Lab Notes And Processes Flashcards
Script Types and When To sync
Remote via CLI: Directly to Device Target. Does not need sync to take effect. Device Layer will automatically retrieve changes to config with Auto-Sync
Device Database: Needs to sync Device layer to device to take effect. Recommended to install both device and policy layer to avoid Unknown status for policy layer
Policy Script: Needs to sync policy layer to device to take effect
ZTP
Zero Touch Provisioning:
Involves settings up Metadata variables and a Pre-run CLI template. Pre-run CLI is used since it unassigns itself from the device after being used. The meta data varaibles are used to set common things like gateway IPs, port IPs, and Hostname
Then add model device to assign values to the variables and assig Pre-run CLI template to the model. The model will show as unknown device layer and never install policy layer. Run Quick install(Device DB) to apply the template to the model. Template unassigns once done, and Policy status will update, but still have modified status. Must install policy DB.
Just have to adjust real device to have a port with fmgr access, static route to fmgr, and set the fortimanager IP under central management. Then execute registration of fmger, this connects the device to fmgr and begins provisioning process, AKA autolinking
Enable VDOMs
On System Information Dashboard of Device > Edit VDOM > Set to Multi-VDOM
Default Priority for Virtual Cluster
128
Does FGSP sync configuration?
No
Session Sync Encryption is encapsulated by
ESP packets over SESSYNC_1 IPsec tunnel
How to enable OSPF ECMP:
Enable the rfc1583-compatible flag
How to block encrypted attack:
Map the device layer local certificate to Dynamic Mapping by creating an inspection profile.
Remember that every time you use an IPsec template,
The interfaces must be mapped to normalize interfaces
Does Unsetting the IPsec template delete the tunnel and dependencies?
No. You must individually remoted the objects and policies that were create and reference the tunnel or its interfaces.