12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring port quarantine<br />

Switch (<strong>FortiGate</strong>-224B only)<br />

Viewing access policies<br />

Name<br />

Enter a name for the detection rule.<br />

Enable any of the following as needed:<br />

FortiClient AV Check Check that FortiClient Host Security is installed and running.<br />

FortiClient Firewall Check Check that the FortiClient Host Security firewall is enabled.<br />

Enable OS Check<br />

Check for operating system version. Select acceptable<br />

operating systems. For Windows XP and Windows 2000 you<br />

can select the minimum acceptable service pack.<br />

Third-Party AV Check<br />

Third-Party Firewall Check<br />

Go to Switch > Port Quarantine > Strict Policy to view, modify or create new<br />

access policies for switch ports. These policies perform host checking according<br />

to the selected profile and apply the selected action if the client fails the host<br />

check.<br />

Dynamic profile applies an existing protection profile to the user and monitors the<br />

port. The port is quarantined if a virus or other form of attack is detected.<br />

Figure 134:Viewing and editing access policies<br />

Check that one of the following products is installed:<br />

• Norton Internet Security 2006<br />

• Trend Micro PC-cillin<br />

• Mcafee<br />

• Sophos anti-virus (antivirus only)<br />

• Panda Platinum 2006 Internet Security<br />

• F-Secure<br />

• Secure Resolution (antivirus only)<br />

• Cat Computer Services<br />

• AHN LAB<br />

• Kaspersky<br />

• ZoneAlarm<br />

Name<br />

Client Profile<br />

Action<br />

Ports<br />

The name of this strict policy.<br />

The client profile (a set of host checks) that applies to this strict policy.<br />

Action if the client fails access host check.<br />

• Allow - access allowed anyway<br />

• Deny - no further access allowed<br />

• Quarantine - port is quarantined<br />

• Dynamic-Profile - user traffic to other VLANs is scanned according to<br />

the protection profile selected in the access policy<br />

The ports to which this strict policy applies.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

222 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!