Comprehensive Fortinet Security Remediation & Upgrade
Budget: ₹37,500 – ₹75,000 INR
Job Title: Fortinet Security Expert Needed: FortiGate 601F Security Remediation & IKEv2 Migration
Project Overview:
We are looking for an expert to execute a comprehensive perimeter security remediation and VPN architecture upgrade based on a recent security audit.
Target Environment:
Hardware: FortiGate 601F High Availability (Active-Passive) Cluster
Firmware: FortiOS 7.4.x
Scale: 1 HQ, 6 Branch Locations (Dynamic IPs), ~600 Remote Users
Scope of Work:
Phase 1: Attack Surface Reduction & VIP Hardening
VIP Cleanup: Remove risky Virtual IPs (VIPs) exposing internal SSH (Port 22) and internal IoT/biometric devices to the WAN. Re-route this traffic over existing internal Site-to-Site VPNs.
Public Services Hardening: Harden essential public-facing VIPs (e.g., Mobile App APIs, Inbound Mail) by enforcing explicit port-forwarding, applying aggressive IPS profiles, and configuring Geo-IP fencing.
DDoS Mitigation: Leverage the NP7 hardware processors to implement baseline IPv4 DoS Anomaly policies in Monitor/Log-Only mode to establish a traffic baseline.
Phase 2: Branch Site-to-Site VPN Hardening
Current State: 6 branch locations (using dynamic IPs) are connected via IKEv1 IPsec tunnels using Aggressive Mode and deprecated SHA-1 hashing.
Remediation: Upgrade all 6 Phase 1/Phase 2 configurations to IKEv2 to natively support dynamic peers without exposing the PSK. Enforce modern cryptographic standards .
Phase 3: Remote Access Architecture Upgrade (SSL VPN to IKEv2)
Migration: Architect a new IKEv2 IPsec Remote Access infrastructure to replace the deprecated SSL VPN for 600 concurrent users. Deploy seamlessly alongside the legacy VPN for zero downtime. Include Geo-fencing Local-In policies.
Authentication Integration (NPS Build Required): Address the IKEv2 EAP-MSCHAPv2 requirement for Active Directory. The client does not currently have a RADIUS server. You will be required to install and configure the Windows Network Policy Server (NPS) role on their existing on-premise AD server, configure the RADIUS clients/policies, and integrate it with the FortiGate to support the new IKEv2 dial-up users.
Phase 4: High Availability (HA) Management Remediation
OOB Management: Configure dedicated Out-of-Band (OOB) HA Management interfaces on both the primary and secondary units using the Management Interface Reservation feature.
Routing: Establish independent routing tables for the management interfaces so the secondary node can successfully reach FortiGuard servers (to fix a current MFA/FortiToken validation failure). This will also serve as a disaster recovery path for split-brain scenarios.
Phase 5: Testing, Cutover & Documentation
Provide the validated XML connection profile or configuration parameters for internal endpoint distribution.
Provide standby pilot testing support for up to 5 users to validate backend routing and authentication. (Note: Internal IT will handle the mass deployment to all 600 endpoints).
Decommission legacy SSL VPN configurations post-migration.
Provide a brief technical handover summary.
Please provide a fixed-price proposal. In your proposal, please break down your pricing into two tiers:
Option 1: Execution of Phase 3 and Phase 5 only (Core Remote Access Migration).
Option 2: Execution of the complete project (Phases 1 through 5 - Full Secure Architecture Overhaul).
Project Overview:
We are looking for an expert to execute a comprehensive perimeter security remediation and VPN architecture upgrade based on a recent security audit.
Target Environment:
Hardware: FortiGate 601F High Availability (Active-Passive) Cluster
Firmware: FortiOS 7.4.x
Scale: 1 HQ, 6 Branch Locations (Dynamic IPs), ~600 Remote Users
Scope of Work:
Phase 1: Attack Surface Reduction & VIP Hardening
VIP Cleanup: Remove risky Virtual IPs (VIPs) exposing internal SSH (Port 22) and internal IoT/biometric devices to the WAN. Re-route this traffic over existing internal Site-to-Site VPNs.
Public Services Hardening: Harden essential public-facing VIPs (e.g., Mobile App APIs, Inbound Mail) by enforcing explicit port-forwarding, applying aggressive IPS profiles, and configuring Geo-IP fencing.
DDoS Mitigation: Leverage the NP7 hardware processors to implement baseline IPv4 DoS Anomaly policies in Monitor/Log-Only mode to establish a traffic baseline.
Phase 2: Branch Site-to-Site VPN Hardening
Current State: 6 branch locations (using dynamic IPs) are connected via IKEv1 IPsec tunnels using Aggressive Mode and deprecated SHA-1 hashing.
Remediation: Upgrade all 6 Phase 1/Phase 2 configurations to IKEv2 to natively support dynamic peers without exposing the PSK. Enforce modern cryptographic standards .
Phase 3: Remote Access Architecture Upgrade (SSL VPN to IKEv2)
Migration: Architect a new IKEv2 IPsec Remote Access infrastructure to replace the deprecated SSL VPN for 600 concurrent users. Deploy seamlessly alongside the legacy VPN for zero downtime. Include Geo-fencing Local-In policies.
Authentication Integration (NPS Build Required): Address the IKEv2 EAP-MSCHAPv2 requirement for Active Directory. The client does not currently have a RADIUS server. You will be required to install and configure the Windows Network Policy Server (NPS) role on their existing on-premise AD server, configure the RADIUS clients/policies, and integrate it with the FortiGate to support the new IKEv2 dial-up users.
Phase 4: High Availability (HA) Management Remediation
OOB Management: Configure dedicated Out-of-Band (OOB) HA Management interfaces on both the primary and secondary units using the Management Interface Reservation feature.
Routing: Establish independent routing tables for the management interfaces so the secondary node can successfully reach FortiGuard servers (to fix a current MFA/FortiToken validation failure). This will also serve as a disaster recovery path for split-brain scenarios.
Phase 5: Testing, Cutover & Documentation
Provide the validated XML connection profile or configuration parameters for internal endpoint distribution.
Provide standby pilot testing support for up to 5 users to validate backend routing and authentication. (Note: Internal IT will handle the mass deployment to all 600 endpoints).
Decommission legacy SSL VPN configurations post-migration.
Provide a brief technical handover summary.
Please provide a fixed-price proposal. In your proposal, please break down your pricing into two tiers:
Option 1: Execution of Phase 3 and Phase 5 only (Core Remote Access Migration).
Option 2: Execution of the complete project (Phases 1 through 5 - Full Secure Architecture Overhaul).