防火墙配置

 

 

 

默认防火墙配置

 

 

 

 

 

 

要在区域中添加策略,您须使用以下步骤将区域添加到防火墙网格:

1

将区域添加到 FortiGate 配置。

 

请见

第 111 页 添加区域

2

将接口和 VLAN 子网络接口添加到这个区域。

 

请见

第 112 页 在区域中添加接口第 112 页 在区域中添加 VLAN 子

 

接口

 

 

3

为这个区域添加防火墙地址。

 

请见

第 152 页 添加地址

地址

 

 

 

 

 

 

要添加接口、VLAN 子接口和区域之间的策略,防火墙的配置中须包含每个接口、

 

VLAN 子接口和区域的地址。默认情况下 FortiGate 设备配置中包含的地址在表 5 中列

 

出。

 

 

 

 

 

表 5: 默认地址

 

 

 

 

 

 

 

 

 

接口

 

地址

 

 

 

 

 

 

 

 

内部

 

内部 _ 全部

这个地址匹配于内部网络的全部地址

 

 

 

 

 

 

 

 

外部

 

外部 _ 全部

这个地址匹配于外部网络的全部地址

 

 

 

 

 

 

 

 

DMZ

 

DMZ _ 全部

这个地址匹配于 DMZ 网络的全部地址

 

 

 

 

 

 

 

防火墙使用这些地址匹配防火墙接收到的数据包的源地址和目的地址。默认的策略 匹配从内部网络来的全部连接,因为它包含了内部 _ 全部 地址。默认策略也匹配到外 部网络的全部连接,因为它包含了 外部 _ 全部 地址。

您可以在每个接口上添加更多的地址以增强您对通过防火墙的连接的控制能力。关 于防火墙地址的详细信息,请见 第 152 页 地址

您也可以添加提供网络地址转换 (NAT)功能的防火墙策略。要使用 NAT 转换目的 地址,须添加虚拟 IP。虚拟 IP 将一个网络中的地址映到另一个网络中的被转换的 地址上。关于虚拟 IP 的详细信息请见 第 162 页 虚拟 IP

服务

防火墙策略也可以根据数据包的服务或目的端口来控制连接。默认的策略接受使用 任何服务或目的端口的连接。防火墙配置中包含了 40 多个预定义的服务。您可以将这 些服务添加到策略中以提高对使用这些服务通过防火墙的连接的控制能力。您也可以 添加用户自定义的服务。关于服务的详细信息,请见 第 155 页 服务

任务计划

策略也可以根据防火墙收到的连接在一当中的时间或一周中的日子来控制连接。 默认的策略可以在任何时间接受连接。防火墙配置中包括了一个在任何时间接受连接 的任务计划。您可以添加更多的任务计划以控制策略生效的时间。关于任务计划的详 细信息,请见 第 159 页 任务计划

FortiGate-500 安装和配置指南

145

Page 157
Image 157
Fortinet 500 manual 任务计划, 145

500 specifications

Fortinet 500 is a next-generation firewall (NGFW) that is part of Fortinet's acclaimed FortiGate family, designed to provide advanced security for medium to large enterprises. This appliance is known for its high performance, flexibility, and ability to protect networks from a variety of cyber threats through its robust features and technologies.

One of the main features of the Fortinet 500 is its integrated security capabilities. It combines multiple security functions into a single device, allowing organizations to manage everything from intrusion prevention and antivirus to web filtering and application control. This integration leads to simplified management and increased efficiency, as users can address multiple security needs without deploying multiple devices.

The Fortinet 500 runs on the FortiOS operating system, which is known for its simplicity and user-friendliness. FortiOS provides a centralized management interface that allows for the easy configuration and monitoring of security policies across the entire network. Additionally, the Fortinet management tools, such as FortiManager and FortiAnalyzer, enable detailed insights and reporting capabilities, helping organizations stay compliant with their security mandates.

Another characteristic that sets Fortinet 500 apart is its advanced threat intelligence, powered by the FortiGuard Labs. This global threat intelligence system continuously updates the firewall with the latest threat signatures and attack vectors, ensuring that organizations stay ahead of emerging threats. The firewall also employs machine learning and artificial intelligence to detect and mitigate sophisticated attacks in real-time.

Performance is crucial in any security appliance, and the Fortinet 500 does not disappoint. With hardware acceleration and purpose-built security processors, it delivers high throughput levels, enabling organizations to maintain productivity without sacrificing security. This level of performance is particularly beneficial in environments with heavy traffic and bandwidth demands.

In addition to these core features, the Fortinet 500 supports seamless integration with other security solutions within the Fortinet Security Fabric. This comprehensive approach allows for greater visibility and control over the entire security posture of an organization.

Overall, the Fortinet 500 is a powerful NGFW that offers a blend of advanced security features, ease of management, top-notch performance, and robust threat intelligence. Its ability to adapt to the ever-evolving landscape of cybersecurity makes it a valuable asset for businesses seeking to safeguard their digital assets and ensure seamless network operation.