规划您的 FortiGate 设备的配置

开始

 

 

您所选择的操作模式决定了 FortiGate 的配置方式。FortiGate 有两种配置方式: NAT/ 路由模式 (默认),或者透明模式。

NAT/ 路由模式

在 NAT/ 模式,FortiGate 在网络中是可见的。此时它类似于路由器,所有的网络 接口连接到不同的子网中。在 NAT/ 路由模式下有以下接口可用:

·外部 是默认的连接到外部网络 (通常是互联网)的接口, ·内部 是连接到内部网络的接口,

·DMZ 是连接到 DMZ 网络的接口。

·如果您建立了 HA簇,HA 是用于连接其他 FortiGate-500 的接口。 ·接口 1 到 8 可以连接到其他网络上。

无论 FortiGate-500 工作在 NAT 模式或是路由模式,您都可以添加安全策略以控制 通过 FortiGate-500 的通讯连接。安全策略根据每个数据包的源地址、目的地址和服 务控制数据流。在 NAT 模式下,FortiGate 在将数据包发送到目的网络之前进行网络地 址转换。在路由模式下,不进行转换。

默认情况下,FortiGate 只有一个 NAT 模式的策略,它使内部网络中的用户可以安 全地从外部网络下载内容。如果您没有配置其他安全策略,其他的数据流都将被阻塞。

FortiGate-500 的 NAT/ 路由模式的一个比较典型的应用是作为私有网络和公共网 络之间的网关。在这种配置中,您可以创建 NAT 模式的策略以控制内部的私有网络和 外部的公共网络 (通常是互联网)之间的数据流通。

如果您安装了多个内部网络,例如除了内部私有网络之外还有 DMZ 网络,您也可以 添加从 DMZ 网络到内部或外部网络之间的路由模式策略。

图 4: NAT/ 路由模式网络配置的例子

具有多个外部网络连接的 NAT/ 路由模式

在 NAT/ 路由模式下,您可以为 FortiGate 设备配置到外部网络 (通常是互联网) 的多重冗余连接。例如,您可以创建以下配置:

·外部接口作为到外部网络 (通常是互联网)的默认接口。 ·接口 1 是到外部网络的冗余接口。 ·内部接口作为到内部网络的接口。

·DMZ 接口作为到 DMZ 网络的接口。

26

美国飞塔有限公司

Page 38
Image 38
Fortinet 500 manual 具有多个外部网络连接的 Nat/ 路由模式, Nat/ 路由模式网络配置的例子

500 specifications

Fortinet 500 is a next-generation firewall (NGFW) that is part of Fortinet's acclaimed FortiGate family, designed to provide advanced security for medium to large enterprises. This appliance is known for its high performance, flexibility, and ability to protect networks from a variety of cyber threats through its robust features and technologies.

One of the main features of the Fortinet 500 is its integrated security capabilities. It combines multiple security functions into a single device, allowing organizations to manage everything from intrusion prevention and antivirus to web filtering and application control. This integration leads to simplified management and increased efficiency, as users can address multiple security needs without deploying multiple devices.

The Fortinet 500 runs on the FortiOS operating system, which is known for its simplicity and user-friendliness. FortiOS provides a centralized management interface that allows for the easy configuration and monitoring of security policies across the entire network. Additionally, the Fortinet management tools, such as FortiManager and FortiAnalyzer, enable detailed insights and reporting capabilities, helping organizations stay compliant with their security mandates.

Another characteristic that sets Fortinet 500 apart is its advanced threat intelligence, powered by the FortiGuard Labs. This global threat intelligence system continuously updates the firewall with the latest threat signatures and attack vectors, ensuring that organizations stay ahead of emerging threats. The firewall also employs machine learning and artificial intelligence to detect and mitigate sophisticated attacks in real-time.

Performance is crucial in any security appliance, and the Fortinet 500 does not disappoint. With hardware acceleration and purpose-built security processors, it delivers high throughput levels, enabling organizations to maintain productivity without sacrificing security. This level of performance is particularly beneficial in environments with heavy traffic and bandwidth demands.

In addition to these core features, the Fortinet 500 supports seamless integration with other security solutions within the Fortinet Security Fabric. This comprehensive approach allows for greater visibility and control over the entire security posture of an organization.

Overall, the Fortinet 500 is a powerful NGFW that offers a blend of advanced security features, ease of management, top-notch performance, and robust threat intelligence. Its ability to adapt to the ever-evolving landscape of cybersecurity makes it a valuable asset for businesses seeking to safeguard their digital assets and ensure seamless network operation.