12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Viewing the firewall policy list<br />

Firewall Policy<br />

Count<br />

Delete icon<br />

Edit icon<br />

Insert Policy Before icon<br />

Move To icon<br />

The <strong>FortiGate</strong> unit counts the number of packets and bytes a<br />

firewall policy is hit.<br />

For example, 5/50B means that a total of five packets and 50<br />

bytes has hit the policy.<br />

The counter is reset when the <strong>FortiGate</strong> unit is restarted or<br />

the policy is deleted and re-configured.<br />

Select to delete the policy from the list.<br />

Select to open the policy for editing.<br />

Select to add a new policy above the corresponding policy<br />

(the New Policy screen appears).<br />

Select to move the corresponding policy before or after<br />

another policy in the list. See “Moving a policy to a different<br />

position in the policy list” on page 270.<br />

Adding a firewall policy<br />

Use the following steps to add a firewall policy to a firewall policy list.<br />

1 Go to Firewall > Policy.<br />

2 Select Create New or select the Insert Policy before icon beside a policy in the list<br />

to add the new policy above that policy.<br />

3 Select the source and destination interfaces.<br />

4 Select the source and destination addresses.<br />

5 Configure the policy.<br />

For information about configuring policies, see “Configuring firewall policies” on<br />

page 271.<br />

6 Select OK.<br />

7 Arrange policies in the policy list so they have the expected results.<br />

For information about arranging policies in a policy list, see “How policy matching<br />

works” on page 268 and “Moving a policy to a different position in the policy list”.<br />

Moving a policy to a different position in the policy list<br />

You can move a policy in the list to influence how policies are evaluated. When<br />

more than one policy has been defined for the same interface pair, the policy that<br />

is first in the list is evaluated first.<br />

The ordering of firewall encryption policies is important to ensure that they take<br />

effect as expected—firewall encryption policies must be evaluated before regular<br />

firewall policies.<br />

Moving a policy in the list does not change its policy ID number.<br />

Figure 165:Move Policy<br />

1 Go to Firewall > Policy.<br />

2 Select the Move To icon in the row beside the policy that you want to move.<br />

3 Specify the position for the policy.<br />

4 Select OK.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

270 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!