ENGLISH

Fortinet Zero Trust Access Lab Guide for FortiOS 7.2

Book information

Language
english
Format
PDF
Filesize
14 MB (14942691 bytes)
Pages
\247
Time added
2023-07-21 04:04:58

Description

Network Topology Lab 1: Legacy Architecture Challenges Exercise 1: Integrating FortiSwitch Add FortiSwitch to ISFW FortiGate Management Configure the Default FortiLink VLAN Test Connectivity Exercise 2: Configuring Microsegmentation Block traffic between endpoints in same VLAN Manage traffic between endpoints in the same VLAN Exercise 3: Configuring Macrosegmentation Create new VLAN segments for each department Restrict Access to the Data Center Exercise 4: Using a VPN for Remote Access Set up a Remote Access VPN Examine the Security Limitations of VPNs Lab 2: Zero Trust Components Exercise 1: Configuring SSL VPN With Digital Certificates Configure SSL VPN for Certificate-Based Authentication Exercise 2: Creating a PKI User and Installing the CA-Signed User Certificate Create a PKI User Add the PKI User to the Existing SSL VPN Group Generate a CA-Signed User Certificate on FortiAuthenticator Test Two-Factor Authentication With a Digital Certificate for the SSL VPN User Exercise 3: Configuring FSSO Authentication for Domain Computers Create an FSSO Agent Enable FortiGate SSO Authentication and DC Polling (Event Log Polling) Create a DC Account Create a FortiGate Filter Add the FortiAuthenticator SSO Group to the FortiGate SSO Agent Create an FSSO User Group Configure an FSSO Firewall Policy Test FSSO Authentication Exercise 4: Configuring LDAP Authentication for Non-Domain Computers (BYOD) Create an LDAP User and User Group Configure Firewall LDAP Authentication Test LDAP Authentication Exercise 5: Adding FortiClient EMS to the Security Fabric Integrate FortiClient EMS With the Security Fabric Lab 3: Network Access Security With FortiNAC Exercise 1: Reviewing the Configuration Wizard and License Details Review the Configuration Wizard Review the License Information Exercise 2: Managing Certificates Generate a CSR Install SSL Certificates for the FortiNAC GUI Install the SSL Certificate for the Captive Portal Install the SSL Certificate for the Persistent Agent Exercise 3: Configuring Network Modeling Create Logical Networks Add FortiGate to the Inventory Restore the FortiGate Configuration Review FortiNAC Service and Captive VLANs Configure FortiGate Device Modeling Lab 3B: Network Access Security With FortiNAC Exercise 1: Integrating FortiNAC With ISFW FortiGate and Active Directory Integrate With ISFW FortiGate Using Service Connectors Integrate Active Directory With FortiNAC Exercise 2: Configuring Device Profiling and Registration Configure Device Profiling for a Domain Connected PC Review FortiGate Policies for Captive Networks Test the Device Profiling Rule Exercise 3: Configuring Role-Based Access Configure an Access Policy for Corporate Devices Configure an Access Policy for BYOD Devices Configure an Access Policy for Guest Devices Configure the Self-Registration Portal Test Role-Based Access Lab 4: Application Security Using ZTNA Exercise 1: Configuring On-Fabric Rules on FortiClient EMS Verify the Connection Between FortiClient, FortiClient EMS, and FortiGate Configure On-Fabric Detection Rules Verify On-Fabric Detection Rules Exercise 2: Configuring ZTNA Tags, Tagging Rules, and Features Enable ZTNA on the FortiGate GUI Configure FortiClient EMS ZTNA Tagging Rules Verify That ZTNA Tags Are Synced Exercise 3: Configuring a Basic HTTPS Access Proxy With SSL Certificate-Based Authentication Configure a Basic HTTPS Access Proxy With Certificate-Based Authentication Test Remote Access to the HTTPS Access Proxy Understand the Default Behavior of the set empty-cert-action Option Exercise 4: Configuring an HTTPS Access Proxy With Basic Local User Authentication and ZTNA Tags Configure an HTTPS Access Proxy With Basic Local User Authentication and ZTNA... Test the Connection for Users Exercise 5: Configuring a TCP Forwarding Access Proxy for RDP and SSH Configure a TCP Access Proxy With ZTNA Tags Test the Connection for Users Exercise 6: Configuring Basic ZTNA IP/MAC Filtering Configure a ZTNA IP/MAC Filtering Firewall Policy Test Endpoint Access Using the IP/MAC Filtering Firewall Policy Lab 5: Secure Access With Endpoint Posture and Compliance Checks Exercise 1: Configuring Endpoint Compliance Configure User and Host Profiles Configure Compliance Scans Configure Endpoint Compliance Configure Endpoint Compliance Policies Exercise 2: Testing Endpoint Compliance for Managed Corporate Devices Install a Persistent Agent and Validate the Settings Test a Persistent Agent Exercise 3: Testing Endpoint Compliance for Guest and BYOD Devices Test Guest Device Compliance Test BYOD Device Compliance Exercise 4: Integrating MDM With Network Access Integrate FortiNAC With FortiClient EMS Modify the User/Host Profile for MDM Compliance Exercise 5: Configuring FortiClient EMS ZTNA Tagging Rules to Block Remotely Controlled Machines Configure the FortiClient EMS ZTNA Tagging Rule for Detecting an RDP Connection Exercise 6: Checking Compliance Using FortiClient EMS Zero-Trust Tags Configure the FortiClient EMS ZTNA Tagging Rule for OS Version and Antivirus ... Configure Firewall Policies for Compliance Checks Test Access Based on Endpoint Compliance Lab 6: ZTA Enforcement and Incident Response Exercise 1: Manually Quarantine Off-Fabric FortiClient Endpoints Configure an SMTP Server and Enable Endpoint Alerts on FortiClient EMS Test Email Alerts and Manually Quarantine an Endpoint on FortiClient EMS Exercise 2: Configuring FortiAnalyzer Playbooks to Trigger Automatic Quarantine Enable the EMS Connector on FortiAnalyzer Configure Playbooks on FortiAnalyzer Test FortiAnalyzer Playbooks Exercise 3: Configuring Automated Response With FortiNAC Configure Security Incident Rules Test Automated Response

