Skip to content
DnsLister Forum

Where domain hunters compare notes

Title: Firewall policies configuration on FortiGate 60F for two remote MikroTik RB2011 sites (connected via Microwave / Wireless Link) and Active Directory

​

​Hi everyone,

​I'm currently managing a main site protected by a FortiGate 60F and two remote sites equipped with MikroTik RB2011 routers. The sites are interconnected via a Microwave (Wireless) link acting as a direct private routed connection (no public internet involved).

​I need to connect the two remote subnets to my main network so that:

​All machines can ping each other across sites.

​Remote machines can reach the main site's Active Directory controllers to join the domain and authenticate properly.

​What is the best approach for static routing and firewall policies on the FortiGate?

​Should I simply create network address objects for the remote subnets and allow specific Active Directory ports (DNS, Kerberos, SMB, LDAP, RPC, etc.) coming from the microwave interface towards my servers?

​Are there any specific pitfalls or best practices to keep in mind (e.g., disabling NAT, handling dynamic RPC ports, proper routing on the RB2011 side)?

​Any advice, configuration best practices, or sample setups would be greatly appreciated. Thanks!

Source: r/fortinet · by /u/Icy_Attorney_4692

Leave a Reply

Your email address will not be published. Required fields are marked *