Hi everyone,
I'm seeking some advice regarding the use of policy mode in FortiGate. Coming from a background of Cisco and Checkpoint environments, I'm quite familiar with their systems, but relatively new to FortiGate. I've come across several discussions suggesting that one should stay away from policy mode due to potential bugs. Can anyone share their experiences or insights about this? Is policy mode a viable option, or should it be avoided? Any advice or perspectives, especially from those who have transitioned from Cisco or Checkpoint, would be greatly appreciated!
Also, do you use central SNAT or no :)
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Bart
I integrated many FortiGates in both profile based mode and policy based mode and both worked fine in critical production.
Below I can give you some comparison that may interest you.
That said, personally I prefer and recommend profile based mode.
Regarding Central SNAT, I generally enable it even in profile based mode, because I am more comfortable with central management & NAT rules.
Note that some NAT operations can be done with Central SNAT but are difficult or even probably not available in non-central mode (sorry I don't remember the operations). I also know that some other operations available in non-central mode are not possible in central SNAT (e.g.: NAT by service), but it was never an issue for me.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1105 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.