SSL VPN host OS patch check

Configuring a FortiGate SSL VPN

SSL VPN host OS patch check

SSLVPN Client OS Patch Check feature allows a client with a specific OS patch to access SSL VPN services. The host check only works on Windows platforms. This means that MacOS/Linux users can always logon (assuming they have the correct user name and password) as the patch check is not applied to them. Options defined in the SSL VPN user group settings support this function (CLI only):

Variable

set sslvpn-os-check {disable enable}

config sslvpn-os-check- list {windows-2000 windows-xp}

set action {allow check-up-to-date deny}

set latest-patch-level {disable 0 - 255}

set tolerance {tolerance_num}

Description

Enable or disable SSL VPN OS patch level check. Default disable.

Configure the OS of the patch level check. Available when set sslvpn-os-checkis set to enable.

Specify how to perform the patch level check.

allow - any level is permitted

check-up-to-date - some patch levels are permitted, make selections for latest-patch-leveland tolerance

deny - OS version does not permit access Available when set sslvpn-os-checkis set to check-up-to-date.

Specify the latest allowed patch level. Default 4 for Windows 2000, 2 for Windows XP.

Available when action is set to enable.

Specify the lowest allowable patch level tolerance. Equals latest-patch-levelminus tolerance and above. Default for Windows 2000 and Windows XP is 0.

Available when action is set to check-up-to-date.

Configuration Example

The following configuration allows a Windows 2000 user with patch level 2

(latest-patch-levelminus tolerance) and above permission to access SSL VPN services, as well as any Windows XP users.

config vpn ssl settings set sslvpn-enable enable set tunnel-endip 10.1.1.10 set tunnel-startip 10.1.1.1

end

config user group edit "g1"

set group-type sslvpn

set sslvpn-tunnel enable

set sslvpn-tunnel-startip 10.1.1.1 set sslvpn-tunnel-endip 10.1.1.10 set sslvpn-webapp enable

set sslvpn-os-check enable

config sslvpn-os-check-list "windows-2000" set action check-up-to-date

set latest-patch-level 3

 

FortiOS v3.0 MR7 SSL VPN User Guide

54

01-30007-0348-20080718

Page 54
Image 54
Fortinet FORTIOS V3.0 MR7 manual SSL VPN host OS patch check, Configuration Example, Variable, Description

FORTIOS V3.0 MR7 specifications

Fortinet's FortiOS v3.0 MR7 marks a significant advancement in network security and management, providing organizations with enhanced features, technologies, and characteristics to better protect their IT environments. This version of FortiOS is designed to facilitate comprehensive security and optimized performance, ensuring that organizations can safeguard their networks against evolving threats.

One of the main features in FortiOS v3.0 MR7 is its robust firewall capabilities. The stateful firewall technology enables dynamic packet filtering based on predefined security policies. This strengthens the organization's perimeter defense by allowing or denying traffic based on user-defined rules. Additionally, the integrated Application Control feature extends the firewall's capabilities by identifying and controlling applications regardless of port usage, enabling organizations to enforce security policies on a finer-grained level.

FortiOS v3.0 MR7 also introduces advanced intrusion prevention system (IPS) functionalities. The next-generation IPS utilizes deep packet inspection and real-time threat intelligence to detect and block attacks before they can compromise the network. Coupled with Fortinet’s threat research team, which ensures timely updates of security signatures, this system helps organizations mitigate risks posed by sophisticated cyber threats.

Another key characteristic of FortiOS v3.0 MR7 is its enhanced VPN capabilities. The support for both SSL and IPsec VPN allows secure remote access for employees and offers flexible options for secure communication over the internet. This feature is essential for organizations that embrace remote work, ensuring that sensitive data remains protected regardless of the user's location.

In addition to its powerful security features, FortiOS v3.0 MR7 includes advanced reporting and logging capabilities. Users can generate detailed reports that highlight security events, traffic patterns, and performance metrics. This data not only improves visibility into network security but also assists in compliance with regulatory requirements.

Moreover, the platform's user-friendly interface enhances the overall management experience. Administrators can quickly configure settings, monitor activity, and respond to incidents effectively. With centralized management capabilities, FortiOS v3.0 MR7 allows organizations to manage multiple devices from a single console, simplifying operations and reducing administrative overhead.

In summary, Fortinet's FortiOS v3.0 MR7 integrates a wealth of security features, including a stateful firewall, advanced IPS, VPN support, and comprehensive reporting functions. Together, these technologies ensure that organizations can maintain a strong security posture in an increasingly complex threat landscape.