Similar books

Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36

Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36

2010 · PDF

THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.

THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.

1858 · PDF

Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.

Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.

2022 · PDF

The travels of Capts. Lewis and Clarke from St. Louis, by way of the Missouri and Columbia rivers, to the Pacific ocean; performed in the years 1804, 1805 & 1806, by order of the government of the United States. Containing delineations of the manners, customs, religion, &c. of the Indians, comp. from various authentic sources, and original documents, and a summary of the Statistical view of the Indian nations, from the official communication of Meriwether Lewis. Illustrated with a map of the country, inhabited by the western tribes of Indians

The travels of Capts. Lewis and Clarke from St. Louis, by way of the Missouri and Columbia rivers, to the Pacific ocean; performed in the years 1804, 1805 & 1806, by order of the government of the United States. Containing delineations of the manners, customs, religion, &c. of the Indians, comp. from various authentic sources, and original documents, and a summary of the Statistical view of the Indian nations, from the official communication of Meriwether Lewis. Illustrated with a map of the country, inhabited by the western tribes of Indians

1809 · PDF

Professional Linux kernel architecture ''Wrox programmer to programmer''--Cover. - ''What you are reading right now is the result of an evolution over more than seven years: After two years of writing, the first edition was published in German by Carl Hanser Verlag in 2003. It then described kernel 2.6.0. The test was used as a basis for the low-level design documentation for the EAL4+ security evaluation of Red Hat Enterprise Linux 5, requiring to update it to kernel 2.6.18 (if the EAL acronym does not mean anything to you, then Wikipedia is once more your friend). Hewlett-Packard sponsored the translation into English and has, thankfully, granted the rights to publish the result. Updates to kernel 2.6.24 were then performed specifically for this book''--P. ix

Professional Linux kernel architecture ''Wrox programmer to programmer''--Cover. - ''What you are reading right now is the result of an evolution over more than seven years: After two years of writing, the first edition was published in German by Carl Hanser Verlag in 2003. It then described kernel 2.6.0. The test was used as a basis for the low-level design documentation for the EAL4+ security evaluation of Red Hat Enterprise Linux 5, requiring to update it to kernel 2.6.18 (if the EAL acronym does not mean anything to you, then Wikipedia is once more your friend). Hewlett-Packard sponsored the translation into English and has, thankfully, granted the rights to publish the result. Updates to kernel 2.6.24 were then performed specifically for this book''--P. ix

2008 · PDF