After some firewall policy advice
Hi all,
I have worked with the Fortigate firewalls now for about 2 years in my current role, but I do not consider myself a firewall person at all.
I seem to struggle to come up with a good naming scheme for my policies and also how to best create policies so:
[ol]So we have policies named like "SiteA to SiteB" allowing all services and from and to has 2 different subnets
Or we have "Allow AD,DNS,NTP from DMZ to LAN" with services "Windows AD" + "NTP" from the DMZ subnet to 2 specific domain controllers.
But we also have policies named "SiteA Server Lan to Datacentre" which has 4 VLAN interfaces in the from field and 1 VPN tunnel in the To field. The problem i seem to have is coming up with a consistent naming format for my policies and we we seem to mix in regards to creating 1 policy per thing either "SiteA to SiteB" or "Allow SMTP for Server1 to Exchange".
[ul]I think it makes sense to me that access to services like AD, NTP, DNS, Exchange could be done from subnets rather than individual servers.
Thx in advance
