12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Firewall Policy<br />

Configuring firewall policies<br />

Traffic Shaping<br />

User<br />

Authentication<br />

Disclaimer<br />

Redirect URL<br />

Comments<br />

Traffic Shaping controls the bandwidth available to, and sets the priority<br />

of the traffic processed by, the policy.<br />

• Be sure to enable traffic shaping on all firewall policies. If you do not<br />

apply any traffic shaping rule to a policy, the policy is set to high<br />

priority by default.<br />

• Distribute firewall policies over all three priority queues (low,<br />

medium and high).<br />

• Be sure that the sum of all Guaranteed Bandwidth in all firewall<br />

policies is significantly less than the bandwidth capacity of the<br />

interface.<br />

For information about how to configure traffic shaping, see “Adding<br />

traffic shaping to firewall policies” on page 278<br />

Display the Authentication Disclaimer page (a replacement message).<br />

The user must accept the disclaimer to connect to the destination. You<br />

can use the disclaimer in conjunction with authentication or a protection<br />

profile. This option is available on some models. It is not available for<br />

SSL-VPN policies.<br />

If you enter a URL, the user is redirected to the URL after<br />

authenticating and/or accepting the user authentication disclaimer. This<br />

option is available on some models. It is not available for SSL-VPN<br />

policies.<br />

Add a description or other information about the policy. The <strong>com</strong>ment<br />

can be up to 63 characters long, including spaces.<br />

Configuring intra-VLAN firewall policies (<strong>FortiGate</strong>-224B only)<br />

In switch view, the <strong>FortiGate</strong>-224B unit can create firewall policies governing<br />

traffic between switch ports that are on the same switch VLAN. These are called<br />

switch VLAN-secure policies. If you want to create policies between VLANs, see<br />

“Firewall policy options” on page 272.<br />

An intra-VLAN policy must have at least one secure port as source or destination.<br />

It is not possible to create a firewall policy between two non-secure ports. For<br />

information about creating secure switch ports, see “Configuring a switch-LAN<br />

interface” on page 210.<br />

Go to Firewall > Policy and select Create New to configure a new firewall policy.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 275

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!