Fortinet fortigate-300 Installationsanweisungen

Seite von 56
34
01-28004-0021-20040830
Fortinet Inc.
Configuring the networks
NAT/Route mode installation
2
Connect the External interface to the Internet.
Connect to the public switch or router provided by your Internet Service Provider. If 
you are a DSL or cable subscriber, connect the External interface to the internal or 
LAN connection of your DSL or cable modem.
3
Optionally connect the DMZ/HA interface to the DMZ network.
You can use a DMZ network to provide access from the Internet to a web server or 
other server without installing the servers on the internal network.
Figure 9: FortiGate-300 NAT/Route mode connections
Configuring the networks
If you are running the FortiGate unit in NAT/Route mode, your networks must be 
configured to route all Internet traffic to the IP address of the FortiGate interface to 
which they are connected. 
• For the internal network, change the default gateway address of all computers and 
routers connected directly to your internal network to the IP address of the 
FortiGate internal interface. 
• For the DMZ network, change the default gateway address of all computers and 
routers connected directly to your DMZ network to the IP address of the FortiGate 
DMZ interface. 
• For the external network, route all packets to the FortiGate external interface.
Esc
Enter
Internet
Internal
External
DMZ
FortiGate-300
Internal Network
DMZ Network
Mail Server
Web Server
Hub or Switch
Hub or Switch
Public Switch
or Router