Week 6 Posting - Security Appliance in the Cloud

One of the most interesting network accomplishments I have completed in my career is getting a Fortigate firewall appliance provisioned in the cloud. Cloud security has not always been intuitive and there are many vulnerabilities that are exploited because systems are left exposed unintentionally. To overcome this challenge I decided to provision the same type of firewall we used on-premise in the cloud.

The challenge was provisioning the cloud appliance. Fortinet had images on their market that could be pulled for the appliance, but in the provisioning phase we needed to apply all the resources needed up front, including cores, memory, interfaces. We did have to do this a couple of times to get it right and figure out the ordering of deployment. Once the appliance was up it was only a matter of getting the Vnet tied to the appliance interfaces and set up routing tables to create defined internal and external networks. After it was completed we could build an IPSec tunnel from the cloud to our on-premise firewalls using the same technology and also create firewall rules within a platform that we were very familiar with. The final step we took was ensuring penetration tests of our systems showed no external access without being filtered and inspected by the cloud firewall.

Comments

Popular posts from this blog

Week 4 Posting - Subnetting in the Cloud

Week 5 Posting - VXLAN and Broadcast Security