IP/MAC 绑定

防火墙配置

 

 

所有能正常连接到防火墙的数据包先在 IP/MAC 绑定列表中查找匹配的

IP/MAC 地址对。

例如,如果 IP 地址为 1.1.1.1 和 MAC 地址为 12:34:56:78:90:ab:cd 的 IP/MAC 地

址对已经添加到 IP/MAC 地址绑定列表了:

·一个 IP 地址为 1.1.1.1 ,MAC 地址为 12:34:56:78:90:ab:cd 的数据包将被允许连 接到防火墙

·一个 IP 地址为 1.1.1.1, 是使用了不同 MAC 地址的数据包将立即被丢弃,以防止 IP 欺骗攻击。

·一个使用了不同 IP 地址是 MAC 地址是 12:34:56:78:90:ab:cd 的数据包也将被丢 弃以防止 IP 欺骗。

·如果这个数据包的 IP 地址和 MAC 地址在 IP/MAC 地址绑定列表没有定义: ·如果 IP/MAC 绑定被设置为允许流通,则允许它连接到防火墙。

·如果 IP/AMC 绑定被设置为阻塞流通,那数据包将被阻塞。

添加 IP/MAC 地址

1 进入防火墙 > IP/MAC 绑定 > 静态 IP/MAC

2 单击新建以添加 IP 地址 /MAC 地址对。

3 输入 IP 地址和对应的 MAC 地址。

可以在同一个 MAC 地址上绑定多个 IP 地址。是不能把多个 MAC 地址绑定到同一个 IP 地址上。

然而,您可以为多个 MAC 地址设置 IP 地址为 0.0.0.0 的绑定。这意味着来自这些地 址的所有数据包可以匹配 IP/MAC 地址绑定列表。

类似地,您也可以为多个 IP 地址设置 MAC 地址为 00:00:00:00:00:00 的 IP 地址绑定。 这意味着所有来自这些 IP 地址的数据包可以匹配 IP/MAC 地址绑定列表。

4 为新的 IP/MAC 地址绑定对输入一个名字。

这个名字可以包含数字 (0-9),大写或者小写字(A-Z,a-z),以及特字符 - 和 _。不允许使用其它特字符和格符。

5 选择启用以启用这个 IP/MAC 地址对的 IP/MAC 地址绑定。

6 单击确定以保存这个 IP/MAC 地址对。

查看动态 IP/MAC 列表

1 进入 防火墙 > IP/MAC 绑定 > 动态 IP/MAC

启用 IP/MAC 地址绑定

!警告:保您在启用 IP/MAC 绑定之前经添加了您的管理员电脑的 IP/MAC 地址对。

1 进入防火墙 > IP/MAC 绑定 > 设置

2 选择启用通过防火墙的 IP/MAC 绑定可以启用对匹配防火墙策略的数据包的 IP/MAC 地

址绑定。

3 选择启用到防火墙的 IP/MAC 绑定可以启用对连接到 FortiGate 的数据包的 IP/MAC 地 址绑定。

168

美国飞塔有限公司

Page 180
Image 180
Fortinet 500 manual 添加 Ip/Mac 地址, 查看动态 Ip/Mac 列表, 启用 Ip/Mac 地址绑定, 168

500 specifications

Fortinet 500 is a next-generation firewall (NGFW) that is part of Fortinet's acclaimed FortiGate family, designed to provide advanced security for medium to large enterprises. This appliance is known for its high performance, flexibility, and ability to protect networks from a variety of cyber threats through its robust features and technologies.

One of the main features of the Fortinet 500 is its integrated security capabilities. It combines multiple security functions into a single device, allowing organizations to manage everything from intrusion prevention and antivirus to web filtering and application control. This integration leads to simplified management and increased efficiency, as users can address multiple security needs without deploying multiple devices.

The Fortinet 500 runs on the FortiOS operating system, which is known for its simplicity and user-friendliness. FortiOS provides a centralized management interface that allows for the easy configuration and monitoring of security policies across the entire network. Additionally, the Fortinet management tools, such as FortiManager and FortiAnalyzer, enable detailed insights and reporting capabilities, helping organizations stay compliant with their security mandates.

Another characteristic that sets Fortinet 500 apart is its advanced threat intelligence, powered by the FortiGuard Labs. This global threat intelligence system continuously updates the firewall with the latest threat signatures and attack vectors, ensuring that organizations stay ahead of emerging threats. The firewall also employs machine learning and artificial intelligence to detect and mitigate sophisticated attacks in real-time.

Performance is crucial in any security appliance, and the Fortinet 500 does not disappoint. With hardware acceleration and purpose-built security processors, it delivers high throughput levels, enabling organizations to maintain productivity without sacrificing security. This level of performance is particularly beneficial in environments with heavy traffic and bandwidth demands.

In addition to these core features, the Fortinet 500 supports seamless integration with other security solutions within the Fortinet Security Fabric. This comprehensive approach allows for greater visibility and control over the entire security posture of an organization.

Overall, the Fortinet 500 is a powerful NGFW that offers a blend of advanced security features, ease of management, top-notch performance, and robust threat intelligence. Its ability to adapt to the ever-evolving landscape of cybersecurity makes it a valuable asset for businesses seeking to safeguard their digital assets and ensure seamless network operation.