Direkt zum Inhalt

Fortinet Firewall Provision Best Practice

0

We are looking at setting up a pair of Fortinet firewalls hosted on EC2. These will be exposed to the Internet. Is it best practice to put these behind a public facing network load balancer?

1 Antwort
2
Akzeptierte Antwort

It depends on what you want the firewalls to do. I'm opinionated about this topic (and you can hear my opinions in the AWS Podcast) - I think that firewalls should definitely not be "front line" - they should be somewhere behind the load balancers and perhaps even behind the workloads.

In general (and this is not a dig at Fortinet who make excellent products) firewalls are expensive and don't scale as quickly as traffic patterns (particularly during a DDoS) require. So using the cloud-native components (such as CloudFront and WAF) is better; and then put the firewalls "later" in the network path to do what they are best at - looking for specific and detailed attack vectors.

EXPERTE

beantwortet vor 2 Jahren

EXPERTE

überprüft vor 2 Jahren

EXPERTE

überprüft vor 2 Jahren

  • Thanks for your answer. We're going for Fortinet FWs to use their SD-WAN feature, allowing us to hook our AWS environment into our on-prem network. Agree with your analysis that a DDoS could potentially cripple this connectivity

  • Security Groups are a good way of protecting the firewalls - you can restrict ports/protocols and IP addresses. That's kind of the opposite of what SD-WAN is intended to do; but if you are building out a network where you know the SD-WAN endpoints it means that only the traffic from those endpoints will reach the firewalls.

  • Intresting point Brett on the scaling. All AWS examples for NGFW are usually being a GWLB and in front of the ALB. Im going to listen to your postcast you have supplied in the link..

Du bist nicht angemeldet. Anmelden um eine Antwort zu veröffentlichen.

Eine gute Antwort beantwortet die Frage klar, gibt konstruktives Feedback und fördert die berufliche Weiterentwicklung des Fragenstellers.