Question
newbie question: policy rules ordering
Hello all, I am new to the FortiOS, but familiar to Checkpoint NGX. Currently I am working on our new Fortigate 200D and migrating our current firewall settings to this box (It' s a hell of a job
) I was wondering though what the best ordering is for the firewall rules. obviously outgoing NAT rules go above more general rules. But e.g. should one group all incoming rules going to VIP-address before internal rules going to the nonnatted addresses, or is a grouping by, say, server more appropriate. something like: all -> vip-server_one all -> vip-server_two all -> vip-server_three all -> server_one all -> server_two all -> server_three or: all -> vip-server_one all -> server_one all -> vip-server_two all -> server_two all -> vip-server_three all -> server_three
) I was wondering though what the best ordering is for the firewall rules. obviously outgoing NAT rules go above more general rules. But e.g. should one group all incoming rules going to VIP-address before internal rules going to the nonnatted addresses, or is a grouping by, say, server more appropriate. something like: all -> vip-server_one all -> vip-server_two all -> vip-server_three all -> server_one all -> server_two all -> server_three or: all -> vip-server_one all -> server_one all -> vip-server_two all -> server_two all -> vip-server_three all -> server_three