12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Firewall Address<br />

About firewall addresses<br />

Firewall Address<br />

Add, edit, and delete firewall addresses as required. Firewall addresses are<br />

added to the source and destination address fields of firewall policies. Firewall<br />

addresses are added to firewall policies to match the source or destination IP<br />

addresses of packets that are received by the <strong>FortiGate</strong> unit.<br />

This section describes:<br />

• About firewall addresses<br />

• Viewing the firewall address list<br />

• Configuring addresses<br />

• Viewing the address group list<br />

• Configuring address groups<br />

About firewall addresses<br />

A firewall address can be:<br />

• The IP address of a single <strong>com</strong>puter (for example, 192.45.46.45).<br />

• The IP address of a subnetwork (for example, 192.168.1.0 for a class C<br />

subnet).<br />

• 0.0.0.0 to represent all possible IP addresses<br />

The netmask corresponds to the type of address being added. For example:<br />

• The netmask for the IP address of a single <strong>com</strong>puter should be<br />

255.255.255.255.<br />

• The netmask for a class A subnet should be 255.0.0.0.<br />

• The netmask for a class B subnet should be 255.255.0.0.<br />

• The netmask for a class C subnet should be 255.255.255.0.<br />

• The netmask for all addresses should be 0.0.0.0<br />

An IP Range address represents:<br />

• A range of IP addresses in a subnet (for example, 192.168.20.1 to<br />

192.168.20.10)<br />

Note: IP address: 0.0.0.0 and Netmask: 255.255.255.255 is not a valid firewall address.<br />

Organize related addresses into address groups to simplify policy creation.<br />

A firewall address can be configured with a name, an IP address, and a netmask,<br />

or a name and IP address range. It can also be a fully qualified domain name<br />

(FQDN).<br />

Enter an IP address and netmask using the following formats:<br />

• x.x.x.x/x.x.x.x, for example 192.168.1.0/255.255.255.0<br />

• x.x.x.x/x, for example 192.168.1.0/24<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 289

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!