Comprehensive Fortinet Security Remediation & Upgrade

Job ID: 40469620

Budget: ₹37,500 – ₹75,000 INR

Job Title: Fortinet Security Expert Needed: FortiGate 601F Security Remediation & IKEv2 Migration
Project Overview:
We are looking for an expert to execute a comprehensive perimeter security remediation and VPN architecture upgrade based on a recent security audit.

Target Environment:

Hardware: FortiGate 601F High Availability (Active-Passive) Cluster

Firmware: FortiOS 7.4.x

Scale: 1 HQ, 6 Branch Locations (Dynamic IPs), ~600 Remote Users

Scope of Work:

Phase 1: Attack Surface Reduction & VIP Hardening

VIP Cleanup: Remove risky Virtual IPs (VIPs) exposing internal SSH (Port 22) and internal IoT/biometric devices to the WAN. Re-route this traffic over existing internal Site-to-Site VPNs.

Public Services Hardening: Harden essential public-facing VIPs (e.g., Mobile App APIs, Inbound Mail) by enforcing explicit port-forwarding, applying aggressive IPS profiles, and configuring Geo-IP fencing.

DDoS Mitigation: Leverage the NP7 hardware processors to implement baseline IPv4 DoS Anomaly policies in Monitor/Log-Only mode to establish a traffic baseline.

Phase 2: Branch Site-to-Site VPN Hardening

Current State: 6 branch locations (using dynamic IPs) are connected via IKEv1 IPsec tunnels using Aggressive Mode and deprecated SHA-1 hashing.

Remediation: Upgrade all 6 Phase 1/Phase 2 configurations to IKEv2 to natively support dynamic peers without exposing the PSK. Enforce modern cryptographic standards .

Phase 3: Remote Access Architecture Upgrade (SSL VPN to IKEv2)

Migration: Architect a new IKEv2 IPsec Remote Access infrastructure to replace the deprecated SSL VPN for 600 concurrent users. Deploy seamlessly alongside the legacy VPN for zero downtime. Include Geo-fencing Local-In policies.

Authentication Integration (NPS Build Required): Address the IKEv2 EAP-MSCHAPv2 requirement for Active Directory. The client does not currently have a RADIUS server. You will be required to install and configure the Windows Network Policy Server (NPS) role on their existing on-premise AD server, configure the RADIUS clients/policies, and integrate it with the FortiGate to support the new IKEv2 dial-up users.

Phase 4: High Availability (HA) Management Remediation

OOB Management: Configure dedicated Out-of-Band (OOB) HA Management interfaces on both the primary and secondary units using the Management Interface Reservation feature.

Routing: Establish independent routing tables for the management interfaces so the secondary node can successfully reach FortiGuard servers (to fix a current MFA/FortiToken validation failure). This will also serve as a disaster recovery path for split-brain scenarios.

Phase 5: Testing, Cutover & Documentation

Provide the validated XML connection profile or configuration parameters for internal endpoint distribution.

Provide standby pilot testing support for up to 5 users to validate backend routing and authentication. (Note: Internal IT will handle the mass deployment to all 600 endpoints).

Decommission legacy SSL VPN configurations post-migration.

Provide a brief technical handover summary.



Please provide a fixed-price proposal. In your proposal, please break down your pricing into two tiers:

Option 1: Execution of Phase 3 and Phase 5 only (Core Remote Access Migration).

Option 2: Execution of the complete project (Phases 1 through 5 - Full Secure Architecture Overhaul).