<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>物件 &#8211; 21點情報網</title>
	<atom:link href="https://ailog.tw/lifelog/tag/%E7%89%A9%E4%BB%B6/feed/" rel="self" type="application/rss+xml" />
	<link>https://ailog.tw/lifelog</link>
	<description></description>
	<lastBuildDate>Sun, 24 Jan 2021 07:30:51 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>
	<item>
		<title>跟小編一起學-FortiGate防火牆-設定「網路服務」物件(Console設定方式)</title>
		<link>https://ailog.tw/lifelog/2021/01/24/fgt-service-cmd/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sun, 24 Jan 2021 07:28:32 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[40F]]></category>
		<category><![CDATA[60B]]></category>
		<category><![CDATA[60D]]></category>
		<category><![CDATA[60E]]></category>
		<category><![CDATA[80C]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[Group]]></category>
		<category><![CDATA[Service]]></category>
		<category><![CDATA[物件]]></category>
		<category><![CDATA[網路服務]]></category>
		<category><![CDATA[網路服務群組]]></category>
		<category><![CDATA[跟小編一起學-FortiGate防火牆-設定「網路服務」物件(Console設定方式)]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=6497</guid>

					<description><![CDATA[今天小編要介紹的單元是透過Console方式，設定FortiGate防火牆「網路服務」及「網路服務群組」物件， &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/01/24/fgt-service-cmd/" class="more-link">閱讀全文<span class="screen-reader-text">〈跟小編一起學-FortiGate防火牆-設定「網路服務」物件(Console設定方式)〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>今天小編要介紹的單元是透過Console方式，設定FortiGate防火牆「網路服務」及「網路服務群組」物件，該物件常使用在防火牆規則的設定過程，趕快跟著小編一起來了解吧。<span id="more-6497"></span><br />
介紹的內容為<br />
透過Console管理畫面：<br />
(1)、建立服務類別<br />
(2)、建立網路服務物件(一)、(二)<br />
(3)、建立網路服務群組物件</p>
<p><span style="font-size: 14pt;"><strong>[建立服務類別]</strong></span><br />
(1)、登入系統<br />
<img decoding="async" class="alignnone wp-image-6501 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-01.jpg" alt="" width="223" height="123" /><br />
注解說明：輸入帳號及密碼登入防火牆</p>
<p>(2)、切換至「網路服務類別」物件設定模式<br />
指令如下：<br />
config firewall service category<br />
<img decoding="async" class="alignnone wp-image-6500 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-02.jpg" alt="" width="377" height="82" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-02.jpg 377w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-02-300x65.jpg 300w" sizes="(max-width: 377px) 100vw, 377px" /><br />
注解說明：開始網路服務類別設定</p>
<p>(3)、新增「網路服務類別」<br />
指令如下：<br />
edit &#8220;ailog.tw&#8221;<br />
<img decoding="async" class="alignnone wp-image-6502 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-03.jpg" alt="" width="334" height="95" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-03.jpg 334w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-03-300x85.jpg 300w" sizes="(max-width: 334px) 100vw, 334px" /><br />
注解說明：本範例新增了一個名稱為「ailog.tw」的類別</p>
<p>(4)、查看設定<br />
指令如下：<br />
show<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6504 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-04.jpg" alt="" width="338" height="167" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-04.jpg 338w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-04-300x148.jpg 300w" sizes="auto, (max-width: 338px) 100vw, 338px" /><br />
注解說明：查看設定是否正確，有無遺漏項目</p>
<p>(5)、離開「網路服務類別」物件設定模式<br />
指令如下：<br />
end<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-6505" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-05.jpg" alt="" width="221" height="83" /><br />
注解說明：如果要繼續新增其他的類別物件則輸入「next」，要結束類別設定則輸入「end」。</p>
<p><span style="font-size: 14pt;"><strong>[建立網路服務物件](一)<br />
</strong></span>(1)、切換至「網路服務」物件設定模式<br />
指令如下：<br />
config firewall service custom<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6507 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-06.jpg" alt="" width="356" height="88" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-06.jpg 356w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-06-300x74.jpg 300w" sizes="auto, (max-width: 356px) 100vw, 356px" /><br />
注解說明：開始網路服務物件設定</p>
<p>(2)、新增「網路服務」物件<br />
指令如下：<br />
edit &#8220;Synology-Drive&#8221;<br />
set category &#8220;ailog.tw&#8221;<br />
set tcp-portrange 5000-5001<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6508 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-07.jpg" alt="" width="510" height="195" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-07.jpg 510w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-07-300x115.jpg 300w" sizes="auto, (max-width: 510px) 100vw, 510px" /><br />
