NAT/Route mode installation
NAT/Route mode installation
Preparing to configure the FortiGate unit in NAT/Route mode
34
For the most secure operation, you should change the configuration of the
external interface so that it does not respond to ping requests. Not responding to
ping requests makes it more difficult for a potential attacker to detect your
FortiGate unit from the Internet.
Depending on the FortiGate unit, the default public interface can be the WAN1
interface or Port 2 interface.
A FortiGate unit responds to ping requests if ping administrative access is enabled
for that interface. You can use the following procedures to disable ping access for
the external interface of a FortiGate unit. You can use the same procedure for any
FortiGate interface. You can also use the same procedure in NAT/Route or
Transparent mode.
To disable ping administrative access from the web-based manager
1
Log into the FortiGate web-based manager.
2
Go to System > Network > Interface.
3
Choose the external interface and select Edit.
4
Clear the Ping Administrative Access check box.
5
Select OK to save the changes.
To disable ping administrative access from the FortiGate CLI
1
Log into the FortiGate CLI.
2
Disable administrative access to the external interface. Enter:
config system interface
edit external
unset allowaccess
end
This section describes how to install the FortiGate unit in NAT/Route mode. This
section includes the following topics:
•
Preparing to configure the FortiGate unit in NAT/Route mode
•
DHCP or PPPoE configuration
•
Using the web-based manager
•
Using the front control buttons and LCD
•
Using the command line interface
•
Connecting the FortiGate unit to the network(s)
•
Configuring the networks
Use
Table 13 on page 35
NAT/Route mode settings.
You can configure the FortiGate unit in three ways:
•
The web-based manager GUI is a complete interface for configuring most
settings. See
"Using the web-based manager" on page
FortiGate-200A, FortiGate-300A, FortiGate-400A, and FortiGate-500A FortiOS 3.0 MR4 Install Guide
to gather the information you need to customize
Configuring the FortiGate unit
35.
01-30004-0268-20070712
Need help?
Do you have a question about the FortiGate FortiGate-200A and is the answer not in the manual?
Questions and answers