Fortinet 50B Benutzerhandbuch

Seite von 84
Configuring the FortiGate unit 
Planning the FortiGate configuration
FortiGate-50A/50B, FortiWiFi-50B and FortiGate-100 FortiOS 3.0 MR4 Install Guide
01-30004-0265-20070831
33
Configuring the FortiGate unit
This section provides an overview of the operating modes of the FortiGate unit. 
Before beginning to configure the FortiGate unit, you need to plan how to 
integrate the unit into your network. Your configuration plan depends on the 
operating mode you select: NAT/Route mode or Transparent mode.
This section includes the following topics:
Planning the FortiGate configuration
Before you configure the FortiGate unit, you need to plan how to integrate the unit 
into the network. Among other things, you must decide whether you want the unit 
to be visible to the network, which firewall functions you want it to provide, and 
how you want it to control the traffic flowing between its interfaces.
Your configuration plan depends on the operating mode you select. You can also 
configure the FortiGate unit and the network it protects using the default settings.
NAT/Route mode
In NAT/Route mode, the FortiGate unit is visible to the network. Like a router, all 
its interfaces are on different subnets. The following interfaces are available in 
NAT/Route mode: 
Modem is the interface for connecting an external modem to the FortiGate-50A. 
See 
You can add firewall policies to control whether communications through the 
FortiGate unit operating in NAT or Route mode. Firewall policies control the flow 
of traffic based on the source address, destination address, and service of each 
packet. In NAT mode, the FortiGate unit performs network address translation 
before it sends the packet to the destination network. In Route mode, there is no 
address translation.
Table 11: NAT/Route mode network segments
FortiGate Unit
Internal Interface External 
Interface
Other
FortiGate-50A
Internal
External
Modem
FortiGate-50B
Internal
WAN1
WAN2
FortiWiFi-50B
Internal
WAN1
WAN2
FortiGate-100A
Internal
External
DMZ