Fortinet FortiGate FortiGate-5001 Administration Manual page 203

Fortigate 5000 series
Hide thumbs Also See for FortiGate FortiGate-5001:
Table of Contents

Advertisement

Firewall
FortiGate-5000 series Administration Guide
Schedule
Select a schedule that controls when the policy is available to be matched with
connections. See
"Schedule" on page
Service
Select the name of a service or service group that matches the service or protocol of
the packets to be matched with this policy. You can select from a wide range of
predefined services or add custom services and service groups. See
page
213.
Action
Select how you want the firewall to respond when the policy matches a connection
attempt.
ACCEPT
Accept connections matched by the policy. You can also configure NAT,
protection profiles, log traffic, traffic shaping, authentication, and differentiated
services. You can also add a comment to the policy.
DENY
Select deny to reject connections matched by the policy. The only other policy
options that you can configure are log traffic (to log the connections denied by
this policy) and differentiated services. You can also add a comment to the
policy.
ENCRYPT
Select encrypt to make this policy an IPSec VPN policy. An IPSec VPN policy
causes the FortiGate unit to accept IPSec packets. When encrypt is selected
the VPN Tunnel Options appear. You can also configure protection profiles, log
traffic, traffic shaping, and differentiated services. You can also add a comment
to the policy. You cannot configure NAT or add authentication to an encrypt
policy. For more information, see
tunnels" on page
VPN Tunnel
Select a VPN tunnel for an ENCRYPT policy. You can select an AutoIKE key or
Manual Key tunnel.
Allow Inbound
Select Allow inbound so that traffic from the remote network or host can start
the IPSec VPN tunnel.
Allow outbound Select Allow outbound if traffic from the local network can start the tunnel.
Inbound NAT
Select Inbound NAT to translate the source address of incoming packets to
the FortiGate internal IP address.
Outbound NAT Select Outbound NAT to translate the source address of outgoing packets to
the FortiGate external IP address.
NAT
Select NAT to enable Network Address Translation for the policy. NAT translates the
source address and port of packets accepted by the policy. If you select NAT, you can
also select Dynamic IP Pool and Fixed Port. NAT is not available in Transparent
mode.
01-28008-0013-20050204
221.
"Adding firewall policies for IPSec VPN
276.
Policy
"Service" on
203

Advertisement

Table of Contents
loading

Table of Contents