Fortinet white logo
Fortinet white logo

Preparing the network

Preparing the network

Creating a virtual network

Create a virtual network and add several subnets for FortiDeceptor management and deployment.

To create a virtual network:
  1. Create a Virtual Network.
    1. In the portal menu, click Virtual networks.

    2. In the Virtual Networks page, click Create.

    3. In the Basics tab, configure the network details.

      SubscriptionSelect a subscription from the dropdown.
      Resource groupSelect a resource group from the dropdown.
      NameEnter a name for the instance.
      RegionSelect a region from the dropdown.
  2. Create Subnets in the Virtual Network.
    1. Click the IP Addresses tab.
    2. Configure the IPv4 address space.
    3. Click Add subnet. The Add subnet pane opens.
    4. Configure the Subnet address range and click Add.

    5. (Optional) Add additional subnets. You can add up to six subnets.

    6. Click Review + Create. The virtual network is validated.
    7. Click Create. The virtual network is created.

Creating network security groups and rules

Create a network security group and add security rules for filtering network traffic to and from FortiDeceptor in a virtual network.

To create a network security group and add rules:

  1. From the Home page, click Create a resource.
  2. In the navigation menu, click Networking > Network security groups.

  3. In the toolbar, click Create. The Create network security group page opens.

  4. Configure the network security group settings and click Review + Create. The security group is validated.

  5. Click Create. The security group is created.
  6. Click Go to resource.

  7. In the menu go to Settings > Inbound security rules and click Add. The Add inbound security rule pane opens.

  8. Configure the Source, Source port ranges, and Destination port ranges, and click Add.
    SourceSelect a source from the dropdown.
    Source port rangesEnter the port source ranges.
    Destination port ranges

    Enter the destination port ranges.

    Tooltip

    Make sure to enable an inbound rule for port 22, 443 and 8443 for the client's first interface/port1 to manage FortiDeceptor cloud appliances. This is enables the FortiDeceptor Manager to communicate with the cloud clients.

    ProtocolSelect TCP.

  9. (Optional) Open additional ports. For example, you can enable port 443, 445, 80, and add other inbound/outbound rules as needed.

Preparing the network

Preparing the network

Creating a virtual network

Create a virtual network and add several subnets for FortiDeceptor management and deployment.

To create a virtual network:
  1. Create a Virtual Network.
    1. In the portal menu, click Virtual networks.

    2. In the Virtual Networks page, click Create.

    3. In the Basics tab, configure the network details.

      SubscriptionSelect a subscription from the dropdown.
      Resource groupSelect a resource group from the dropdown.
      NameEnter a name for the instance.
      RegionSelect a region from the dropdown.
  2. Create Subnets in the Virtual Network.
    1. Click the IP Addresses tab.
    2. Configure the IPv4 address space.
    3. Click Add subnet. The Add subnet pane opens.
    4. Configure the Subnet address range and click Add.

    5. (Optional) Add additional subnets. You can add up to six subnets.

    6. Click Review + Create. The virtual network is validated.
    7. Click Create. The virtual network is created.

Creating network security groups and rules

Create a network security group and add security rules for filtering network traffic to and from FortiDeceptor in a virtual network.

To create a network security group and add rules:

  1. From the Home page, click Create a resource.
  2. In the navigation menu, click Networking > Network security groups.

  3. In the toolbar, click Create. The Create network security group page opens.

  4. Configure the network security group settings and click Review + Create. The security group is validated.

  5. Click Create. The security group is created.
  6. Click Go to resource.

  7. In the menu go to Settings > Inbound security rules and click Add. The Add inbound security rule pane opens.

  8. Configure the Source, Source port ranges, and Destination port ranges, and click Add.
    SourceSelect a source from the dropdown.
    Source port rangesEnter the port source ranges.
    Destination port ranges

    Enter the destination port ranges.

    Tooltip

    Make sure to enable an inbound rule for port 22, 443 and 8443 for the client's first interface/port1 to manage FortiDeceptor cloud appliances. This is enables the FortiDeceptor Manager to communicate with the cloud clients.

    ProtocolSelect TCP.

  9. (Optional) Open additional ports. For example, you can enable port 443, 445, 80, and add other inbound/outbound rules as needed.