12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Firewall Policy<br />

Firewall policy examples<br />

With their current network topography, all 15 of the internal <strong>com</strong>puters are behind<br />

a router and must go to an external source to access the IPS Mail and Web<br />

servers. All home based employees access the router through open/non secured<br />

connections.<br />

Figure 172:Example SOHO network before <strong>FortiGate</strong> installation<br />

Company A requires secure connections for home-based workers. Like many<br />

<strong>com</strong>panies, they rely heavily on email and Internet access to conduct business.<br />

They want a <strong>com</strong>prehensive security solution to detect and prevent network<br />

attacks, block viruses, and decrease spam. They want to apply different protection<br />

settings for different departments. They also want to integrate web and email<br />

servers into the security solution.<br />

To deal with their first requirement <strong>com</strong>pany A configures specific policies for each<br />

home-based worker to ensure secure <strong>com</strong>munication between the home-based<br />

worker and the internal network.<br />

1 Go to Firewall > Policy.<br />

2 Select Create New and enter or select the following settings for Home_User_1:<br />

Interface / Zone Source: internal Destination: wan1<br />

Address<br />

Source:<br />

Destination: Home_User_1<br />

CompanyA_Network<br />

Schedule<br />

Always<br />

Service<br />

ANY<br />

Action<br />

IPSEC<br />

VPN Tunnel<br />

Home1<br />

Allow Inbound<br />

yes<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 283

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!