12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Firewall policy examples<br />

Firewall Policy<br />

Options to check FortiClient on hosts<br />

On the <strong>FortiGate</strong> model 1000A, 3600A, and 5005FA2, firewall policies can deny<br />

access for hosts that do not have FortiClient Host Security software installed and<br />

operating. This feature can detect FortiClient software version 3.0 MR2 or later.<br />

Figure 171:FortiClient Host Security check options<br />

Check FortiClient Installed<br />

and Running<br />

Redirect Restricted Users to<br />

<strong>FortiGate</strong> Download Portal<br />

Select to check that the source host is running FortiClient<br />

Host Security software. Enable the following reasons to<br />

deny access as needed:<br />

• FortiClient is Not Installed<br />

• FortiClient is Not Licensed<br />

• AV/IPS Database Out-of-Date<br />

• AV Disabled<br />

• Firewall Disabled<br />

• Web Filter Disabled<br />

Select to redirect denied users to the internal web portal<br />

which provides the reason for denial. On units that<br />

support it, users can download FortiClient Host Security<br />

software.<br />

Firewall policy examples<br />

<strong>FortiGate</strong> units are fully capable of meeting various network requirements from<br />

home use to SOHO, to large enterprises and ISPs. The following two scenarios<br />

will demonstrate the practical applications of firewall policies in the SOHO and<br />

large enterprise environments.<br />

For more detail on these two examples please see the Example Library Network<br />

and SOHO and SMB Network Protection example guides in the FortiOS v3.0 MR2<br />

documentation.<br />

• Scenario one: SOHO sized business<br />

• Scenario two: enterprise sized business<br />

Scenario one: SOHO sized business<br />

Company A is a small software <strong>com</strong>pany performing development and providing<br />

customer support. In addition to their internal network of 15 <strong>com</strong>puters, they also<br />

have several employees that work from home all or some of the time.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

282 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!