Optional Services
Firewall
Example 1
Rules for Filtering Packets
l
The users from the internet (WAN) can only access FTP Server 211.21.48.195 through port 21.
l
The users from LAN can access all servers and hosts on the internet (WAN) through port 25 (SMTP), port 80
(HTTP), port 21 (FTP), and port 110 (POP3).
l
All other packets are blocked.
The rules table for the example will look like this:
Source
Destination
Service
Action
WAN
211.21.48.195
FTP (21)
Accept
WAN
DMZ
Any
Deny
LAN
WAN
HTTP (80)
Accept
LAN
WAN
SMTP (25)
Accept
LAN
WAN
FTP (21)
Accept
LAN
WAN
POP3 (110)
Accept
LAN
WAN
Any
Deny
216
FortiWAN Handbook
Fortinet Technologies Inc.