Vlan Subinterfaces; Zones; Addresses - Fortinet FortiGate 4000 User Manual

Fortinet incorporated user manual switch fortigate 4000
Table of Contents

Advertisement

Firewall configuration

VLAN subinterfaces

Zones

Addresses

FortiGate-4000 Installation and Configuration Guide
You can also add VLAN subinterfaces to the FortiGate configuration to control
connections between VLANs. For more information about VLANs, see
NAT/Route mode" on page 151
page
153.
To add policies that include VLAN subinterfaces, you must use the following steps to
add the VLAN subinterfaces to the firewall policy grid:
1
Add VLAN subinterfaces to the FortiGate configuration.
2
Add firewall addresses for the VLAN subinterface.
See
"Adding addresses" on page
You can add zones to the FortiGate configuration to group together related interfaces
and VLAN subinterfaces to simplify firewall policy creation. For more information
about zones, see
To add policies for zones, you must use the following steps to add the zones to the
firewall policy grid:
1
Add zones to the FortiGate configuration.
See
"Adding zones" on page
2
Add interfaces and VLAN subinterfaces to the zone.
See
"Adding an interface to a zone" on page
3
Add firewall addresses for the zone.
See
"Adding addresses" on page
To add policies between interfaces, VLAN subinterfaces and zones, the firewall
configuration must contain addresses for each interface, VLAN subinterface, or zone.
By default the firewall configuration includes the addresses listed in
Table 45: Default addresses
Interface
Address
Internal
Internal_All
External
External_All This address matches all addresses on the external network.
The firewall uses these addresses to match the source and destination addresses of
packets received by the firewall. The default policy matches all connections from the
internal network because it includes the Internal_All address. The default policy also
matches all connections to the Internet because it includes the External_All address.
You can add more addresses to each interface to improve the control you have over
connections through the firewall. For more information about addresses, see
"Addresses" on page
or
"Virtual domains in Transparent mode" on
202.
"Configuring zones" on page
142.
202.
Description
This address matches all addresses on the internal network.
202.
Default firewall configuration
141.
143.
"VLANs in
Table
45.
193

Advertisement

Table of Contents
loading

Table of Contents