注解說明：本範例新增了一個名稱為「Synology-Drive」的網路服務，並將類別設定為「ailog.tw」，並定義採用「TCP」協定，服務埠(Port)則為5000與5001兩個。</p>
<p>(3)、查看設定<br />
指令如下：<br />
show<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6509 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-08.jpg" alt="" width="373" height="204" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-08.jpg 373w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-08-300x164.jpg 300w" sizes="auto, (max-width: 373px) 100vw, 373px" /><br />
注解說明：查看設定是否正確，有無遺漏項目</p>
<p>(4)、離開「網路服務」物件設定模式<br />
指令如下：<br />
end<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6510 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-09.jpg" alt="" width="277" height="76" /><br />
注解說明：如果要繼續新增其他的網路服務物件則輸入「next」，要結束類別設定則輸入「end」。</p>
<p><span style="font-size: 14pt;"><strong>[建立網路服務物件](二)</strong></span><br />
(1)、切換至「網路服務」物件設定模式<br />
指令如下：<br />
config firewall service custom<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6507 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-06.jpg" alt="" width="356" height="88" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-06.jpg 356w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-06-300x74.jpg 300w" sizes="auto, (max-width: 356px) 100vw, 356px" /><br />
注解說明：開始網路服務物件設定</p>
<p>(2)、新增「網路服務」物件<br />
指令如下：<br />
edit &#8220;tomcat&#8221;<br />
set category &#8220;ailog.tw&#8221;<br />
set tcp-portrange 8080<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6511 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-10.jpg" alt="" width="381" height="186" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-10.jpg 381w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-10-300x146.jpg 300w" sizes="auto, (max-width: 381px) 100vw, 381px" /><br />
注解說明：本範例新增了一個名稱為「tomcat」的網路服務，並將類別設定為「ailog.tw」，並定義採用「TCP」協定，服務埠(Port)則為8080。</p>
<p>(3)、查看設定<br />
指令如下：<br />
show<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6513 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-10-1.jpg" alt="" width="318" height="162" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-10-1.jpg 318w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-10-1-300x153.jpg 300w" sizes="auto, (max-width: 318px) 100vw, 318px" /><br />
注解說明：查看設定是否正確，有無遺漏項目</p>
<p>(4)、離開「網路服務」物件設定模式<br />
指令如下：<br />
end<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-6512" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-11.jpg" alt="" width="212" height="79" /><br />
注解說明：如果要繼續新增其他的網路服務物件則輸入「next」，要結束類別設定則輸入「end」。</p>
<p>&nbsp;</p>
<p><span style="font-size: 14pt;"><strong>[建立網路服務群組物件]<br />
</strong></span>(1)、切換至「網路服務群組」物件設定模式<br />
指令如下：<br />
config firewall service group<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6514 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-12.jpg" alt="" width="372" height="78" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-12.jpg 372w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-12-300x63.jpg 300w" sizes="auto, (max-width: 372px) 100vw, 372px" /><br />
注解說明：開始網路服務群組物件設定</p>
<p>(2)、設定「網路服務群組」物件<br />
指令如下：<br />
edit &#8220;Ailog.tw-Service&#8221;<br />
set member &#8220;Synology-Drive&#8221; &#8220;tomcat&#8221;<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6515 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-13.jpg" alt="" width="609" height="152" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-13.jpg 609w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-13-300x75.jpg 300w" sizes="auto, (max-width: 609px) 100vw, 609px" /><br />
注解說明：本範例新增了一個名稱為「Ailog.tw-Service」的網路服務群組，並定義群組內包含了「Synology-Drive」、「tomcat」這兩個服務。</p>
<p>(3)、查看設定<br />
指令如下：<br />
show<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6517 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-15.jpg" alt="" width="456" height="180" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-15.jpg 456w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-15-300x118.jpg 300w" sizes="auto, (max-width: 456px) 100vw, 456px" /><br />
注解說明：查看設定是否正確，有無遺漏項目</p>
<p>(4)、離開「網路服務群組」物件設定模式<br />
指令如下：<br />
end<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6516 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-14.jpg" alt="" width="315" height="81" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-14.jpg 315w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-14-300x77.jpg 300w" sizes="auto, (max-width: 315px) 100vw, 315px" /><br />
