Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rolo
New Contributor

How to Open RDP on fortigate 40F

Hello I've tried several guides to open RDP on a fortigate but haven't managed to get success , Anyone can provide me the guide which works or if anyone has ready config to send me what am i missing.

4 REPLIES 4
boneyard
Valued Contributor

what do you mean with open RDP?

 

you want to access the FortiGate with RDP? you want to access a system behind the FortiGate with RDP? you want to access outside the FortiGate with RDP?

rolo
New Contributor

There is fortigate and after that fortigate is PC where windows 10 installed, so i want to access that PC from outside, so i want to open RDP on fortigate to have access on PC from different place.

boneyard
Valued Contributor

you create a virtual IP, which a public IP address on the external side and the IP address of the Windows 10 on the internal side.

 

use that virtual IP in a firewall policy from external to internal.

 

you probably only want to allow RDP traffic on the firewall policy

 

this is assuming that you have a public IP address on the FortiGate. if you haven't that you will have to do the forward on the ISP modem / router towards the FortiGate and then use the virtual IP

SmokeyMountian_Tech

boneyard wrote:

you create a virtual IP, which a public IP address on the external side and the IP address of the Windows 10 on the internal side.

 

use that virtual IP in a firewall policy from external to internal.

 

you probably only want to allow RDP traffic on the firewall policy

 

this is assuming that you have a public IP address on the FortiGate. if you haven't that you will have to do the forward on the ISP modem / router towards the FortiGate and then use the virtual IP

I would recommend using a non-standard port from WAN. EG incoming connection WANIP:103389 Mapped to 3389 in the Virtual IP setup.

Make sure you have a secure password.

If you know what IP's you'll connect from, only allow those IP's in your IPv4 policy.

If you can't do that, consider adding some GEO blocking to filter out other countries.

Labels
Top Kudoed Authors