12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Firewall policy examples<br />

Firewall Policy<br />

The first firewall policy for main office staff members allows full access to the<br />

Internet at all times. A second policy will allow direct access to the DMZ for staff<br />

members. A second pair of policies are required to allow branch staff members<br />

the same access.<br />

The staff firewall policies will all use a protection profile configured specifically for<br />

staff access. Enabled features include virus scanning, spam filtering, IPS, and<br />

blocking of all P2P traffic. FortiGuard web filtering is also used to block<br />

advertising, malware, and spyware sites.<br />

A few users may need special web and catalog server access to update<br />

information on those servers, depending on how they’re configured. Special<br />

access can be allowed based on IP address or user.<br />

The proposed topography has the main branch staff and the catalog access<br />

terminals going through a Fortigate HA cluster to the servers in a DMZ. The public<br />

access terminals first go through a ForitWiFi unit, where additional policies can be<br />

applied, to the HA Cluster and finally to the servers.<br />

The branch office has all three users routed through a ForitWiFi unit to the main<br />

branch via VPN tunnels.<br />

Figure 175:Proposed library system network topology<br />

Policies are configured in Firewall > Policy. Protection Profiles are configured in<br />

Firewall > Protection Profile.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

286 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!