Configuring the FortiGate for the
Network
FortiGate-5000 series Installation Guide
FortiGate-5000 series Installation Guide Version 2.80 MR11
This chapter provides an overview of the operating modes of the FortiGate unit.
Before beginning to configure the FortiGate-5000 security system module, you need
to plan how to integrate the unit into your network. Your configuration plan is
dependent upon the operating mode that you select: NAT/Route mode or Transparent
mode.
Note: Before using the information in this chapter to configure your FortiGate-5000 module
refer to the
FortiGate-5000 Series Hardware Guide
hardware components.
NAT/Route mode standalone configuration
In NAT/Route mode standalone configuration, each FortiGate-5000 module in the
FortiGate chassis operates as a separate FortiGate antivirus firewall. Each of these
FortiGate antivirus firewalls is visible to the networks that it is connected to.
For each FortiGate-5000 module, all interfaces are available for processing network
traffic in NAT/Route mode. The IP address of each interface must be on a different
subnet.
You can add firewall policies to control whether communications through the
FortiGate-5000 module operate in NAT or Route mode. Firewall policies control the
flow of traffic based on the source address, destination address, and service of each
packet. In NAT mode, the FortiGate-5000 module performs network address
translation before it sends the packet to the destination network. In Route mode, there
is no translation.
By default, the FortiGate blocks all network traffic until you add firewall policies.
You typically use NAT/Route mode when the FortiGate-5000 module is operating as a
gateway between private and public networks. In this configuration, you would create
NAT mode firewall policies to control traffic flowing between the internal, private
network and the external, public network (usually the Internet).
01-28011-0259-20060210
to install and connect your FortiGate-5000
11
Need help?
Do you have a question about the FortiGate FortiGate-5001FA2 and is the answer not in the manual?
Questions and answers