12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring dynamic policies<br />

Switch (<strong>FortiGate</strong>-224B only)<br />

Configuring dynamic policies<br />

The <strong>FortiGate</strong>-224B unit can protect the network from a potential security threat<br />

by moving the affected switch port to the quarantine VLAN. This isolates devices<br />

on that switch port from the rest of the network.<br />

The <strong>FortiGate</strong>-224B unit can quarantine a port for several different reasons:<br />

• The host <strong>com</strong>puter failed access host-check. For more information, see<br />

“Configuring port quarantine” on page 220.<br />

• The antivirus or IPS system triggered an alert based on the activity on the port.<br />

For more information, see “Configuring a dynamic policy” on page 224.<br />

• The administrator assigned the port to the quarantine VLAN<br />

From the quarantine VLAN, only the quarantine web portal and selected thirdparty<br />

URLs are accessible. All other URL requests are redirected to the web<br />

portal. The web portal provides downloadable FortiClient Host Security or other<br />

security software. Optionally, the user can request a new host-check. If the hostcheck<br />

passes, the port is removed from the quarantine VLAN.<br />

Viewing quarantine policies<br />

Go to Switch > Port Quarantine > Dynamic Policy to configure dynamic policies<br />

for the switch ports.<br />

Figure 136:Viewing Dynamic policies<br />

Name<br />

AV/IPS Alert<br />

Ports<br />

Quarantine Portal<br />

Client Profile<br />

Delete icon<br />

Edit icon<br />

The name of the dynamic policy.<br />

Shows whether antivirus (AV) and/or IPS protection are enabled in<br />

this dynamic policy. See “Configuring a dynamic policy” on<br />

page 224.<br />

The ports to which this policy applies.<br />

Lists the Quarantine web portal settings for this policy. See<br />

“Configuring a dynamic policy” on page 224.<br />

The name of the client profile. For more information, see<br />

“Configuring a client profile” on page 221.<br />

Delete this dynamic policy.<br />

Edit this dynamic policy.<br />

Configuring a dynamic policy<br />

Go to Switch > Port Quarantine > Dynamic Policy and select Create New to<br />

configure a dynamic policy. You can configure dynamic web portal page settings<br />

for selected switch ports.<br />

Note: A dynamic policy is effective only if there is a firewall policy for the port.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

224 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!