NAT/Route mode installation

Configuration example: Multiple connections to the Internet

 

 

Adding more firewall policies

In most cases your firewall configuration includes more than just the default policy. However, the basic premise of creating redundant policies applies even as the firewall configuration becomes more complex. To configure the FortiGate unit to use multiple Internet connections you must add duplicate policies for connections between the internal network and both interfaces connected to the Internet. As well, as you add redundant policies, you must arrange them in both policy lists in the same order.

Restricting access to a single Internet connection

In some cases you might want to limit some traffic to only being able to use one Internet connection. For example, in the topology shown in Figure 8 on page 53 the organization might want its mail server to only be able to connect to the SMTP mail server of ISP1. To do this, you add a single port1->port2 firewall policy for SMTP connections. Because redundant policies have not been added, SMTP traffic from the Internet network is always connected to ISP1. If the connection to ISP1 fails the SMTP connection is not available.

FortiGate-400 Installation and Configuration Guide

59

Page 59
Image 59
Fortinet 400 manual Adding more firewall policies, Restricting access to a single Internet connection