12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Switch (<strong>FortiGate</strong>-224B only)<br />

Configuring port quarantine<br />

Viewing client profiles<br />

• Quarantine the switch port to which the user is connected. Allow a re-check of<br />

the <strong>com</strong>puter after installing or activating the required software. For<br />

information about quarantine, see “Configuring dynamic policies” on page 224.<br />

• Dynamic profile. Provide access to the network using a specified protection<br />

profile. The <strong>FortiGate</strong>-224B unit applies antivirus scanning, IPS and content<br />

filtering as specified in the protection profile. Optionally, you can make the<br />

client’s port a secure port. It is then subject to firewall policies. For information<br />

about dynamic policies, see “Viewing access policies” on page 222.<br />

• Allow. Permit network access in spite of failed host check.<br />

The <strong>FortiGate</strong>-224B host check uses an ActiveX control to determine the security<br />

of the client <strong>com</strong>puter. When the user connects to the port with a web browser, the<br />

ActiveX control is downloaded and checks the client system’s AV software,<br />

firewall software and operating system, depending on the detection settings.<br />

Go to Switch > Port Quarantine > Client Profile to configure access control host<br />

checks.<br />

Figure 132:Client profile list<br />

Configuring a client profile<br />

Create New Create a new client profile. See “Configuring a client profile” on page 221.<br />

Name The name of the client profile.<br />

Detect Items The types of host check this profile includes: Antivirus (AV), Firewall, OS<br />

check. See “Configuring a client profile” on page 221.<br />

Delete icon Delete the profile. You cannot delete a profile that is used in a Strict or<br />

Dynamic policy.<br />

Edit icon Edit the profile.<br />

Go to Switch > Port Quarantine > Client Profile and select Create New to<br />

create a client profile or select the Edit icon of an existing profile to modify it.<br />

Figure 133:Configuring a client profile<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 221

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!