Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
IronMan
New Contributor III

New FortiGate Setup - Creating Firewall Policies

I have a FortiGate 101F that I just set up and I created a few policies like in the image below.

Everything is working but can someone check if I've done it right.

 

Internal LAN, is out network switch/Access point, Maxis-Internet is or internet line.

 

Have I done the security profiles correctly?

We're not subscribed to AntiVirus, so that's why its not in Internet policy, but somehow there's a basic one for Internal.

Screenshot 2025-01-15 151201.png

5 REPLIES 5
AEK
SuperUser
SuperUser

You may add application control profile to deny unwanted applications.

AEK
AEK
IronMan
New Contributor III

I'll do that too.

But the firewall configuration part is done right? As in my current setup will prevent attacks to the network?

AEK

With this initial config you have covered a large part of the attack surface.

Other extra tuning may be done (like deep inspection) to block more attacks.

AEK
AEK
sw2090
SuperUser
SuperUser

your second policy will never be hit because traffic from port2 to port2 is within one subnet and will not hit the firewall.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
vbandha
Staff
Staff

Hello @IronMan 

You can also setup IPv4 DOS policy to protect against DOS attacks to your network:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-IPv4-DOS-policy/ta-p/1896...

 

Regards,

Varun

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors