![Fortinet FortiGate 60R Installation And Configuration Manual Download Page 141](http://html1.mh-extra.com/html/fortinet/fortigate-60r/fortigate-60r_installation-and-configuration-manual_2321841141.webp)
Firewall configuration
Default firewall configuration
FortiGate-60R Installation and Configuration Guide
141
You can add more addresses to each interface to improve the control you have over
connections through the firewall. For more information about addresses, see
“Addresses” on page 148
.
You can also add firewall policies that perform network address translation (NAT). To
use NAT to translate destination addresses, you must add virtual IPs. Virtual IPs map
addresses on one network to a translated address on another network. For more
information about Virtual IPs, see
“Virtual IPs” on page 158
.
Services
Policies can also control connections based on the service or destination port number
of packets. The default policy accepts connections to using any service or destination
port number. The firewall is configured with over 40 predefined services. You can add
these services to a policy for more control over the services that can be used by
connections through the firewall. You can also add user-defined services. For more
information about services, see
“Services” on page 151
.
Schedules
Policies can also control connections based on the time of day or day of the week
when the firewall receives the connection. The default policy accepts connections at
any time. The firewall is configured with one schedule that accepts connections at any
time. You can add more schedules to control when policies are active. For more
information about schedules, see
“Schedules” on page 155
.
Content profiles
Content profiles can be added to policies to apply antivirus protection, web filtering,
and email filtering to web, file transfer, and email services. The FortiGate unit includes
the following default content profiles:
• Strict: to apply maximum content protection to HTTP, FTP, IMAP, POP3, and SMTP
content traffic.
• Scan: to apply antivirus scanning to HTTP, FTP, IMAP, POP3, and SMTP content
traffic.
• Web: to apply antivirus scanning and Web content blocking to HTTP content traffic.
• Unfiltered: to allow oversized files to pass through the FortiGate unit without
scanned for viruses.
By default, the Scan content profile is selected for the default policy.
For more information about content profiles, see
“Content profiles” on page 167
.
Summary of Contents for FortiGate 60R
Page 12: ...Contents 12 Fortinet Inc...
Page 26: ...26 Fortinet Inc Customer service and technical support Introduction...
Page 42: ...42 Fortinet Inc Next steps Getting started...
Page 138: ...138 Fortinet Inc Customizing replacement messages System configuration...
Page 228: ...228 Fortinet Inc Logging attacks Network Intrusion Detection System NIDS...
Page 242: ...242 Fortinet Inc Exempt URL list Web filtering...
Page 256: ...256 Fortinet Inc Configuring alert email Logging and reporting...
Page 260: ...260 Fortinet Inc Glossary...
Page 270: ...270 Fortinet Inc Index...