配置举例:到互联网的多重连接

NAT/ 路由 模式安装

 

 

只有您已经定义了类似于在前面章节中描述的目的路由之后,在这些例子中描述的 策略路由才能正常工作。

·将通讯从内部子网路由到不同的外部网络 ·路由到外部网络的服务

关于策略路由的详细信息,请见 第 122 页 策略路由

将通讯从内部子网路由到不同的外部网络

如果 FortiGate 提供了从多个内部子网到互联网的访问,您可以使用策略路由控制 从各个内部子网到互联网的通讯的路由。例如,如果内部网络包含了 192.168.10.0 子 网和 192.168.20.0 子网,您可以输入如下策略路由:

1 输入以下命令路由从 192.168.10.0 子网到外部网络 100.100.100.0 的通讯:

set system route policy 1 src 192.168.10.0 255.255.255.0 dst 100.100.100.0 255.255.255.0 gw 1.1.1.1

2 输入以下命令路由从 192.168.20.0 子网到外部网络 200.200.200.0 的通讯:

set system route policy 2 src 192.168.20.0 255.255.255.0 dst 200.200.200.0 255.255.255.0 gw 2.2.2.1

路由到外部网络的服务

您可以使用以下策略路由将所有 HTTP 通讯 (使用 80 端口)定向到一个外部网络, 而将其他的全部通讯定向到另一个外部网络。

1 输入以下命令将使用 80 端口的全部 HTTP 通讯路由到 IP 地址为 1.1.1.1 的网关。

set system route policy 1 src 0.0.0.0 0.0.0.0 dst 0.0.0.0 0.0.0.0 protocol 6 port 1 1000 gw 1.1.1.1

2 输入以下命令将其他的全部通讯路由到 IP 地址为 2.2.2.1 的网关。

Set system route policy 2 src 0.0.0.0 0.0.0.0 dst 0.0.0.0 0.0.0.0 gw 2.2.2.1

防火墙策略举例

防火墙策略控制着通过 FortiGate 设备的通讯流。一旦配置了到互联网的多重连接 的路由,您需要创建对应的防火墙策略,控制允许通过 FortiGate 设备的通讯,以及 允许通讯使用的接口。

为了使从内部网络发出的通讯能够通过两个互联网连接线路连接到互联网,您必须 添加从内部接口到每个带有互联网连接的接口的冗余策略。添加完策略之后,路由配 置可以控制使用哪个到互联网的连接。

添加冗余的默认策略

第 40 页 图 9 显示了 FortiGate 设备使用外部和 DMZ 连接到互联网的例子。默 认的策略允许全部的通讯从内部网络通过外部接口连接到互联网。如果您添加了一个 类似的从内部网络到 DMZ 接口的策略列表,这一策略将允许所有通讯从内部网络通过 DMZ 接口连接到互联网。在防火墙配置中添加了这两个策略之后,路由配置可以决定从 内部网络到互联网的连接实际使用哪条到互联网的线路。关于默认策略的详细信息, 请见 第 144 页 默认防火墙配置.

44

美国飞塔有限公司

Page 56
Image 56
Fortinet 500 manual 防火墙策略举例, 添加冗余的默认策略, ·将通讯从内部子网路由到不同的外部网络 ·路由到外部网络的服务

500 specifications

Fortinet 500 is a next-generation firewall (NGFW) that is part of Fortinet's acclaimed FortiGate family, designed to provide advanced security for medium to large enterprises. This appliance is known for its high performance, flexibility, and ability to protect networks from a variety of cyber threats through its robust features and technologies.

One of the main features of the Fortinet 500 is its integrated security capabilities. It combines multiple security functions into a single device, allowing organizations to manage everything from intrusion prevention and antivirus to web filtering and application control. This integration leads to simplified management and increased efficiency, as users can address multiple security needs without deploying multiple devices.

The Fortinet 500 runs on the FortiOS operating system, which is known for its simplicity and user-friendliness. FortiOS provides a centralized management interface that allows for the easy configuration and monitoring of security policies across the entire network. Additionally, the Fortinet management tools, such as FortiManager and FortiAnalyzer, enable detailed insights and reporting capabilities, helping organizations stay compliant with their security mandates.

Another characteristic that sets Fortinet 500 apart is its advanced threat intelligence, powered by the FortiGuard Labs. This global threat intelligence system continuously updates the firewall with the latest threat signatures and attack vectors, ensuring that organizations stay ahead of emerging threats. The firewall also employs machine learning and artificial intelligence to detect and mitigate sophisticated attacks in real-time.

Performance is crucial in any security appliance, and the Fortinet 500 does not disappoint. With hardware acceleration and purpose-built security processors, it delivers high throughput levels, enabling organizations to maintain productivity without sacrificing security. This level of performance is particularly beneficial in environments with heavy traffic and bandwidth demands.

In addition to these core features, the Fortinet 500 supports seamless integration with other security solutions within the Fortinet Security Fabric. This comprehensive approach allows for greater visibility and control over the entire security posture of an organization.

Overall, the Fortinet 500 is a powerful NGFW that offers a blend of advanced security features, ease of management, top-notch performance, and robust threat intelligence. Its ability to adapt to the ever-evolving landscape of cybersecurity makes it a valuable asset for businesses seeking to safeguard their digital assets and ensure seamless network operation.