12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Zone<br />

System Network<br />

Zone<br />

You can use zones to group related interfaces and VLAN subinterfaces. Grouping<br />

interfaces and VLAN subinterfaces into zones simplifies policy creation. If you<br />

group interfaces and VLAN subinterfaces into a zone, you can configure policies<br />

for connections to and from this zone, but not between interfaces in the zone.<br />

You can add zones, rename and edit zones, and delete zones from the zone list.<br />

When you add a zone, you select the names of the interfaces and VLAN<br />

subinterfaces to add to the zone.<br />

Zones are added to virtual domains. If you have added multiple virtual domains to<br />

your <strong>FortiGate</strong> configuration, make sure you are configuring the correct virtual<br />

domain before adding or editing zones.<br />

Figure 47: Zone list<br />

Zone settings<br />

Create New<br />

Name<br />

Block intra-zone<br />

traffic<br />

Go to System > Network > Zone to configure zones. Select Create New or select<br />

the Edit icon for a zone to modify that zone.<br />

Figure 48: Zone options<br />

Select Create New to create a new zone.<br />

The names of the zones that you have added.<br />

Displays Yes if traffic between interfaces in the same zone is blocked<br />

and No if traffic between interfaces in the same zone is not blocked.<br />

Interface Members The names of the interfaces added to the zone. Interface names<br />

depend on the <strong>FortiGate</strong> model.<br />

Edit/View icons Edit or view a zone.<br />

Delete icon Delete a zone.<br />

Name<br />

Block intra-zone<br />

traffic<br />

Enter the name to identify the zone.<br />

Select Block intra-zone traffic to block traffic between interfaces or<br />

VLAN subinterfaces in the same zone.<br />

Interface members Select the interfaces that are part of this zone. This list includes<br />

configured VLANs.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

98 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!