http://docs.fortinet.com/uploaded/files/1954/Best_Practices_52.pdf
At the time of this post Aug-6-2014 is the most updated. It's a very well written doc that commons normal to advance subjects from;
- management
- firewall policies
- vdom
- vpn
- advance routing
"Use a non-NPU interface for at least one heartbeat interface to rule out potential NPU"
issues."
NOTE: always try to use a lower performing port for HA operations.
Firmware updates are most, so stay up to date & so you an take advantage of new features. I always try to obtain a copy of original software that I'm running b4 any firmware updates in case I need to format the flash.
Perform routine backups b4 any major changes, updates or firewall resets.
Try to avoid "any" in firewpolicies for interfaces or services unless that what you intended.
Review the fortinet bcp document and use what's applicable in your design & operations.
Ken Felix
NSE ( network security expert) and Route/Switching Engineer
kfelix -----a----t---- socpuppets ---dot---com
^ ^
=( @ @ )=
o
/ \
No comments:
Post a Comment