Configuring system settings
Before configuring system settings, enable the certificates feature.
To enable certificates:
- Go to System > Feature Visibility.
- Under Additional Features, enable Certificates, and click Apply.
To configure system settings:
- Go to System > Settings.
- Set Time zone to reflect the location of the FortiGate.
- Change HTTPS port from 443 to an uncommon port number, such as, 9443.
- For HTTPS server certificate, use automated certificate enrollment to leverage the ACME protocol with the Let’s Encrypt service.
- Use the dropdown next to HTTPS server certificate to select +Create.
- Select Use Let’s Encrypt.
- Provide an appropriate name for the certificate.
- Set Domain to the public FQDN of the FortiGate.
- Set Email to a valid email address.
- Select Create.
For further details on the process, see FortiOS 7.0 Administration Guide > ACME certificate support .
- Change the SSH port from 22 to an uncommon port number, such as, 9922.
- Ensure the Idle timeout is under 10 minutes. Five (5) minutes is recommended.
A setting of 10 minutes or less minimizes the amount of time administrators can remain logged in when away from their computer.
- Enable a password policy for admin with the minimum following values:
Password scope Admin Minimum length 8 Minimum number of new characters 0 Character requirements Enable Upper case 1 Lower case 1 Number (0-9)
1
Special 1 Allow password reuse Disable Password expiration
Disable
- Disable VLAN switch mode.
- Under Start Up Settings, disable Detect configuration.
- Disable Detect firmware.
- Click Apply.