140
Fortinet Inc.
Default firewall configuration
Firewall configuration
Default firewall configuration
By default, the users on your internal network can connect through the FortiGate unit
to the Internet through the WAN1 interface. The firewall blocks all other connections.
The firewall is configured with a default policy that matches any connection request
received from the internal network and instructs the firewall to forward the connection
through the WAN1 interface to the Internet.
The default policy also applies virus scanning to all HTTP, FTP, SMTP, POP3, and
IMAP traffic matched by the policy. The policy applies virus scanning because the
Antivirus & Web Filter option is selected and the Content profile is set to Scan. For
more information about content profiles, see
“Content profiles” on page 167
.
Figure 4: Default firewall policy
•
Interfaces
•
Addresses
•
Services
•
Schedules
•
Content profiles
Interfaces
Add policies to control connections between FortiGate interfaces and between the
networks connected to these interfaces. By default, you can add policies for
connections that include the internal, WAN1, and DMZ interfaces. If you want to add
policies that include the WAN2 interface, you must configure this interface with an IP
address. See
“Changing an interface static IP address” on page 108
.
Addresses
To add policies between interfaces, the firewall configuration must contain addresses
for each interface. By default the firewall configuration includes the following firewall
addresses.
• Internal_All, added to the internal interface, this address matches all addresses on
the internal network.
• WAN1_All, added to the WAN1 interface, this address matches all addresses on
the external or WAN1 network.
• DMZ_All, added to the DMZ interface, this address matches all addresses on the
DMZ network.
The firewall uses these addresses to match the source and destination addresses of
packets received by the firewall. The default policy matches all connections from the
internal network because it includes the Internal_All address. The default policy also
matches all connections to the WAN1 network because it includes the WAN1_All
address.
Содержание FortiGate 60R
Страница 12: ...Contents 12 Fortinet Inc...
Страница 26: ...26 Fortinet Inc Customer service and technical support Introduction...
Страница 42: ...42 Fortinet Inc Next steps Getting started...
Страница 106: ...106 Fortinet Inc Registering a FortiGate unit after an RMA Virus and attack definitions updates and registration...
Страница 138: ...138 Fortinet Inc Customizing replacement messages System configuration...
Страница 228: ...228 Fortinet Inc Logging attacks Network Intrusion Detection System NIDS...
Страница 242: ...242 Fortinet Inc Exempt URL list Web filtering...
Страница 256: ...256 Fortinet Inc Configuring alert email Logging and reporting...
Страница 260: ...260 Fortinet Inc Glossary...
Страница 270: ...270 Fortinet Inc Index...