I have a FortiGate 101F that I just set up and I created a few policies like in the image below.
Everything is working but can someone check if I've done it right.
Internal LAN, is out network switch/Access point, Maxis-Internet is or internet line.
Have I done the security profiles correctly?
We're not subscribed to AntiVirus, so that's why its not in Internet policy, but somehow there's a basic one for Internal.
You may add application control profile to deny unwanted applications.
I'll do that too.
But the firewall configuration part is done right? As in my current setup will prevent attacks to the network?
With this initial config you have covered a large part of the attack surface.
Other extra tuning may be done (like deep inspection) to block more attacks.
your second policy will never be hit because traffic from port2 to port2 is within one subnet and will not hit the firewall.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Hello @IronMan
You can also setup IPv4 DOS policy to protect against DOS attacks to your network:
Regards,
Varun
User | Count |
---|---|
2101 | |
1184 | |
770 | |
451 | |
344 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.