10
FortiGate Quick Install Guide by ITDC FortiOS 5.x ,Rev.01 ®´ªo°¸Éª¦¦µ 1. Policy ´ ÊÄo宦´¦oµ Firewall Policy ¹ ɳ¤¸ Address ,User Identify ,Device Indentify 2. 宦´µ¦°nµ Policy ´ Ê FortiGate ³¤¸ Option Ä®onµÅo Ś  a. Session View ³Áȵ¦°nµ Policy µ¤ Interface Án Intrenal => Wan1 b. Global View ³Áȵ¦°nµ Policy µ¤ Sequent µ¦Îµµ° Firewall ®¤µ¥Á®» : 宦´µ¦ View ´ Ê 2 µ¤µ¦Á¡·É¤ Filed Åo ¸ÉÄoµn°¥ÇÅoÂn ID ,Count ,Status mc

FortiGate Manual Thai v.5.x-9itq.lnwfile.com/_/q/_raw/02/g2/bh.pdfFortiGate Quick Install Guide by ITDC FortiOS 5.x ,Rev.01 ®´ª o¸É ª µ 1. Policy Ê´ Ä oε® ´ oµ Firewall

  • Upload
    others

  • View
    10

  • Download
    0

Embed Size (px)

Citation preview

Page 1: FortiGate Manual Thai v.5.x-9itq.lnwfile.com/_/q/_raw/02/g2/bh.pdfFortiGate Quick Install Guide by ITDC FortiOS 5.x ,Rev.01 ®´ª o¸É ª µ 1. Policy Ê´ Ä oε® ´ oµ Firewall

FortiGate Quick Install Guide by ITDC

FortiOS 5.x ,Rev.01

1. Policy Firewall Policy Address ,User Identify ,Device Indentify

2. Policy FortiGate Option

a. Session View Policy Interface Intrenal => Wan1

b. Global View Policy Sequent Firewall

: View 2 Filed ID ,Count ,Status

mc

Page 2: FortiGate Manual Thai v.5.x-9itq.lnwfile.com/_/q/_raw/02/g2/bh.pdfFortiGate Quick Install Guide by ITDC FortiOS 5.x ,Rev.01 ®´ª o¸É ª µ 1. Policy Ê´ Ä oε® ´ oµ Firewall

FortiGate Quick Install Guide by ITDC

FortiOS 5.x ,Rev.01

Firewall Objects ( Address )

1. Object Address Firewall Policy

a. FQDN Fully Qualified Domain Name facebook.com ,youtube.com

b. Geography IP Address Assign

c. IP-Range IP Address . . . - . . .d. Subnet IP Address Subnet . . . /

:

Interface Object Address Interface Firewall Policy “Any”

ce e

9itco

m.com

FF

Domain Namemain Name

Assign Assign

IP Address IP Address

IP AIP A

Page 3: FortiGate Manual Thai v.5.x-9itq.lnwfile.com/_/q/_raw/02/g2/bh.pdfFortiGate Quick Install Guide by ITDC FortiOS 5.x ,Rev.01 ®´ª o¸É ª µ 1. Policy Ê´ Ä oε® ´ oµ Firewall

FortiGate Quick Install Guide by ITDC

FortiOS 5.x ,Rev.01

Firewall Objects ( Service )

Object Service FortiGate Service

Pre-Define Custom Service Service Object

Protocol Source Port ,Destination Port

Custom Service Service Group

Create “Group Service” Service

9itco

m ( Service ) ( Service

ect ServServ

m

Page 4: FortiGate Manual Thai v.5.x-9itq.lnwfile.com/_/q/_raw/02/g2/bh.pdfFortiGate Quick Install Guide by ITDC FortiOS 5.x ,Rev.01 ®´ª o¸É ª µ 1. Policy Ê´ Ä oε® ´ oµ Firewall

FortiGate Quick Install Guide by ITDC

FortiOS 5.x ,Rev.01

Firewall Objects ( Schedule )

Object Schedule FortiGate “Always”