注解說明：如果要繼續新增其他的網路服務群組物件則輸入「next」，要結束類別設定則輸入「end」。</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>跟小編一起學-FortiGate防火牆-設定「網路服務」物件(web設定方式)</title>
		<link>https://ailog.tw/lifelog/2021/01/23/fgt-service-web/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Fri, 22 Jan 2021 16:00:24 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[40F]]></category>
		<category><![CDATA[60B]]></category>
		<category><![CDATA[60D]]></category>
		<category><![CDATA[60E]]></category>
		<category><![CDATA[80C]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[Service]]></category>
		<category><![CDATA[物件]]></category>
		<category><![CDATA[網路服務]]></category>
		<category><![CDATA[網路服務群組]]></category>
		<category><![CDATA[跟小編一起學-FortiGate防火牆-設定「網路服務」物件(web設定方式)]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=6400</guid>

					<description><![CDATA[今天小編要介紹的單元是設定FortiGate防火牆的「網路服務」及「網路服務群組」物件，該物件常使用在防火牆規 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/01/23/fgt-service-web/" class="more-link">閱讀全文<span class="screen-reader-text">〈跟小編一起學-FortiGate防火牆-設定「網路服務」物件(web設定方式)〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>今天小編要介紹的單元是設定FortiGate防火牆的「網路服務」及「網路服務群組」物件，該物件常使用在防火牆規則的設定過程，趕快跟著小編一起來了解吧。<span id="more-6400"></span></p>
<p>介紹的內容為<br />
透過web管理畫面：<br />
(1)、建立服務類別<br />
(2)、建立網路服務物件<br />
(3)、建立網路服務群組物件</p>
<p><span style="font-size: 14pt;"><strong>[建立服務類別]</strong></span><br />
(1)、登入系統<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5823 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-LOGIN-08.jpg" alt="" width="381" height="235" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-LOGIN-08.jpg 381w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-LOGIN-08-300x185.jpg 300w" sizes="auto, (max-width: 381px) 100vw, 381px" /></p>
<p>(2)、切換至「網路服務」物件設定畫面<br />
點選「<strong>Policy &amp; Objects</strong>」→「<strong>Services</strong>」<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6401 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-01.jpg" alt="" width="249" height="387" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-01.jpg 249w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-01-193x300.jpg 193w" sizes="auto, (max-width: 249px) 100vw, 249px" /></p>
<p>(3)、新增「網路服務」類別<br />
點選「<strong>Create New</strong>」→「<strong>Category</strong>」<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6402 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-02.jpg" alt="" width="230" height="153" /></p>
<p>(4)、設定「網路服務」類別<br />
<strong>Name</strong>：輸入自訂的類別名稱，本範例輸入「ailog.tw」做為新增的類別名稱，接著點選「OK」完成設定步驟。</p>
<p><strong>Comments</strong>：輸入類別名稱的注解，方便識別類別用途。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6403 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-03.jpg" alt="" width="696" height="223" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-03.jpg 696w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-03-300x96.jpg 300w" sizes="auto, (max-width: 696px) 100vw, 696px" /></p>
<p>(5)、查看設定狀態<br />
返回類別列表畫面可以看見剛剛新增的「ailog.tw」在列表中，代表已順利新增「網路服務」類別。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6404 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-04.jpg" alt="" width="411" height="439" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-04.jpg 411w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-04-281x300.jpg 281w" sizes="auto, (max-width: 411px) 100vw, 411px" /></p>
<p><span style="font-size: 14pt;"><strong>[建立網路服務物件]</strong></span><br />
(1)、新增「網路服務」物件<br />
點選「<strong>Create New</strong>」→「<strong>Service</strong>」<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-6405" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-05.jpg" alt="" width="260" height="154" /></p>
<p>(2)、設定「網路服務」物件<br />
<strong>Name</strong>：輸入自訂的服務物件名稱，建議採用有識別性的名稱，方便日後操作識別用，本範例輸入Synology-Drive。<br />
<strong><br />
Show in Service List</strong>：是否顯示在「網路服務」清單，有些情境會透過該設定來隱藏「網路服務」不顯示在設定的候選清單內，避免干擾設定、增加選取「網路服務」的複雜度，但通常都還是採用預設的顯示設定狀態。<br />
<strong><br />
Category</strong>：類別選取前一步驟所新增的「ailog.tw」<br />
※ailog.tw為本範例的類別名稱，請網友們輸入適當的名稱。</p>
<p><strong>Destination Port</strong>：挑選協定類型「TCP」、「UDP」、「SCTP」，並輸入要定義的服務埠，本範例採用TCP協定的5000~5001兩個服務埠。</p>
<p>輸入以上資訊後接著點選「OK」完成新增「網路服務」物件新增的步驟。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6406 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-06.jpg" alt="" width="690" height="461" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-06.jpg 690w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-06-300x200.jpg 300w" sizes="auto, (max-width: 690px) 100vw, 690px" /></p>
