
Restricted_User - No system and read-only access for devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

ADOMS with FGT VDOMS

A

Normal: Cannot assign VDOMs from the same FGT to multiple FAZ ADOMS. Must assign the FGT and all of its VDOMs to a single ADOM

Advanced: Can assign VDOMs from the same FGT to multiple FAZ ADOMs. Can use FortiView, Event Management, and Reports functions to analyze data for individual VDOMs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Creating an ADOM

A

Create new ADOMs if default ones do not fit requirements. Devices and be registers to their device-specificADOMs only

Disk quota configured per ADOM
Cannot delete default ADOMs
Cannot delete a custom ADOM if a device is still assigned to is.
command to view ADOMs: # diagnose dvm adom list

ADOM type must match the device type you are planning to add. By default, the ADOM type is set to Fabric for the root ADOM or when creating a new ADOM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Security Fabric ADOM

A

Can contain all devices in a Security Fabric in the same ADOM
Allows for fast data processing and log correlation

Combines results to be presented in: Reports, FortiView, Incidents & Events, Device Manager, LogView

After a Fabric ADOM is created, it is listed under the Security Fabric section of All ADOMs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

When alloted disk space is full:

A

An automatic alert is generated
Oldest logs are overwritten (Default behavior)
Can stop logging when full using the command: config system locallog disk setting
set diskfull nolog
end

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Disk Quota

A

Comprised of Analytics logs and Archive Logs
Default Ratio is 30%/70%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

% for Reserved Disk Quota and % for allocated

A

5-20% reserved for system usage and unexpected quota overflow

Only 80-95% is available for allocation to devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Command to see amount of reserved space on FAZ

A

diagnose log device

17
Q

How Raid affects Reserved Disk Quota

A

It determines the disk size and reserved quota level.

18
Q

Total Quota Value

A

Total System Storage - Reserved Space

19
Q

Allocated Space

A

Archive Quota + Analytics Quota for all ADOMs

19
Q

Disk Quota on License Information Widget

A

It shows values lower than the disk quota
Only reports on the number of logs pushed to FAZ on THAT DAY
Limited to stats gathered by fortilogd daemon

20
Q

Disk Quota Enforcement Daemons

A

logfiled - Monitors and enforces log file size, SQL database size, and archive file size; sends commands to the other daemons to process. checks processes every two minutes(unless system resources are high) and estimates space used by SQL database. If the disk quota is estimated to be above 95%, FAZ removes files as needed until down to 85%

sqlplugind - Enforces the SQL database size

oftpd - Enforces the archive file size

21
Q

Modify ADOM Disk Quota

A

diagnose log device

Allocating an insufficient quota can:
prevent you from reaching log retention objective
cause unnecessary CPU resources enforcing quota with log deletion and database trims
affect reporting if the quota enforcement acts on analytical data before a report is complete

22
Q

Increasing Disk Space

A

With FAZ VMs, you can dynamically add more disk space:
1. Power off the VM and add a new virtual disk
2. Start the VM and run execute lvm info to confirm the new disk was detected (it will be labeled as unused)
3. Run execute lvm extend (adds the space of the new disk to the lvm volume)
4. Reboot the VM, and then run the command get system status to see the new disk space available

With hardware FAZ, you must add one or more disks to the device. (If using RAID, must rebuild RAID array)

23
Q

System Config Backup contains…

A

Backups contain system info, Device list, report information

Does NOT include logs and generated reports

Can only restore to same model and firmware version

If FAZ is a VM, can use VM snapshots

24
Best Practices
Shut down gracefully, not doing so can damage databases (# execute shutdown) Use a UPS Save an unencrypted backup to secure location Synchronize the time on FAZ and all registered devices with an NTP
25
Match all Users on remote server:
Allow Administrators to log in to FAZ using their credentials on a remote Auth server. This option is useful for creating wildcard admins, and removes the need for FAZ to store local credentials.
26
(SAML) When FAZ is configured as SP, it...
it automatically registers itself to the Fabric root FGT as an SP. A default SSO admin is automatically created for each Security Fabric. The IdP certificate is also automatically uploaded to FAZ
27
How to see FGT System event:
FortiView>System>System Events FGT logging settings must be configured to log events and to send to FAZ