日志和报告

配置通讯日志

 

 

类型

选择 会话或包。如果您选择了会话,FortiGate 设备将每个会话发送和接

 

收的包的数量。如果您选择了包,FortiGate 设备将记录每个会话的包的

 

平均长度 (以字节为单位)。

显示

如果您希望通讯日志消息列出端口号,例如,80/TCP,则选择端口号。如

 

果您希望通讯日志消息列出服务的名称,例如,TCP,则选择服务名称。

3 单击应用。

图 40: 通讯过滤列表的例子

添加通讯过滤的条目

 

在通讯过滤列表中添加条目可以过滤通讯日志记录的消息。如果您不在通讯过滤列

 

表中添加任何条目,FortiGate 记录所有的通讯日志消息。您可以在通讯过滤列表中添

 

加条目来限制通讯日志记录的内容。您可以选择记录来自某个指定源 IP 地址和网络

 

码、到某个指定目的地址和码以及某个特定类型服务的通讯日志。通讯过滤条目可

 

以包含源地址、目的地址和服务类型的任意组合。

 

以下步骤在通讯过滤列表中添加条目。

1

进入 日志和报告 > 日志设置 > 通讯过滤

2

单击新建。

 

3

配置通讯过滤,选择您希望通讯日志记录的通讯的类型。

 

名称

输入一个名称以识别这个通讯过滤条目。

 

 

名称可以包含数字 (0- 9),大写或小写字母 (A-Z, a-z),以及特殊字

 

 

符 - 和 _。不能使用其他特殊字符和空格。

 

源 IP 地址

输入您希望 FortiGate 设备记录通讯日志消息的源 IP 地址和网络掩

 

源网络

码。地址可以是一个独立的主机、一个子网或者一个网络。

 

目的 IP 地址

输入您希望 FortiGate 设备记录通讯日志消息的目的 IP 地址和网络

 

目的网络

掩码。地址可以是一个独立的主机、一个子网或者一个网络。

 

服务

选择您希望 FortiGate 设备记录的通讯日志消息的服务组或单独的服

 

 

务类型。

4

单击确定。

 

 

通讯过滤列表根据您在 第 246 页 启用通讯日志中选择的设置显示新的通讯地

 

址条目。

 

FortiGate-500 安装和配置指南

247

Page 259
Image 259
Fortinet 500 manual 添加通讯过滤的条目, 247, 进入 日志和报告 日志设置 通讯过滤 。

500 specifications

Fortinet 500 is a next-generation firewall (NGFW) that is part of Fortinet's acclaimed FortiGate family, designed to provide advanced security for medium to large enterprises. This appliance is known for its high performance, flexibility, and ability to protect networks from a variety of cyber threats through its robust features and technologies.

One of the main features of the Fortinet 500 is its integrated security capabilities. It combines multiple security functions into a single device, allowing organizations to manage everything from intrusion prevention and antivirus to web filtering and application control. This integration leads to simplified management and increased efficiency, as users can address multiple security needs without deploying multiple devices.

The Fortinet 500 runs on the FortiOS operating system, which is known for its simplicity and user-friendliness. FortiOS provides a centralized management interface that allows for the easy configuration and monitoring of security policies across the entire network. Additionally, the Fortinet management tools, such as FortiManager and FortiAnalyzer, enable detailed insights and reporting capabilities, helping organizations stay compliant with their security mandates.

Another characteristic that sets Fortinet 500 apart is its advanced threat intelligence, powered by the FortiGuard Labs. This global threat intelligence system continuously updates the firewall with the latest threat signatures and attack vectors, ensuring that organizations stay ahead of emerging threats. The firewall also employs machine learning and artificial intelligence to detect and mitigate sophisticated attacks in real-time.

Performance is crucial in any security appliance, and the Fortinet 500 does not disappoint. With hardware acceleration and purpose-built security processors, it delivers high throughput levels, enabling organizations to maintain productivity without sacrificing security. This level of performance is particularly beneficial in environments with heavy traffic and bandwidth demands.

In addition to these core features, the Fortinet 500 supports seamless integration with other security solutions within the Fortinet Security Fabric. This comprehensive approach allows for greater visibility and control over the entire security posture of an organization.

Overall, the Fortinet 500 is a powerful NGFW that offers a blend of advanced security features, ease of management, top-notch performance, and robust threat intelligence. Its ability to adapt to the ever-evolving landscape of cybersecurity makes it a valuable asset for businesses seeking to safeguard their digital assets and ensure seamless network operation.