What’s new in FortiOS 4.0
“Any” interface for firewall policies
FortiGate Version 4.0 Administration Guide
01-400-89802-20090424
35
•
next
end
3
Configure the interfaces that connected to cache servers to accept WCCP traffic.
config system interface
edit <interface_name)
(configure the interface)
set wccp {enable | disable}
next
edit <interface_name)
(configure the interface)
set wccp {enable | disable}
next
end
“Any” interface for firewall policies
You can now define a firewall policy where the source or destination interface is
any
. If you
add a firewall policy with the source or destination interface set to
any
, the firewall will
match the policy with packets to or from any interface.
For more information, see
“Viewing the firewall policy list” on page 321
Global view of firewall policies
In FortiOS 3.0 you could display firewall policies organized by source and destination
interfaces. In FortiOS 4.0 this is called
Section View
. You can also switch to
Global View
to list all firewall policies in order according to a sequence number. The sequence number
indicates the order of the policies in the policy list. When you rearrange the policy order
the sequence number changes. The Policy ID remains independent of the sequence
number.
If you have firewall policies with
Any
as source or destination, only the global view is
available.
For more information, see
“Viewing the firewall policy list” on page 321
Figure 2: Example global view including an “any” firewall policy
Identity-based firewall policies
FortiOS 4.0 supports firewall policy authentication in a more flexible way than earlier
releases. Any firewall policy that requires authentication is now known as an identity-
based policy. Optionally, you can permit different schedules or services and apply different
protection profiles to different user groups.
For more information, see
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...