Firewall
Policy
FortiGate-1000A/FA2 Administration Guide
01-28011-0254-20051115
211
You can configure policies to apply DSCP values for both original (or forward) traffic
and reverse (or reply) traffic. These values are optional and may be enabled
independently from each other. When both are disabled, no changes to the DS field
are made.
Comments
You can add a description or other information about the policy. The comment can be
up to 63 characters long, including spaces.
Configuring firewall policies
Use the following procedures to add, delete, edit, re-order, disable, and enable a
firewall policy.
To add a firewall policy
1
Go to
Firewall > Policy
.
2
Select Create New.
You can also select the Insert Policy before icon beside a policy in the list to add the
new policy above that policy.
3
Select the source and destination interfaces.
4
Select the source and destination addresses.
5
Configure the policy.
For information about configuring the policy, see
“Policy options” on page 205
.
6
Select OK to add the policy.
7
Arrange policies in the policy list so that they have the results that you expect.
For information about arranging policies in a policy list, see
“How policy matching
works” on page 204
.
To delete a policy
1
Go to
Firewall > Policy
.
2
Select the Delete icon beside the policy you want to delete.
3
Select OK.
To edit a policy
1
Go to
Firewall > Policy
.
2
Select the Edit icon beside the policy you want to edit.
3
Edit the policy as required.
4
Select OK.
Original
(forward) DSCP
value
Set the DSCP
value for packets accepted by the policy. For example, for an
Internal
->
External policy the value is applied to outgoing packets as they
exit the external interface and are forwarded to their destination.
Reverse (reply)
DSCP value
Set the DSCP
value for reply packets. For example, for an
Internal
->
External policy the value is applied to incoming reply packets
before they exit the internal interface and returned to the originator.
Summary of Contents for FortiGate 1000A
Page 80: ...80 01 28011 0254 20051115 Fortinet Inc FortiGate IPv6 support System Network ...
Page 88: ...88 01 28011 0254 20051115 Fortinet Inc Dynamic IP System DHCP ...
Page 122: ...122 01 28011 0254 20051115 Fortinet Inc FortiManager System Config ...
Page 248: ...248 01 28011 0254 20051115 Fortinet Inc Protection profile Firewall ...
Page 260: ...260 01 28011 0254 20051115 Fortinet Inc CLI configuration User ...
Page 380: ...380 01 28011 0254 20051115 Fortinet Inc CLI configuration Log Report ...
Page 392: ...392 01 28011 0254 20051115 Fortinet Inc Glossary ...