防火墙配置

 

 

服务

 

 

 

 

 

 

 

表 6: FortiGate 预定义的服务 ( 续 )

 

 

 

 

 

 

 

 

 

 

服务名称

内容

协议

端口

 

 

 

 

 

 

 

 

PPTP

点对点通道协议是一个允许组织结构通过公共

tcp

1723

 

 

 

网络上的私有通道拓展他们自己的网络的协

 

 

 

 

 

议。

 

 

 

 

 

 

 

 

 

 

QUAKE

流行的多人电脑游戏 Quake 的连接协议。

udp

26000,

 

 

 

 

 

27000,

 

 

 

 

 

27910,

 

 

 

 

 

27960

 

 

 

 

 

 

 

 

RAUDIO

用于实时多媒体音频流传输。

udp

7070

 

 

 

 

 

 

 

 

RLOGIN

用于远程登录到服务器的 Rlogin 服务。

tcp

513

 

 

 

 

 

 

 

 

RIP

路由信息协议是一个公共距离向量路由协议。

udp

520

 

 

 

 

 

 

 

 

SMTP

用于在互联网上的电子邮件服务器之间发送邮

tcp

25

 

 

 

件。

 

 

 

 

 

 

 

 

 

 

SNMP

简单网络管理协议是用于管理复杂网络的一组

tcp

161-162

 

 

 

协议。

 

 

 

 

 

udp

161-162

 

 

 

 

 

 

 

 

 

 

 

 

SSH

用于安全连接到一台电脑进行远程管理的 SSH

tcp

22

 

 

 

服务。

 

 

 

 

 

udp

22

 

 

 

 

 

 

 

 

 

 

 

 

SYSLOG

用于远程记录日志的系统日志服务。

udp

514

 

 

 

 

 

 

 

 

TALK

一种支持两个或多个用户之间交谈的协议。

udp

517-518

 

 

 

 

 

 

 

 

TCP

全部 TCP 端口。

tcp

0-65535

 

 

 

 

 

 

 

 

TELNET

连接到远程电脑运行命令的 Telnet 服务。

tcp

23

 

 

 

 

 

 

 

 

TFTP

微型文件传输协议,一个比 FTP 更简单的文件

udp

69

 

 

 

传输协议,没有安全功能。

 

 

 

 

 

 

 

 

 

 

UDP

全部的 UPD 端口。

udp

0-65535

 

 

 

 

 

 

 

 

UUCP

UNIX 到 UNIX 文件拷贝协议。一个简单的文件

udp

540

 

 

 

复制协议。

 

 

 

 

 

 

 

 

 

 

VDOLIVE

用于 VDO Live 多媒体数据流通讯。

tcp

7000-7010

 

 

 

 

 

 

 

 

WAIS

广域信息服务器。一种互联网搜索协议。

tcp

210

 

 

 

 

 

 

 

 

WINFRAME

两台运行 Windows NT 的电脑之间 WinFrame

tcp

1494

 

 

 

通讯的协议。

 

 

 

 

 

 

 

 

 

 

X-WINDOWS

X-Windows 服务器和 X-Windows 客户之间远

tcp

6000-6063

 

 

 

程通讯的协议。

 

 

 

 

 

 

 

 

 

访问定服务

如果需要创建一个含有不包括在预定义服务列表中的服务的策略,可以添加一个定 制的服务。

1 进入 防火墙 > 服务 > 定

2 单击

3 输入服务的。当您添加一个新的策略时,这个名字将出现在服务列表中。

这个名字可以包含数字 (0-9),大写或者小写字(A-Z,a-z),以及特字符 - 和 _。不允许使用其它特字符和格符。

4 选择服务使用的 协议 (可以是 TCP 或者 UDP)。

FortiGate-500 安装和配置指南

157

Page 169
Image 169
Fortinet 500 manual 访问定制服务, 157, 如果需要创建一个含有不包括在预定义服务列表中的服务的策略,可以添加一个定 制的服务。, 进入 防火墙 服务 定制。

500 specifications

Fortinet 500 is a next-generation firewall (NGFW) that is part of Fortinet's acclaimed FortiGate family, designed to provide advanced security for medium to large enterprises. This appliance is known for its high performance, flexibility, and ability to protect networks from a variety of cyber threats through its robust features and technologies.

One of the main features of the Fortinet 500 is its integrated security capabilities. It combines multiple security functions into a single device, allowing organizations to manage everything from intrusion prevention and antivirus to web filtering and application control. This integration leads to simplified management and increased efficiency, as users can address multiple security needs without deploying multiple devices.

The Fortinet 500 runs on the FortiOS operating system, which is known for its simplicity and user-friendliness. FortiOS provides a centralized management interface that allows for the easy configuration and monitoring of security policies across the entire network. Additionally, the Fortinet management tools, such as FortiManager and FortiAnalyzer, enable detailed insights and reporting capabilities, helping organizations stay compliant with their security mandates.

Another characteristic that sets Fortinet 500 apart is its advanced threat intelligence, powered by the FortiGuard Labs. This global threat intelligence system continuously updates the firewall with the latest threat signatures and attack vectors, ensuring that organizations stay ahead of emerging threats. The firewall also employs machine learning and artificial intelligence to detect and mitigate sophisticated attacks in real-time.

Performance is crucial in any security appliance, and the Fortinet 500 does not disappoint. With hardware acceleration and purpose-built security processors, it delivers high throughput levels, enabling organizations to maintain productivity without sacrificing security. This level of performance is particularly beneficial in environments with heavy traffic and bandwidth demands.

In addition to these core features, the Fortinet 500 supports seamless integration with other security solutions within the Fortinet Security Fabric. This comprehensive approach allows for greater visibility and control over the entire security posture of an organization.

Overall, the Fortinet 500 is a powerful NGFW that offers a blend of advanced security features, ease of management, top-notch performance, and robust threat intelligence. Its ability to adapt to the ever-evolving landscape of cybersecurity makes it a valuable asset for businesses seeking to safeguard their digital assets and ensure seamless network operation.