Fortinet fortigate-200a Betriebsanweisung

Seite von 392
Introduction 
About FortiGate Antivirus Firewalls
FortiGate-300A Administration Guide
01-28006-0092-20041105
 17
VLANs and virtual domains
Fortigate Antivirus Firewalls support IEEE 802.1Q-compliant virtual LAN (VLAN) tags. 
Using VLAN technology, a single FortiGate unit can provide security services to, and 
control connections between, multiple security domains according to the VLAN IDs 
added to VLAN packets. The FortiGate unit can recognize VLAN IDs and apply 
security policies to secure network and IPSec VPN traffic between each security 
domain. The FortiGate unit can also apply authentication, content filtering, and 
antivirus protection to VLAN-tagged network and VPN traffic.
The FortiGate unit supports VLANs in NAT/Route and Transparent mode. In 
NAT/Route mode, you enter VLAN subinterfaces to receive and send VLAN packets.
FortiGate virtual domains provide multiple logical firewalls and routers in a single 
FortiGate unit. Using virtual domains, one FortiGate unit can provide exclusive firewall 
and routing services to multiple networks so that traffic from each network is 
effectively separated from every other network. 
You can develop and manage interfaces, VLAN subinterfaces, zones, firewall policies, 
routing, and VPN configuration for each virtual domain separately. For these 
configuration settings, each virtual domain is functionally similar to a single FortiGate 
unit. This separation simplifies configuration because you do not have to manage as 
many routes or firewall policies at one time.
Intrusion Prevention System (IPS)
The FortiGate Intrusion Prevention System (IPS) combines signature and anomaly 
based intrusion detection and prevention. The FortiGate unit can record suspicious 
traffic in logs, can send alert email to system administrators, and can log, pass, drop, 
reset, or clear suspicious packets or sessions. Both the IPS predefined signatures and 
the IPS engine are upgradeable through the FortiProtect Distribution Network (FDN). 
You can also create custom signatures.
VPN
Using FortiGate virtual private networking (VPN), you can provide a secure 
connection between widely separated office networks or securely link telecommuters 
or travellers to an office network.