Yuri Slobodyanyuk Blog on Information Security 2024年07月23日
Fortigate FortiOS 7.0 is out - what's new Visual Guide
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

本文详细介绍了 FortiOS 7.0 版本中 Web 管理 GUI 的可视化变更,涵盖了 API 预览、CLI 编辑、安全管理、SD-WAN、SSL 证书、安全 Fabric 自动化、网络路由对象、流量整形、安全配置文件、SSL VPN 客户端配置和 Zero Trust 网络等方面。

📈 **API 预览选项**:在几乎所有配置屏幕上都提供 API 预览选项,用户可以查看底层的 API 调用以实现自动化配置。此功能可以帮助用户更好地理解 Fortigate API,并更方便地进行自动化操作。

💻 **CLI 编辑选项**:在许多地方添加了 CLI 编辑选项,用户可以在 GUI 中直接进入配置级别,方便进行更精细的配置操作。

📢 **安全管理改进**:不安全的管理员协议在界面页面上以醒目的红色突出显示,并移除了 GUI 中的 Telnet 访问,只能通过 CLI 启用。

📃 **SD-WAN 配置整合**:将所有与 SD-WAN 相关的配置整合到一个页面上的不同选项卡中,更方便用户管理 SD-WAN 配置。

📁 **本地 Out 设置**:新增了本地 Out 设置,允许用户设置 Fortigate 发起流量的源 IP 地址。

📄 **免费 SSL 证书**:支持通过 ACME Let's Encrypt 使用 DNS 验证获取免费 SSL 证书,但有效期最长为 60 天。

📅 **安全 Fabric 自动化改进**:将安全 Fabric 自动化相关页面合并到一个页面上的不同选项卡中,简化了管理操作。

📂 **网络路由对象页面**:新增了网络路由对象页面,用于管理路由相关配置,包括前缀列表、社区、路由映射等。

📀 **流量整形页面合并**:将所有流量整形相关页面合并到一个页面上的不同选项卡中,更方便用户管理流量整形配置。

📆 **安全配置文件改进**:SSL 检查功能允许用户为同一个配置文件选择多个 SSL 证书,以保护同一 IP/服务器上的多个网站。

📇 **视频过滤器页面**:将视频过滤器从 Web 过滤配置文件中分离出来,并提供独立的页面,方便用户管理视频过滤配置。

📉 **SSL VPN 客户端配置**:新增了 SSL VPN 客户端配置功能,允许 Fortigate 作为 VPN SSL 客户端连接到另一个 Fortigate。

📊 **Zero Trust 网络功能**:新增了 Zero Trust 网络功能,为用户提供更安全的网络访问控制。

📋 **其他改进**:除了上述功能,FortiOS 7.0 还包含其他一些改进,例如移除了一些旧的颜色主题,增加了新的颜色主题等。

On 30th of March Fortinet released FortiOS 7.0 for all the supported models (alas, many D series Fortigates like 500D, are not supported), and here is the visual walkthrough of changes that can be seen in GUI.

Note
All the videos below come without sound.

New color themes were added, some old ones were removed (bad)

It is a tradition for Fortinet to redesign Web management GUI of each new major FortiOS release, with most of their hit-and-miss redesigns being a miss. Finally, in Fortigate 6.0, they came up with the Green theme that most of the people liked. Only that in FortiOS 7.0 …​ it was removed. To provoke emotional selling point they added the Retro theme, see below. Unfortunately, to me, this theme of FortiOS 2.8 era provokes not much nostalgia (Fortinet marketing hoped), but bad memories of Fortigate 60 never coming up after you push Reboot button in this Web GUI. The only theme I find the least ugly is the Mariner one, but let’s hope that after much discontent I see coming, Fortinet will get back the Green theme.

