12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring a protection profile<br />

Firewall Protection Profile<br />

Block Login<br />

Block File Transfers<br />

Block Audio<br />

Inspect Non-standard Port<br />

Action<br />

Limit (KBytes/s)<br />

Enable to prevent instant message users from logging in to<br />

AIM, ICQ, MSN, Yahoo, and SIMPLE services.<br />

Enable to block file transfers for AIM, ICQ, MSN, and Yahoo<br />

protocols.<br />

Enable to block audio for AIM, ICQ, MSN, and Yahoo<br />

protocols.<br />

Enable inspection of non-standard ports for IM traffic.<br />

Pass, block, or rate limit P2P transfers for BitTorrent,<br />

eDonkey, Gnutella, Kazaa, and WinNY protocols. Skype<br />

transfers can be passed or blocked, but not rate limited.<br />

Specify bandwidth limit for BitTorrent, eDonkey, Gnutella,<br />

Kazaa, and WinNY protocols if action is set to rate limit.<br />

Changes to IM protection profile options, while IM users are logged in, will take<br />

effect only upon their next login. Enabling Block Login, for example, cannot be<br />

used to disconnect currently logged in users.<br />

See “IM, P2P & VoIP” on page 459 for more IM configuration options.<br />

VoIP options<br />

The <strong>FortiGate</strong> unit supports rate limiting for SIP (including SIMPLE) and SCCP<br />

protocols.<br />

Figure 220:Protection profile VoIP options<br />

The following options are available for VoIP through the protection profile:<br />

Limit RIGISTER Request<br />

Limit INVITE Request<br />

Limit Call Setup<br />

Set a rate limit to SIP RIGISTER requests (per second).<br />

Set a rate limit to SIP INVITE requests (per seconds).<br />

Set a rate limit to SCCP call setup (calls per minute)<br />

between call clients and the call manager.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

340 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!