Fortigate 200D Deployment & VPN
Budget: $30 – $250 AUD
I have an existing Fortigate 200D with my ISP’s modem already patched into WAN1. What I need now is a clean, production-ready configuration that lets 11-20 Mac workstations + some phones plug into the LAN ports, talk to one another for screen sharing and file transfers, and reach the internet without hiccups. We used this Fortigate previously at our old office so it still has some things configured, ideally all that will be required is changing the IPs.
The second part of the job is enabling secure remote access: an SSL VPN that will let me log in from outside the office and reach any of those Macs as if I were on-site.
Here’s the flow I have in mind:
• Initial setup and firmware check
• Basic WAN1 settings (static or DHCP from the modem—will confirm)
• Internal interface (or VLANs if you feel it’s cleaner) with DHCP and split-horizon DNS so hostnames resolve inside the LAN
• Firewall/NAT policies that keep everyday browsing smooth yet block obvious threats
• SSL VPN portal and user group, tested end-to-end on macOS (FortiClient)
• Access will be granted via screenshare with a laptop physically plugged in to the Lan2 port, nothing else is configured yet.
I’ll give you remote access to the Fortigate and modem details. The hand-off is complete when:
1. Any LAN machine reaches the web and other Macs by hostname.
2. I can connect via SSL VPN from outside and do the same.
3. You drop a short text file summarising the key settings, just in case I need to rebuild.
If that checklist sounds straightforward, let’s get it done. (This should be pretty trivial if you've set up a Fortigate before, which would be ideal).
The second part of the job is enabling secure remote access: an SSL VPN that will let me log in from outside the office and reach any of those Macs as if I were on-site.
Here’s the flow I have in mind:
• Initial setup and firmware check
• Basic WAN1 settings (static or DHCP from the modem—will confirm)
• Internal interface (or VLANs if you feel it’s cleaner) with DHCP and split-horizon DNS so hostnames resolve inside the LAN
• Firewall/NAT policies that keep everyday browsing smooth yet block obvious threats
• SSL VPN portal and user group, tested end-to-end on macOS (FortiClient)
• Access will be granted via screenshare with a laptop physically plugged in to the Lan2 port, nothing else is configured yet.
I’ll give you remote access to the Fortigate and modem details. The hand-off is complete when:
1. Any LAN machine reaches the web and other Macs by hostname.
2. I can connect via SSL VPN from outside and do the same.
3. You drop a short text file summarising the key settings, just in case I need to rebuild.
If that checklist sounds straightforward, let’s get it done. (This should be pretty trivial if you've set up a Fortigate before, which would be ideal).