FortiGate 出厂默认设置

 

开始

 

 

 

 

 

表 3: 出厂默认的透明模式网络设置

 

 

 

 

 

 

 

Internal

HTTPS, Ping

 

 

External

Ping

 

 

DMZ

HTTPS, Ping

 

 

接口 1

Ping

 

 

接口 2

Ping

 

管理访问

接口 3

Ping

 

 

接口 4

Ping

 

 

接口 5

Ping

 

 

接口 6

Ping

 

 

接口 7

Ping

 

 

接口 8

Ping

 

 

 

 

出厂时默认的防火墙配置

NAT/ 路由模式和透明模式具有相同的出厂默认的防火墙配置。

表 4: 出厂默认防火墙设置

 

 

IP: 0.0.0.0

表示内部网络中的全部 IP 地址

内部地址

内部 _ 全部

 

 

掩码:

 

 

 

 

 

 

0.0.0.0

 

 

 

 

 

 

 

IP: 0.0.0.0

表示外部网络中的全部 IP 地址

外部地址

外部 _ 全部

 

 

掩码:

 

 

 

 

 

 

0.0.0.0

 

 

 

 

 

 

 

IP: 0.0.0.0

表示 DMZ 网络中的全部 IP 地址。

DMZ 地址

DMZ_ 全部

 

 

掩码:

 

 

 

 

 

 

0.0.0.0

 

 

 

 

 

环任务

总是

 

任务计划始终有效。这意味着防火墙策略始终有

计划

 

 

效。

 

 

 

 

防火墙策

内部 -> 外部

 

从内部网络到外部网络的防火墙策略

 

 

 

 

 

 

 

 

内部 _ 全部

策略的源地址。内部 _ 全部意味着策略接受来自任

 

 

 

何内部 IP 地址的连接请求。

 

 

 

 

 

目的

外部 _ 全部

策略的目的地址。外部 _ 全部意味着策略接受到外

 

 

 

部网络中的任何 IP 地址的连接请求。

 

 

 

 

 

任务计划

总是

策略的任务计划。 总是 意味着这个策略始终有效。

 

 

 

 

 

服务

任意

策略的服务。任意 意味着这个策略可以处理所有服

 

 

 

务类型的连接。

 

 

 

 

 

动作

接受

策略的动作。接受 意味着策略允许建立连接。

 

 

 

 

 

! NAT

 

NAT 在 NAT/ 路由模式的默认策略中被选中,以使得

 

 

 

策略对其处理的通讯进行网络地址转换。NAT 在透

 

 

 

明模式下不可用。

 

 

 

 

 

" 流量控制

 

流量控制未被选中。策略不会对其所控制的通讯应

 

 

 

用流量控制。您可以选中这一选项,以控制这一策

 

 

 

略所处理的通讯的最大或最小带宽。

 

 

 

 

22

美国飞塔有限公司

Page 34
Image 34
Fortinet 500 manual 出厂时默认的防火墙配置, Nat/ 路由模式和透明模式具有相同的出厂默认的防火墙配置。

500 specifications

Fortinet 500 is a next-generation firewall (NGFW) that is part of Fortinet's acclaimed FortiGate family, designed to provide advanced security for medium to large enterprises. This appliance is known for its high performance, flexibility, and ability to protect networks from a variety of cyber threats through its robust features and technologies.

One of the main features of the Fortinet 500 is its integrated security capabilities. It combines multiple security functions into a single device, allowing organizations to manage everything from intrusion prevention and antivirus to web filtering and application control. This integration leads to simplified management and increased efficiency, as users can address multiple security needs without deploying multiple devices.

The Fortinet 500 runs on the FortiOS operating system, which is known for its simplicity and user-friendliness. FortiOS provides a centralized management interface that allows for the easy configuration and monitoring of security policies across the entire network. Additionally, the Fortinet management tools, such as FortiManager and FortiAnalyzer, enable detailed insights and reporting capabilities, helping organizations stay compliant with their security mandates.

Another characteristic that sets Fortinet 500 apart is its advanced threat intelligence, powered by the FortiGuard Labs. This global threat intelligence system continuously updates the firewall with the latest threat signatures and attack vectors, ensuring that organizations stay ahead of emerging threats. The firewall also employs machine learning and artificial intelligence to detect and mitigate sophisticated attacks in real-time.

Performance is crucial in any security appliance, and the Fortinet 500 does not disappoint. With hardware acceleration and purpose-built security processors, it delivers high throughput levels, enabling organizations to maintain productivity without sacrificing security. This level of performance is particularly beneficial in environments with heavy traffic and bandwidth demands.

In addition to these core features, the Fortinet 500 supports seamless integration with other security solutions within the Fortinet Security Fabric. This comprehensive approach allows for greater visibility and control over the entire security posture of an organization.

Overall, the Fortinet 500 is a powerful NGFW that offers a blend of advanced security features, ease of management, top-notch performance, and robust threat intelligence. Its ability to adapt to the ever-evolving landscape of cybersecurity makes it a valuable asset for businesses seeking to safeguard their digital assets and ensure seamless network operation.