API Preview option is available almost for all configuration screens (good)

That’s pretty cool - now we can see underlying API calls to automate the configuration. A bit of context - Fortigate (and other Fortinet products), have well working REST API, which you can use to programmatically configure/monitor these devices via HTTPS REST API requests. Unfortunately for us, Fortinet hid the API Documentation behind the paywall. To access the full Fortigate API reference, you have to have subscription to the Fortinet Developers Network, which costs about 2000 Euro a year. They offer a free access (kind of) though - if you can find 2 "sponsors" to vouch for you at Fortinet, you can ask for free developer access to the FDN (without ability to post on forums or any support obviously). But now, with this API Preview button, we can see the API calls and get along without access to API documentation.

Edit in CLI option added in many places

This enters configuration level up to the very object we have opened in GUI.

Insecure admin protocols are highlighted in bold red on the interface page (good)

It was previously in pink, but now it screams at the administrators "What are you doing?". The Telnet access was even removed from GUI and can only be enabled on CLI.

All SD-WAN related configs are now in a single page on different tabs (good)

That was begging to be fixed - no sense to separate part of the same feature into 3 different pages.

Dropped support for many/most of the D series Fortigates (bad)

Not sure whether it is marketing-reasoned or technically based, but we have clients with various D models that work just fine, also with valid updated subscriptions. And the thought of upgrading firewall just because no new FortiOS versions will be released for it is not much fun as puts pressure on admins to upgrade while everything works fine. Fortinet announced few months ago Long Time Support program to keep older FortiOS versions up-to-date security-wise, but I haven’t heard anything about it since then.

new Local Out settings (must be 1st enabled in Visibility) to set Source IP for Fortigate-originated traffic (good)

This feature was available in CLI only, now it has been exposed in GUI as well. We can control what source IP Fortigate will use for the traffic it originates, e.g. FortiGuard/DNS etc. When enabling SD-WAN it can be quite important.

Free SSL Certificates via ACME Let’s Encrypt with DNS verification, but only for 60 days validity max (good)

Another "cool category" feature - we can set up Fortigate to request and update automatically SSL certificate from Let’s Encrypt certificates issuer, and of course it is totally free. This takes away the last reason not to install valid SSL certificate for admin access "But it costs money …​".

Security Fabric → Automation rearranged, new tabs for Triggers, Actions (good)

Here too, they just combined Automation related pages into tabs of the same page, no new functionality.

New: Network → Routing Objects (good)

Finally, not only cool, but essential feature - all routing-related configs available in CLI until now, got their own page in Network → Routing objects. Prefix lists, Community, route-map - all the things you can’t really do without when enabling dynamic routing protocols on Fortigate. I , personally, will continue configuring those things on CLI.

Merge all Traffic Shaping related pages into one with Policy & Objects → Traffic Shaping with multiple tabs (good)

Also, not new functionality, but re-arrangement that was only logical.

Security Profiles → SSL Inspection, now multiple SSL certificates can be chosen for the same profile to protect multiple web sites residing on the same IP/server (good)

Quite important one for those who use Fortigate to protect their internal servers with load-balancing and SSL offloading.

Security Profiles → Video Filter (good)

What was in the past part of Web Filtering profiles, now has moved to its own page. I see it mostly used by K-12, university environments, and for regular Enterprise admins it was just a distraction on the Web Filtering page.

SSL VPN Client configuration is now available for Fortigate to connect as VPN SSL Client to another Fortigate (good)

This is completely new feature - we can now (seemingly) set up local Fortigate to connect to the remote one as VPN SSL client. Fortigate as IPSec VPN client capability has been around for ages and works actually well. Let’s wait and see how it works in production. Usually, brand new features take their time to work as expected.

Zero Trust Network capability (good, probably?)

This one is so new that I can’t find much information on the Fortinet site. So can’t say much except that exists, will update once have some experience with it, as every vendor means different things for Zero Trust Access.

That’s all for today, I will be posting about new features as I test them, so come back again to read about them.

Follow me on https://www.linkedin.com/in/yurislobodyanyuk/ not to miss what I publish on Linkedin, Github, blog, and more.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

FortiOS 网络安全 防火墙 GUI API SD-WAN SSL Zero Trust 网络管理
相关文章