Skip to content

FortiGate 120G — Firewall Management (HA)

Basic Information

FieldValue
CategoryInfrastructure
OwnerFilip Kohák
DeputyArtem Ryzhkov
SLA24x7
DeploymentOn-prem (2× FortiGate 120G, Active-Passive HA, 2 ISPs)

Description

FortiGate 120G is Etnetera's perimeter firewall, running in an Active-Passive HA pair. It provides network protection, traffic filtering, VPN access, and SD-WAN for redundant connectivity across two ISPs.

Key features:

  • Stateful firewall + NAT
  • IPS/IDS (Intrusion Prevention System)
  • Web Filtering (URL categorization)
  • SSL Inspection
  • SD-WAN with two ISPs (load balancing, failover)
  • VPN: IPsec site-to-site, SSL-VPN for remote access
  • FortiNAC integration for 802.1X

Access and Login

  • URL: https://[fortigate-mgmt-ip] (management VLAN, internal network or VPN only)
  • Login: admin account (stored in Passbolt)
  • CLI access: ssh admin@[fortigate-mgmt-ip]
  • HA status: active node = node1, standby = node2

Warning

Make all configuration changes on the active HA node. The passive node syncs automatically. Discuss major changes (new policies, SD-WAN rules) with the owner before applying.

Procedure — Check HA Status

  1. Log in to FortiGate GUI
  2. Go to System → HA
  3. Verify both nodes are Synchronized and the active node is marked Master
  4. CLI: get system ha status

Procedure — Add a Firewall Policy

  1. Go to Policy & Objects → Firewall Policy
  2. Click Create New
  3. Fill in: Incoming Interface, Outgoing Interface, Source, Destination, Schedule, Service
  4. Set Inspection Mode and NAT as needed
  5. Save and verify policy order (policies are evaluated top-down)

Tip

Always test new policies during off-peak hours. Use Address Groups and Service Groups for clean configuration.

Procedure — SD-WAN Management

  1. Go to Network → SD-WAN → SD-WAN Zones
  2. Check status of both ISP links (green = active)
  3. SD-WAN rules are under SD-WAN Rules — define which traffic uses which ISP
  4. SLA monitoring: Network → SD-WAN → SD-WAN Health Check

Procedure — Firmware Update

  1. Check current version: Dashboard → System Information
  2. Download new firmware from support.fortinet.com
  3. Backup config: System → Config → Backup
  4. Upload firmware: System → Firmware → Upload
  5. After update, verify HA sync and critical policy functionality

Troubleshooting

ProblemSolution
Internet outageCheck ISP link status: Network → SD-WAN → Health Check; verify BGP/static routes
HA failover occurredCheck cause in System → Event Log; verify HA link physical connections
Traffic blockedPolicy & Objects → Firewall Policy → check order and rule match; Log & Report → Traffic Log
VPN not workingVPN → IPsec Tunnels or SSL-VPN Settings; check certificates and IKE phases
IPS false positivesSecurity Profiles → IPS → adjust signature action (Pass/Monitor instead of Block)

Contact

  • Owner: Filip Kohák — Slack @filip / filip.kohak@etnetera.cz
  • Deputy: Artem Ryzhkov — Slack @artem
  • Urgent incidents (internet/firewall outage): Slack #it-alerts

Etnetera a.s. — IT Team