Preparing the network
Creating a virtual network
Create a virtual network and add several subnets for FortiDeceptor management and deployment.
To create a virtual network:
- Create a Virtual Network.
- In the portal menu, click Virtual networks.
- In the Virtual Networks page, click Create.
- In the Basics tab, configure the network details.
Subscription Select a subscription from the dropdown. Resource group Select a resource group from the dropdown. Name Enter a name for the instance. Region Select a region from the dropdown.
- Create Subnets in the Virtual Network.
- Click the IP Addresses tab.
- Configure the IPv4 address space.
- Click Add subnet. The Add subnet pane opens.
- Configure the Subnet address range and click Add.
- (Optional) Add additional subnets. You can add up to six subnets.
- Click Review + Create. The virtual network is validated.
- Click Create. The virtual network is created.
Creating network security groups and rules
Create a network security group and add security rules for filtering network traffic to and from FortiDeceptor in a virtual network.
To create a network security group and add rules:
- From the Home page, click Create a resource.
- In the navigation menu, click Networking > Network security groups.
- In the toolbar, click Create. The Create network security group page opens.
- Configure the network security group settings and click Review + Create. The security group is validated.
- Click Create. The security group is created.
- Click Go to resource.
- In the menu go to Settings > Inbound security rules and click Add. The Add inbound security rule pane opens.
- Configure the Source, Source port ranges, and Destination port ranges, and click Add.
Source Select a source from the dropdown. Source port ranges Enter the port source ranges. Destination port ranges Enter the destination port ranges.
Make sure to enable an inbound rule for port 22, 443 and 8443 for the client's first interface/port1 to manage FortiDeceptor cloud appliances. This is enables the FortiDeceptor Manager to communicate with the cloud clients.
Protocol Select TCP. - (Optional) Open additional ports. For example, you can enable port 443, 445, 80, and add other inbound/outbound rules as needed.