198
01-28007-0144-20041217
Fortinet Inc.
Policy
Firewall
.
Comments
You can add a description or other information about the policy. The comment can be
up to 63 characters long, including spaces.
Configuring firewall policies
Use the following procedures to add, delete, edit, re-order, disable, and enable a
firewall policy.
To add a firewall policy
1
Go to
Firewall > Policy
.
2
Select Create New.
You can also select the Insert Policy before icon beside a policy in the list to add the
new policy above that policy.
3
Select the source and destination interfaces.
4
Select the source and destination addresses.
5
Configure the policy.
For information about configuring the policy, see
“Policy options” on page 193
.
6
Select OK to add the policy.
7
Arrange policies in the policy list so that they have the results that you expect.
For information about arranging policies in a policy list, see
“How policy matching
works” on page 192
.
To delete a policy
1
Go to
Firewall > Policy
.
2
Select the Delete icon beside the policy you want to delete.
3
Select OK.
To edit a policy
1
Go to
Firewall > Policy
.
2
Select the Edit icon beside the policy you want to edit.
3
Edit the policy as required.
4
Select OK.
To change the position of a policy in the list
1
Go to
Firewall > Policy
.
2
Select the Move To icon beside the policy you want to move.
Original
(forward) DSCP
value
Set the DSCP
value for packets accepted by the policy. For example, for an
Internal
->
External policy the value is applied to outgoing packets as they
exit the external interface and are forwarded to their destination.
Reverse (reply)
DSCP value
Set the DSCP
value for reply packets. For example, for an
Internal
->
External policy the value is applied to incoming reply packets
before they exit the internal interface and returned to the originator.
Содержание FortiGate FortiGate-60M
Страница 12: ...Contents 12 01 28007 0144 20041217 Fortinet Inc Index 369 ...
Страница 43: ...System status Changing the FortiGate firmware FortiGate 60M Administration Guide 01 28007 0144 20041217 43 ...
Страница 44: ...44 01 28007 0144 20041217 Fortinet Inc Changing the FortiGate firmware System status ...
Страница 74: ...74 01 28007 0144 20041217 Fortinet Inc FortiGate IPv6 support System network ...
Страница 82: ...82 01 28007 0144 20041217 Fortinet Inc Dynamic IP System DHCP ...
Страница 116: ...116 01 28007 0144 20041217 Fortinet Inc Access profiles System administration ...
Страница 234: ...234 01 28007 0144 20041217 Fortinet Inc Protection profile Firewall ...
Страница 246: ...246 01 28007 0144 20041217 Fortinet Inc CLI configuration Users and authentication ...
Страница 278: ...278 01 28007 0144 20041217 Fortinet Inc CLI configuration VPN ...
Страница 340: ...340 01 28007 0144 20041217 Fortinet Inc Using Perl regular expressions Spam filter ...
Страница 358: ...358 01 28007 0144 20041217 Fortinet Inc CLI configuration Log Report ...
Страница 376: ...376 01 28007 0144 20041217 Fortinet Inc Index ...