<p>(3)、確認「網路服務」物件狀態<br />
在網路服務列表中可以看見剛剛新增的物件。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6407 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-07.jpg" alt="" width="543" height="433" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-07.jpg 543w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-07-300x239.jpg 300w" sizes="auto, (max-width: 543px) 100vw, 543px" /></p>
<p>(4)、下圖是新增第二個網路服務物件範例。<br />
該範例中名稱定義為「tomcat」，「顯示」在網路服務物件的候選清單內，類別定義在「ailog.tw」，採用TCP協定的8080埠。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6408 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-08.jpg" alt="" width="689" height="462" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-08.jpg 689w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-08-300x201.jpg 300w" sizes="auto, (max-width: 689px) 100vw, 689px" /></p>
<p><span style="font-size: 14pt;"><strong>[建立網路服務群組物件]</strong></span><br />
(1)、建立「網路服務群組」物件<br />
點選「<strong>Create New</strong>」→「<strong>Service Group</strong>」<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6409 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-09.jpg" alt="" width="170" height="129" /></p>
<p>(2)、設定「網路服務群組」物件<br />
<strong>Group Name</strong>：輸入自訂的服務群組物件名稱，建議採用有識別性的名稱，方便日後操作識別用，本範例輸入Ailog.tw-Service。</p>
<p><strong>Comments</strong>：輸入類別名稱的注解，方便識別類別用途。</p>
<p><strong>Color：</strong>設定「服務群組」物件的顯示顏色。</p>
<p><strong>Members</strong>：設定要綑綁在一起的服務。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6410 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-10.jpg" alt="" width="413" height="170" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-10.jpg 413w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-10-300x123.jpg 300w" sizes="auto, (max-width: 413px) 100vw, 413px" /></p>
<p>(3)、選取要綑綁在一起的服務<br />
在網路服務物件列表清單中，選取要綑綁的服務物件項目。<br />
<img loading="lazy" decoding="async" class="alignnone size-medium wp-image-6411" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-11-300x148.jpg" alt="" width="300" height="148" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-11-300x148.jpg 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-11.jpg 303w" sizes="auto, (max-width: 300px) 100vw, 300px" /></p>
<p>(4)、選取服務完成畫面<br />
本範例選取了「Synology-Drive」及「tomcat」<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-6412" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-12.jpg" alt="" width="299" height="135" /></p>
<p>(5)、完成「網路服務群組」物件<br />
點選「OK」完成「網路服務群組」物件新增步驟<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6413 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-13.jpg" alt="" width="688" height="301" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-13.jpg 688w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-13-300x131.jpg 300w" sizes="auto, (max-width: 688px) 100vw, 688px" /></p>
<p>(6)、確認「網路服務群組」物件狀態<br />
在網路服務列表中可以看見剛剛新增的「網路服務」及「網路服務群組」物件。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6414 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-14.jpg" alt="" width="556" height="298" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-14.jpg 556w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-14-300x161.jpg 300w" sizes="auto, (max-width: 556px) 100vw, 556px" /></p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>跟小編一起學-FortiGate防火牆-設定「網路位址」物件(Console設定方式)</title>
		<link>https://ailog.tw/lifelog/2021/01/17/fortigate-address-objects2/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sun, 17 Jan 2021 15:33:10 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[40F]]></category>
		<category><![CDATA[60B]]></category>
		<category><![CDATA[60D]]></category>
		<category><![CDATA[60E]]></category>
		<category><![CDATA[80C]]></category>
		<category><![CDATA[Address]]></category>
		<category><![CDATA[Address Group]]></category>
		<category><![CDATA[cmd]]></category>
		<category><![CDATA[command]]></category>
		<category><![CDATA[command line]]></category>
		<category><![CDATA[console]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[物件]]></category>
		<category><![CDATA[網路位址]]></category>
		<category><![CDATA[網路位址群組]]></category>
		<category><![CDATA[跟小編一起學-FortiGate防火牆-設定「網路位址」物件(Console設定方式)]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=6284</guid>

