Firewall configuration
Services
Schedules
Content profiles
Adding firewall policies
FortiGate-50R Installation and Configuration Guide
Policies can also control connections based on the service or destination port number
of packets. The default policy accepts connections to using any service or destination
port number. The firewall is configured with over 40 predefined services. You can add
these services to a policy for more control over the services that can be used by
connections through the firewall. You can also add user-defined services. For more
information about services, see
Policies can also control connections based on the time of day or day of the week
when the firewall receives the connection. The default policy accepts connections at
any time. The firewall is configured with one schedule that accepts connections at any
time. You can add more schedules to control when policies are active. For more
information about schedules, see
Content profiles can be added to policies to apply antivirus protection, web filtering,
and email filtering to web, file transfer, and email services. The FortiGate unit includes
the following default content profiles:
•
Strict: to apply maximum content protection to HTTP, FTP, IMAP, POP3, and SMTP
content traffic.
•
Scan: to apply antivirus scanning to HTTP, FTP, IMAP, POP3, and SMTP content
traffic.
•
Web: to apply antivirus scanning and Web content blocking to HTTP content traffic.
•
Unfiltered: to allow oversized files to pass through the FortiGate unit without
scanned for viruses.
By default, the Scan content profile is selected for the default policy.
For more information about content profiles, see
Add Firewall policies to control connections and traffic between FortiGate interfaces.
1
Go to Firewall > Policy.
2
Select the policy list to which you want to add the policy.
3
Select New to add a new policy.
You can also select Insert Policy before
policy above a specific policy.
4
Configure the policy:
See
"Firewall policy options" on page 116
5
Select OK to add the policy.
6
Arrange policies in the policy list so that they have the results that you expect.
Arranging policies in a policy list is described in
"Services" on page
125.
"Schedules" on page
"Content profiles" on page
on a policy in the list to add the new
for information about policy options.
"Configuring policy lists" on page
Adding firewall policies
129.
140.
120.
115