
178
Fortinet Inc.
Configuring policy lists
Firewall configuration
A policy that is an exception to the default policy, for example, a policy to block FTP
connections, must be placed above the default policy in the port1
->
port2 policy list. In
this example, all FTP connection attempts from the internal network would then match
the FTP policy and be blocked. Connection attempts for all other kinds of services
would not match with the FTP policy but they would match with the default policy.
Therefore, the firewall would still accept all other connections from the internal
network.
Changing the order of policies in a policy list
1
Go to
Firewall > Policy
.
2
Select the policy list that you want to rearrange.
3
Choose a policy to move and select Move To
to change its order in the policy list.
4
Type a number in the Move to field to specify where in the policy list to move the policy
and select OK.
Enabling and disabling policies
You can enable and disable policies in the policy list to control whether the policy is
active or not. The FortiGate unit matches enabled policies but does not match
disabled policies.
Disabling a policy
Disable a policy to temporarily prevent the firewall from selecting the policy. Disabling
a policy does not stop active communications sessions that have been allowed by the
policy. To stop active communication sessions, see
“System status” on page 110
.
1
Go to
Firewall > Policy
.
2
Select the policy list containing the policy to disable.
3
Clear the check box of the policy to disable.
Enabling a policy
Enable a policy that has been disabled so that the firewall can match connections with
the policy.
1
Go to
Firewall > Policy
.
2
Select the policy list containing the policy to enable.
3
Select the check box of the policy to enable.
Note:
Policies that require authentication must be added to the policy list above matching
policies that do not; otherwise, the policy that does not require authentication is selected first.
Summary of Contents for FortiGate 400
Page 13: ...Contents FortiGate 400 Installation and Configuration Guide 13 Glossary 295 Index 299 ...
Page 14: ...Contents 14 Fortinet Inc ...
Page 44: ...44 Fortinet Inc Next steps Getting started ...
Page 74: ...74 Fortinet Inc Transparent mode configuration examples Transparent mode installation ...
Page 148: ...148 Fortinet Inc Providing DHCP services to your internal network Network configuration ...
Page 168: ...168 Fortinet Inc Customizing replacement messages System configuration ...
Page 200: ...200 Fortinet Inc Content profiles Firewall configuration ...
Page 258: ...258 Fortinet Inc Logging attacks Network Intrusion Detection System NIDS ...
Page 294: ...294 Fortinet Inc Configuring alert email Logging and reporting ...
Page 298: ...298 Fortinet Inc Glossary ...
Page 308: ...308 Fortinet Inc Index ...