					<description><![CDATA[今天小編要介紹的單元是透過Console方式設定FortiGate防火牆的「網路位址」物件，「網路位址」被使用 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/01/17/fortigate-address-objects2/" class="more-link">閱讀全文<span class="screen-reader-text">〈跟小編一起學-FortiGate防火牆-設定「網路位址」物件(Console設定方式)〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>今天小編要介紹的單元是透過Console方式設定FortiGate防火牆的「網路位址」物件，「網路位址」被使用在防火牆規則與VPN的設定過程，趕快跟著小編一起來了解吧。<span id="more-6284"></span></p>
<p>介紹的內容為<br />
透過Console的Command指令模式：<br />
(1)、建立IP型態的網路位址物件<br />
(2)、建立FQDN型態的網路位址物件<br />
(3)、建立IP範圍區段的網路位址物件<br />
(4)、建立國家地區型態的網路位址物件<br />
(5)、建立網路位址群組</p>
<p>一、登入系統<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5930 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user011.jpg" alt="" width="396" height="102" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user011.jpg 396w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user011-300x77.jpg 300w" sizes="auto, (max-width: 396px) 100vw, 396px" /></p>
<p>二、切換至網路位址物件設定模式<br />
輸入「config firewall address」接著按下enter送出指令，即可進入網路位址物件設定模式。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6291 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-01.jpg" alt="" width="522" height="77" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-01.jpg 522w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-01-300x44.jpg 300w" sizes="auto, (max-width: 522px) 100vw, 522px" /></p>
<p>三、新增網路位址物件<br />
(1)、建立IP型態的「網路位址」物件<br />
a.輸入「edit &#8220;TW-Yahoo-IP&#8221;」接著按下enter送出指令，即可產生一個名稱為「TW-Yahoo-IP」的「網路位址」物件。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6297 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-02-1.jpg" alt="" width="486" height="60" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-02-1.jpg 486w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-02-1-300x37.jpg 300w" sizes="auto, (max-width: 486px) 100vw, 486px" /></p>
<p>b.輸入「set subnet 180.222.102.201 255.255.255.255」接著按下enter送出指令，即可定義該物件IP位址為「180.222.102.201 255.255.255.255」。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6298 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-02-2.jpg" alt="" width="596" height="37" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-02-2.jpg 596w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-02-2-300x19.jpg 300w" sizes="auto, (max-width: 596px) 100vw, 596px" /></p>
<p>c.輸入「set associated-interface &#8220;wan1&#8243;」接著按下enter送出指令，即可定義該物件的網路介面綁定為wan1。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6299 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-02-3.jpg" alt="" width="484" height="32" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-02-3.jpg 484w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-02-3-300x20.jpg 300w" sizes="auto, (max-width: 484px) 100vw, 484px" /></p>
<p>d.輸入「set comment &#8220;台灣Yahoo網頁IP&#8221;」接著按下enter送出指令，即可定義該物件的注解為「台灣Yahoo網頁IP」，在Conosle畫面輸入中文會有亂碼畫面，但只要是採用UTF-8編碼是不影響設定結果。<br />
<span style="font-size: 12pt; color: #ff6600;">※在Console輸入中文的技巧為，先把要設定的指令在筆記本輸入好後再將指令複製進Console</span><br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6300 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-02-4.jpg" alt="" width="863" height="43" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-02-4.jpg 863w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-02-4-300x15.jpg 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-02-4-768x38.jpg 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>e.輸入「show」接著按下enter送出指令，即可查看設定結果<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6295 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-03.jpg" alt="" width="535" height="213" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-03.jpg 535w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-03-300x119.jpg 300w" sizes="auto, (max-width: 535px) 100vw, 535px" /></p>
<p>f.輸入「next」接著按下enter送出指令，即可接續設定下一個「網路位置」物件<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6296 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-04.jpg" alt="" width="390" height="68" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-04.jpg 390w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-04-300x52.jpg 300w" sizes="auto, (max-width: 390px) 100vw, 390px" /></p>
<p>(2)、建立FQDN型態的「網路位址」物件<br />
a.輸入「edit &#8220;TW-Yahoo-FQDN&#8221;」接著按下enter送出指令，即可產生一個名稱為「TW-Yahoo-FQDN」的「網路位址」物件。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6303 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-1.jpg" alt="" width="505" height="57" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-1.jpg 505w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-1-300x34.jpg 300w" sizes="auto, (max-width: 505px) 100vw, 505px" /></p>
