12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Firewall Policy<br />

Viewing the firewall policy list<br />

Figure 164:Sample policy list<br />

Filter<br />

Delete Edit<br />

Insert Policy Before<br />

Move To<br />

The policy list displays the following information. Note that some of the columns<br />

are not displayed by default. Use Column Settings to add or remove table<br />

columns.<br />

Create New<br />

Column Settings<br />

Filter icon<br />

ID<br />

Source<br />

Destination<br />

Schedule<br />

Service<br />

Profile<br />

Action<br />

Status<br />

From<br />

To<br />

VPN Tunnel<br />

Authentication<br />

Comments<br />

Label<br />

Log<br />

Select to add a firewall policy. See “Adding a firewall policy”<br />

on page 270. Select the down arrow beside Create New to<br />

choose to either add a firewall policy or firewall policy section.<br />

A firewall policy section is a way of grouping firewall policies.<br />

Select to customize the table view. You can select the<br />

columns to show and specify the column displaying order in<br />

the table.<br />

By default, the Status, From, To, VPN Tunnel, Authentication,<br />

Comments, Label, Count, Log and Index columns are not<br />

displayed.<br />

Select to edit the column filters, which allow you to filter or<br />

sort the policy list according to the criteria you specify. For<br />

details, see “Adding filters to web-based manager lists” on<br />

page 43.<br />

The policy identifier. Policies are numbered in the order they<br />

are added to the policy list.<br />

The source address or address group to which the policy<br />

applies. See “Firewall Address” on page 289. Address<br />

information can also be edited from the policy list. Clicking on<br />

the address opens the Edit Address dialog box.<br />

The destination address or address group to which the policy<br />

applies. See “Firewall Address” on page 289. Address<br />

information can also be edited from the policy list. Clicking on<br />

the address opens the Edit Address dialog box.<br />

The schedule that controls when the policy should be active.<br />

See “Firewall Schedule” on page 301.<br />

The service to which the policy applies. See “Firewall<br />

Service” on page 293.<br />

The protection profile that is associated with the policy.<br />

The response to make when the policy matches a connection<br />

attempt.<br />

Either enabled or disabled.<br />

The source interface.<br />

The destination interface.<br />

The VPN tunnel the VPN policy uses.<br />

The user authentication method the policy uses.<br />

Comments entered when creating or editing the policy.<br />

The firewall section title.<br />

A green check mark indicates traffic logging is enable for the<br />

policy; a grey cross mark indicates traffic logging is disabled<br />

for the policy.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 269

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!