fortigate 80c configuration manual

Also, note that if you perform any additional actions between procedures, your configuration may have different results.
One method to configure a Cisco switch is to connect over a serial connection to the console port on the switch, and enter the commands at the CLI.
When choosing firewall address names, use informative and unique names. Vlan_100 is on the subnet, and vlan_200 is on the subnet. Test the configuration Use diagnostic commands, such as tracert, to test traffic routed through the FortiGate unit and the Cisco switch. There are two different internal network vlans in this example. If you do not want to allow all services on a vlan, you can create a security policy for each service you want to allow. The switch has the configuration: Port 0/3 vlan ID 100, Port 0/9 vlan ID 200, Port 0/24 802.1Q trunk. To complete the setup, configure devices on vlan_100 and vlan_200 with default gateways. Adding vlan subinterfaces can be completed through the web-based manager, or the CLI. FortiGate unit and the Cisco 2950 switch are installed and connected and that basic configuration has been completed. In this example, the _Net part of the address name indicates a range of addresses instead of a unique address.
T o add the security policies web-based manager.
T o configure the external interface web-based manager.

Configure the FortiGate unit: Configure the external interface, Add two vlan subinterfaces to the internal network interface, Add firewall addresses and address ranges for the internal and external networks, Add security policies to allow the vlan networks to access each other and the vlan networks to access the external network. For best results in this configuration, follow the procedures in the order given. The external interface has an IP address and connects to the Internet. On the switch, you will need to be able to access the CLI to enter commands. The IP address of the internal interface does not matter, as long as it does not overlap with the subnets of the vlan subinterfaces we are configuring. The default gateway for vlan_200 is the FortiGate vlan_200 subinterface. Interface FastEthernet0/24 switchport trunk encapsulation dot1q switchport mode trunk! This configuration could apply to two departments in a single company, or to different companies.
It is assumed that both the.
T es t i n g traffic from vlan_200 to the external network In this example, a route is traced from an internal network to the external network.