By Manny Fernandez

February 12, 2019

Using Tags on the Fortigate Firewall

Tags are something that I have adopted into my workflow on most applications. I use Tags in Evernote, OmniFocus, macOS, this blog site, Fortigates, etc. Although, I would like to see Fortinet expand on ‘Tags’ this is what we have to work with today. Ideally, I would like to tag an address object, a policy, a route, VPN, etc. Then do a global search for all things ‘tagged’ with that tag.

Use case Example: VPN Tunnel

Create an address object for the local Phase II selector (possibly an address group)
Create an address object fort the remote Phase II selector (possibly an address group)
Create a VPN
Create the Static Routes (I only use ‘custom’ so the wizard does not create it for me)
Create an IPv4 Policy

With that said, Fortinte HAS done a great job implementing ‘tags’ on FortiOS. Minimum version is 6.0.

Fortinet’s implementation allows you to create a ‘Category’ for tags. In my example, I am using Location, Network, and Manager.

Location COULD identify what IDF, Building, Campus, etc.
Network COULD identify VLAN information, Subnets, Named LAN objects, etc.
Manager COULD identify the owner of the device (e.g. Manny Fernandez, Omar Ortiz, etc). You will see where this is useful.

Obviously, you can choose your own names that make sense in your environment.

Lets get started.

To get to the ‘Tags’ Section, go to ‘System’ then ‘Tags

Here you can see the blank screen that allows you to define you selections.

Here you can see the ‘Location’. I opted for IDF (Intermediate Distribution Frame) and MDF (Main Distribution Frame) locations. However, as stated before, you can use anything you like.

Now ‘Networks’ which tell you what type of network element it is (e.g. Security Cameras, AV, Servers, etc)

Manager is the next section. This is useful to identify devices and networks that belong to Police Department, Fire Department, Water and Sewage etc. It can identify who needs to be contacted in case something is identified.

Now we will start tagging devices. Here we can see a PS4. I have tagged it with the ‘Location’ of ‘IDF3-South’ as well as the ‘Manager’ which in my example is ‘Manny

Next we see my MacBook Pro. On this one, I have identified it as being in the MDF and managed by me.

Now for the interesting part. Under ‘Security Fabric’ you can see your devices on the LANs as well as your access layer devices (switches and APs).

You will be able to hover over a device and it will not only show you the AD Avatar for the user logged into the device, the MAC address(s) of the device, the physical port and switch it is plugged into, or the Wireless Access Point & SSID, Vulnerabilities, Bytes used, Sessions, and tags.

That is a wrap for ‘Tagging’ on FortiOS 6.x. Hopefully Fortinet will continue to enhance the tagging capabilities of FortiOS.

Hope this helps

Recent posts

  • If you've spent any time configuring user authentication on... Full Story

  • DNS is one of those technologies that quietly underpins... Full Story

  • BGP issues on FortiGate firewalls usually trace back to... Full Story

  • Every time your laptop talks to your router, a... Full Story

  • If you've spent any time configuring NAT on a... Full Story

  • If you have spent any time configuring firewall policies... Full Story

  • High availability on FortiGate is one of those features... Full Story

  • If you've configured SD-WAN on a FortiGate, you've almost... Full Story

  • FortiLink is the management protocol that turns a FortiSwitch... Full Story

  • FortiSwitches are pretty rock solid from Mean Time Between... Full Story

  • This is a quicky tip.  Have you ever gone... Full Story

  • DNS is one of those quiet pieces of internet... Full Story

  • This article is an updated version of the previous... Full Story

  • You will add ns2 as a secondary (slave) BIND9... Full Story

  • In the process of deploying my lab, I needed... Full Story

  • RFC 8805, used to be known as Self-Correcting IP... Full Story

  • Years back, I wrote an article about certificate pinning. ... Full Story

  • FortiGates have the ability to send alerts to Microsoft... Full Story

  • In this post, I am going to walk through... Full Story

  • Troubleshooting VoIP on a FortiGate can feel like trying... Full Story

  • Prior to FortiOS 7.0, there were three commands to... Full Story

  • In this post, I am going to go over... Full Story

  • What we are going to do:  We are going... Full Story

  • Choosing between FGCP (FortiGate Clustering Protocol) and FGSP (FortiGate... Full Story

  • Creating a VLAN on macOS (The "Pro" Move) A... Full Story

  • This blog post explores the logic behind how macOS... Full Story

  • Pretty Fly for a Wi-Fi Tell My Wi-Fi Love... Full Story

  • Part of my daily gig is creating BoMs (Bill-of-Materials)... Full Story

  • ICMP introduces several security risks, but careful filtering, rate... Full Story

  • The command diag debug application dhcps -1 enables full... Full Story

  • In the world of FortiOS, execute tac report is... Full Story

  • LLDP; What is it The Link Layer Discovery Protocol... Full Story

  • What it actually does When you run diagnose fdsm... Full Story

  • Monkey Bites are bite-sized, high-impact security insights designed for... Full Story

  • I have run macOS in macOS with Parallels but... Full Story

  • Don't be confused with my other FortiNAC posts where... Full Story

  • This is the third session in a multi-part article... Full Story

  • Today I was configuring key-based authentication on a FortiGate... Full Story

  • Netcat, often called the "Swiss Army knife" of networking,... Full Story

  • At its core, IEEE 802.1X is a network layer... Full Story

  • In case you did not see the previous FortiNAC... Full Story

  • This is our 5th session where we are going... Full Story

  • Now that we have Wireshark installed and somewhat configured,... Full Story

  • The Philosophy of Packet Analysis Troubleshooting isn't about looking... Full Story

  • 1. High-Level Overview The FortiGate Wireless Intrusion Detection System... Full Story

  • What MIMO Actually Does Multiple Input, Multiple Output (MIMO)... Full Story

  • A practitioner's tour of the diagnose, test, and fnsysctl... Full Story