Ordering security policies to allow different access levels
73
the PC policy, not the Internet access only
policy, select the
Seq.#
column and drag the
policy to the top of the list.
The device identity list will now appear at the
top of the list. After the list is refreshed, this
policy will be assigned
Seq.#
1.
With this new order set, the FortiGate unit
will attempt to apply the policy for the PC to
all traf
fi
c from the LAN interface. If the traf
fi
c
comes from a different source, the FortiGate
will attempt to apply the Internet access only
policy. If this attempt also fails, traf
fi
c will be
blocked using the default deny policy.
When ordering multiple security policies, the
most speci
fi
c policies (in this case, the policy
for the PC) must go to the top of the list, to
ensure that the FortiGate unit checks them
fi
rst when determining which policy to apply.
Results
Browse the Internet using the PC and
another network device, then refresh the
policy list. You can now see
Sessions
occuring for both policies.
THE FOR
TIGA
TE COOKBOOK
Summary of Contents for FortiGate 1U
Page 1: ...FortiOS 5 0 4 1U Models ...
Page 3: ......
Page 4: ...2 ...
Page 5: ...3 QUICKSTART GUIDE FortiGate 1U QuickStart Guide ...
Page 14: ......
Page 15: ...The FortiGate Cookbook Recipes for Success with your FortiGate THE FORTIGATE COOKBOOK ...
Page 16: ......
Page 20: ......
Page 24: ......
Page 88: ......
Page 158: ......
Page 198: ......
Page 229: ...Using redundant OSPF routing over IPsec VPN 209 THE FORTIGATE COOKBOOK ...
Page 235: ...Using redundant OSPF routing over IPsec VPN 215 THE FORTIGATE COOKBOOK ...
Page 238: ......
Page 239: ...About Fortinet High Performace Network Security Q3 2013 ...
Page 253: ...PRODUCT GUIDE Product Guide ...
Page 265: ......