<p>b.輸入「set type fqdn」接著按下enter送出指令，即可定義該物件的型態為FQDN。<br />
<img loading="lazy" decoding="async" class="alignnone size-medium wp-image-6304" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-2-300x38.jpg" alt="" width="300" height="38" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-2-300x38.jpg 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-2.jpg 325w" sizes="auto, (max-width: 300px) 100vw, 300px" /></p>
<p>c.輸入「set fqdn &#8220;tw.yahoo.com&#8221;」接著按下enter送出指令，即可定義該物件fqdn位址為「tw.yahoo.com」。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6305 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-3.jpg" alt="" width="420" height="41" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-3.jpg 420w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-3-300x29.jpg 300w" sizes="auto, (max-width: 420px) 100vw, 420px" /></p>
<p>d.輸入「set associated-interface &#8220;wan1&#8243;」接著按下enter送出指令，即可定義該物件的網路介面綁定為wan1。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6306 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-4.jpg" alt="" width="504" height="37" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-4.jpg 504w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-4-300x22.jpg 300w" sizes="auto, (max-width: 504px) 100vw, 504px" /></p>
<p>e.輸入「set comment &#8220;台灣Yahoo網頁Doamin Name&#8221;」接著按下enter送出指令，即可定義該物件的注解為「台灣Yahoo網頁Doamin Name」，在Conosle畫面輸入中文會有亂碼畫面，但只要是採用UTF-8編碼是不影響設定結果。<br />
<span style="font-size: 12pt; color: #ff6600;">※在Console輸入中文的技巧為，先把要設定的指令在筆記本輸入好後再將指令複製進Console</span><br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6308 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-5.jpg" alt="" width="970" height="40" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-5.jpg 970w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-5-300x12.jpg 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-5-768x32.jpg 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>f.輸入「show」接著按下enter送出指令，即可查看設定結果<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6309 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-6.jpg" alt="" width="542" height="230" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-6.jpg 542w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-6-300x127.jpg 300w" sizes="auto, (max-width: 542px) 100vw, 542px" /></p>
<p>g.輸入「next」接著按下enter送出指令，即可接續設定下一個「網路位置」物件<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6310 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-7.jpg" alt="" width="427" height="42" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-7.jpg 427w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-05-7-300x30.jpg 300w" sizes="auto, (max-width: 427px) 100vw, 427px" /></p>
<p>(3)、建立IP範圍區段的網路位址<br />
a.輸入「edit &#8220;Home-1F-Range&#8221;」接著按下enter送出指令，即可產生一個名稱為「Home-1F-Range」的「網路位址」物件。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6313 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-1.jpg" alt="" width="499" height="54" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-1.jpg 499w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-1-300x32.jpg 300w" sizes="auto, (max-width: 499px) 100vw, 499px" /></p>
<p>b.輸入「set type iprange」接著按下enter送出指令，即可定義該物件的型態為IP範圍區段。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6314 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-2.jpg" alt="" width="351" height="40" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-2.jpg 351w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-2-300x34.jpg 300w" sizes="auto, (max-width: 351px) 100vw, 351px" /></p>
<p>c.輸入「set start-ip 192.168.1.1」接著按下enter送出指令，即可定義該物件的起始IP為「192.168.1.1」。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6315 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-3.jpg" alt="" width="427" height="35" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-3.jpg 427w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-3-300x25.jpg 300w" sizes="auto, (max-width: 427px) 100vw, 427px" /></p>
<p>d.輸入「set end-ip 192.168.1.30」接著按下enter送出指令，即可定義該物件的結束IP為「192.168.1.30」。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6316 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-4.jpg" alt="" width="420" height="36" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-4.jpg 420w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-4-300x26.jpg 300w" sizes="auto, (max-width: 420px) 100vw, 420px" /></p>
