12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Policy Route<br />

Router Static<br />

Adding a route policy<br />

Source The IP source addresses and network masks that cause policy routing to<br />

occur.<br />

Destination The IP destination addresses and network masks that cause policy routing to<br />

occur.<br />

Delete icon Select to delete a policy route.<br />

Edit icon Select to edit a policy route.<br />

Move To<br />

icon<br />

Select to move policy route up or down in the policy route table. Selecting<br />

this icon will bring up the Move Policy Route screen where you can specify<br />

the new location in the Policy Route table. See “Moving a route policy”.<br />

Route policy options define which attributes of a in<strong>com</strong>ing packet cause policy<br />

routing to occur. If the attributes of a packet match all the specified conditions, the<br />

<strong>FortiGate</strong> unit routes the packet through the specified interface to the specified<br />

gateway.<br />

To add a route policy, go to Router > Static > Policy Route and select Create<br />

New.<br />

Figure 150 shows the New Routing Policy dialog box belonging to a <strong>FortiGate</strong> unit<br />

that has interfaces named “external” and “internal”. The names of the interfaces<br />

on your <strong>FortiGate</strong> unit may be different.<br />

Figure 150:New Routing Policy<br />

Protocol<br />

To perform policy routing based on the value in the protocol field of<br />

the packet, type the protocol number to match. The range is from 0<br />

to 255. A value of 0 disables the feature.<br />

In<strong>com</strong>ing Interface Select the name of the interface through which in<strong>com</strong>ing packets<br />

subjected to the policy are received.<br />

Source Address /<br />

Mask<br />

Destination<br />

Address / Mask<br />

Destination Ports<br />

To perform policy routing based on the IP source address of the<br />

packet, type the source address and network mask to match. A value<br />

of 0.0.0.0/0.0.0.0 disables the feature.<br />

To perform policy routing based on the IP destination address of the<br />

packet, type the destination address and network mask to match. A<br />

value of 0.0.0.0/0.0.0.0 disables the feature.<br />

To perform policy routing based on the port on which the packet is<br />

received, type the same port number in the From and To fields. If you<br />

want policy routing to apply to a range of ports, type the starting port<br />

number in the From field and the ending port number in the To field.<br />

Zero values disable this feature.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

240 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!