12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Enabling switch view<br />

Switch (<strong>FortiGate</strong>-224B only)<br />

• Use access control to enforce security requirements on host <strong>com</strong>puters that<br />

connect to switch LAN ports. You can require hosts to run antivirus or firewall<br />

software and ensure that their operating system is up-to-date. There are<br />

several options, including quarantine, to address hosts that do not meet the<br />

requirements.<br />

• Create quarantine policies to isolate ports that trigger AV or IPS alerts.<br />

• Use IEEE 802.1X authentication on your network.<br />

There are also features to improve the operation of your network:<br />

• Spanning-Tree Protocol prevents network loops and provides reliable<br />

operation through path redundancy<br />

• IGMP snooping improves the efficiency of multicasting<br />

• Quality of Service (QoS) controls use of network bandwidth<br />

Enabling switch view<br />

You must enable switch view to make the switch features available and to enable<br />

you to create intra-VLAN firewall policies. You must use the CLI to enable switch<br />

view.<br />

To enable switch view<br />

In the CLI, enter the following <strong>com</strong>mands:<br />

config system global<br />

set switch-view enable<br />

end<br />

When asked if you want to continue, respond y. The system resets and restores<br />

factory default values. You might have to use the console to restore the<br />

appropriate IP address and enable administrative access for the web-based<br />

manager.<br />

To return to firewall mode, use the CLI <strong>com</strong>mands shown above, but set<br />

switch-view to disable.<br />

Viewing WAN ports and WAN VLAN interfaces<br />

<strong>FortiGate</strong>-224B WAN1 and WAN2 ports are the same as network interfaces on<br />

other <strong>FortiGate</strong> models. Go to System > Network > Interface to view and<br />

configure the WAN ports and WAN VLAN interfaces. See “Interface” on page 79.<br />

Note: Virtual Domain (VDOM) and Transparent mode do not apply to the <strong>FortiGate</strong>-224B.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

208 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!