12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Firewall Address<br />

Configuring addresses<br />

Configuring addresses<br />

Addresses can also be created or edited during firewall policy configuration from<br />

the firewall policy window.<br />

One FQDN may be mapped to multiple machines for load balancing and HA. A<br />

single FQDN firewall policy can be created in which the <strong>FortiGate</strong> unit<br />

automatically resolves and maintains a record of all addresses to which the FQDN<br />

resolves.<br />

!<br />

Caution: Using a fully qualified domain name in a firewall policy, while convenient, does<br />

present some security risks. Be very cautious when using this feature.<br />

To add an IP address, IP range, or FQDN, go to Firewall > Address, select<br />

Create New.<br />

Figure 177:New address or IP range options<br />

Address Name Enter a name to identify the firewall address. Addresses, address<br />

groups, and virtual IPs must have unique names to avoid confusion in<br />

firewall policies.<br />

Type<br />

Select the type of address: Subnet/IP Range or FQDN.<br />

Subnet/IP Range Enter the firewall IP address, forward slash, and subnet mask or enter<br />

an IP address range separated by a hyphen<br />

Interface Select the interface or zone you want the IP address to associate with.<br />

Select Any if you want to associate the IP address with the<br />

interface/zone when you create the policy.<br />

Viewing the address group list<br />

If virtual domains are enabled on the <strong>FortiGate</strong> unit, address groups are<br />

configured separately for each virtual domain. To access address groups, select a<br />

virtual domain from the list in the main menu.<br />

Organize related addresses into address groups to make it easier to configure<br />

policies. For example, after adding three addresses and configuring them in an<br />

address group, configure a single policy using all three addresses.<br />

To view the address group list, go to Firewall > Address > Group.<br />

Note: If an address group is included in a policy, it cannot be deleted unless it is first<br />

removed from the policy.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 291

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!