12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Firewall Policy<br />

Configuring firewall policies<br />

Configuring firewall policies<br />

Use firewall policies to define how a firewall policy is selected to be applied to a<br />

<strong>com</strong>munication session and to define how the <strong>FortiGate</strong> unit process the packets<br />

in that <strong>com</strong>munication session.<br />

To add or edit a firewall policy go to Firewall > Policy.<br />

You can add ACCEPT policies that accept <strong>com</strong>munication sessions. Using an<br />

accept policy you can apply <strong>FortiGate</strong> features such as virus scanning and<br />

authentication to the <strong>com</strong>munication session accepted by the policy. An ACCEPT<br />

policy can enable interface-mode IPSec VPN traffic if either the source or the<br />

destination is an IPSec virtual interface. For more information, see “Overview of<br />

IPSec interface mode” on page 343.<br />

You can add DENY policies to deny <strong>com</strong>munication sessions.<br />

You can also add IPSec encryption policies to enable IPSec tunnel mode VPN<br />

traffic and SSL VPN encryption policies to enable SSL VPN traffic. Firewall<br />

encryption policies determine which types of IP traffic will be permitted during an<br />

IPSec or SSL VPN session. If permitted by the firewall encryption policy, a tunnel<br />

may be initiated automatically whenever an IP packet of the specified type arrives<br />

at the <strong>FortiGate</strong> interface to the local private network. For more information, see<br />

“IPSec firewall policy options” on page 280 and/or “SSL-VPN firewall policy<br />

options” on page 281.<br />

Figure 166:Policy options - NAT/Route mode ACCEPT policy<br />

The source and destination Interface/Zone match the firewall policy with the<br />

source and destination of a <strong>com</strong>munication session. The Address Name matches<br />

the source and destination address of the <strong>com</strong>munication session<br />

Schedule defines when the firewall policy is enabled.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 271

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!