Schedule Firewall

Policy FortiGate

Schedule “Recurring” One-Time

Object Schedule Group

OObject ject 9itcbjects ( Scheduects ( Sched

om

Page 5: FortiGate Manual Thai v.5.x-9itq.lnwfile.com/_/q/_raw/02/g2/bh.pdfFortiGate Quick Install Guide by ITDC FortiOS 5.x ,Rev.01 ®´ª o¸É ª µ 1. Policy Ê´ Ä oε® ´ oµ Firewall

FortiGate Quick Install Guide by ITDC

FortiOS 5.x ,Rev.01

Firewall Objects ( Traffic Shaper )

Object Traffic Shaper “Shared ,Per IP”

Shared “Per Policy” Traffic

Policy “For All Policy” Traffic Shaper Policy Object Traffic Shaper Policy Per IP Object Traffic Shaper IP Traffic Maximum

Object Traffic Shaper “Per IP” Firewall Policy

9itco

m ( Traffic Shap ( Traffic Sha

ect TraffTraf

m

Page 6: FortiGate Manual Thai v.5.x-9itq.lnwfile.com/_/q/_raw/02/g2/bh.pdfFortiGate Quick Install Guide by ITDC FortiOS 5.x ,Rev.01 ®´ª o¸É ª µ 1. Policy Ê´ Ä oε® ´ oµ Firewall

FortiGate Quick Install Guide by ITDC

FortiOS 5.x ,Rev.01

Firewall Objects ( VIP )

Object VIP “Static NAT 1:1” Real IP Private IP “Static NAT 1:1”

Forward Port Private IP IP Port Port Forward Port Private IP Apps Server

Real IP Assign

Objj

ewall wall Object Object 9it

com.co

m

cts (

Page 7: FortiGate Manual Thai v.5.x-9itq.lnwfile.com/_/q/_raw/02/g2/bh.pdfFortiGate Quick Install Guide by ITDC FortiOS 5.x ,Rev.01 ®´ª o¸É ª µ 1. Policy Ê´ Ä oε® ´ oµ Firewall

FortiGate Quick Install Guide by ITDC

FortiOS 5.x ,Rev.01

Security Profile ( UTM Profile )

Security Profile FortiGate Flow Based ,Proxy Based

Flow Based Packets Proxy Based Complete Content

Security Profile

m

Page 8: FortiGate Manual Thai v.5.x-9itq.lnwfile.com/_/q/_raw/02/g2/bh.pdfFortiGate Quick Install Guide by ITDC FortiOS 5.x ,Rev.01 ®´ª o¸É ª µ 1. Policy Ê´ Ä oε® ´ oµ Firewall

FortiGate Quick Install Guide by ITDC

FortiOS 5.x ,Rev.01

Packets Flow FortiGate 9

Page 9: FortiGate Manual Thai v.5.x-9itq.lnwfile.com/_/q/_raw/02/g2/bh.pdfFortiGate Quick Install Guide by ITDC FortiOS 5.x ,Rev.01 ®´ª o¸É ª µ 1. Policy Ê´ Ä oε® ´ oµ Firewall

FortiGate Quick Install Guide by ITDC

FortiOS 5.x ,Rev.01

AntiVirus Security Profile Scan 2 Flow Base Proxy Base Scan Protocol

WebFilter FortiGuard Categories URL

WebSite Filter WebSite Filter

mm.co

m2 FloFl

Page 10: FortiGate Manual Thai v.5.x-9itq.lnwfile.com/_/q/_raw/02/g2/bh.pdfFortiGate Quick Install Guide by ITDC FortiOS 5.x ,Rev.01 ®´ª o¸É ª µ 1. Policy Ê´ Ä oε® ´ oµ Firewall

FortiGate Quick Install Guide by ITDC

FortiOS 5.x ,Rev.01

FortiGuard Block WebSite Categories

WebSite Alcohol Action = Block (http://www.johnniewalker.com)

m.coon = Block (htt = Block (httcom