FortiGate Version 3.0 MR4 Administration Guide
142 01-30004-0203-20070102
Operation mode and VDOM management access System Config
Management access
You can configure management access on any interface in your VDOM. See “For
a VDOM running in NAT/Route mode, you can control administrative access to the
interfaces in that VDOM.” on page 83. In NAT/Route mode, the interface IP
address is used for management access. In Transparent mode, you configure a
single management IP address that applies to all interfaces in your VDOM that
permit management access. The FortiGate also uses this IP address to connect to
the FDN for virus and attack updates (see “FortiGuard Center” on page 161).
The system administrator (admin) can access all VDOMs, and create regular
administrator accounts. A regular administrator account can access only the
VDOM to which it belongs. The management computer must connect to an
interface in that VDOM. It does not matter to which VDOM the interface belongs.
In both cases, the management computer must connect to an interface that
permits management access and its IP address must be on the same network.
Management access can be via HTTP, HTTPS, telnet, or SSH sessions if those
services are enabled on the interface. HTTPS and SSH are preferred as they are
more secure.
You can allow remote administration of the FortiGate unit. However, allowing
remote administration from the Internet could compromise the security of the
FortiGate unit. You should avoid this unless it is required for your configuration. To
improve the security of a FortiGate unit that allows remote administration from the
Internet:
• Use secure administrative user passwords.
• Change these passwords regularly.
• Enable secure administrative access to this interface using only HTTPS or
SSH.
• Use Trusted Hosts to limit where the remote access can originate from.
• Do not change the system idle timeout from the default value of 5 minutes (see
“Settings” on page 153).
Interface IP/Netmask Enter a valid IP address and netmask for the network from
which you want to manage the FortiGate unit.
Device Select the interface to which the Interface IP/Netmask
settings apply.
Default Gateway Enter the default gateway required to reach other networks
from the FortiGate unit.
Gateway Device Select the interface to which the default gateway is
connected.
Asymmetric Routing Select to allow asymmetric routing.