<p>e.輸入「set associated-interface &#8220;internal&#8221;」接著按下enter送出指令，即可定義該物件的網路介面綁定為內部網路的internal。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6318 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-5.jpg" alt="" width="539" height="36" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-5.jpg 539w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-5-300x20.jpg 300w" sizes="auto, (max-width: 539px) 100vw, 539px" /></p>
<p>f.輸入「set comment &#8220;家裡1樓所使用IP範圍&#8221;」接著按下enter送出指令，即可定義該物件的注解為「家裡1樓所使用IP範圍」，在Conosle畫面輸入中文會有亂碼畫面，但只要是採用UTF-8編碼是不影響設定結果。<br />
<span style="font-size: 12pt; color: #ff6600;">※在Console輸入中文的技巧為，先把要設定的指令在筆記本輸入好後再將指令複製進Console</span><br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6319 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-6.jpg" alt="" width="1141" height="58" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-6.jpg 1141w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-6-300x15.jpg 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-6-1024x52.jpg 1024w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-6-768x39.jpg 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>g.輸入「show」接著按下enter送出指令，即可查看設定結果<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6326 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-7.jpg" alt="" width="540" height="253" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-7.jpg 540w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-7-300x141.jpg 300w" sizes="auto, (max-width: 540px) 100vw, 540px" /></p>
<p>h.輸入「next」接著按下enter送出指令，即可接續設定下一個「網路位置」物件<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6327 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-8.jpg" alt="" width="403" height="40" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-8.jpg 403w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-06-8-300x30.jpg 300w" sizes="auto, (max-width: 403px) 100vw, 403px" /></p>
<p>(4)、建立國家地區型態的網路位址<br />
a.輸入「edit &#8220;Taiwan&#8221;」接著按下enter送出指令，即可產生一個名稱為「Taiwan」的「網路位址」物件。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6328 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-07-1.jpg" alt="" width="430" height="59" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-07-1.jpg 430w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-07-1-300x41.jpg 300w" sizes="auto, (max-width: 430px) 100vw, 430px" /></p>
<p>b.輸入「set type geography」接著按下enter送出指令，即可定義該物件的型態為國家地區。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6329 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-07-2.jpg" alt="" width="310" height="42" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-07-2.jpg 310w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-07-2-300x41.jpg 300w" sizes="auto, (max-width: 310px) 100vw, 310px" /></p>
<p>c.輸入「set country &#8220;TW&#8221;」接著按下enter送出指令，即可定義該物件的國家地區為「Taiwan」。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6330 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-07-3.jpg" alt="" width="281" height="38" /></p>
<p>d.輸入「set associated-interface &#8220;wan1&#8243;」接著按下enter送出指令，即可定義該物件的網路介面綁定為外部網路的wan1。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6331 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-07-4.jpg" alt="" width="428" height="42" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-07-4.jpg 428w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-07-4-300x29.jpg 300w" sizes="auto, (max-width: 428px) 100vw, 428px" /></p>
<p>e.輸入「set comment &#8220;台灣來源IP&#8221;」接著按下enter送出指令，即可定義該物件的注解為「台灣來源IP」，在Conosle畫面輸入中文會有亂碼畫面，但只要是採用UTF-8編碼是不影響設定結果。<br />
<span style="font-size: 12pt; color: #ff6600;">※在Console輸入中文的技巧為，先把要設定的指令在筆記本輸入好後再將指令複製進Console</span><br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6332 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-07-5.jpg" alt="" width="769" height="42" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-07-5.jpg 769w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-07-5-300x16.jpg 300w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>f.輸入「show」接著按下enter送出指令，即可查看設定結果<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6333 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-07-6.jpg" alt="" width="537" height="230" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-07-6.jpg 537w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-07-6-300x128.jpg 300w" sizes="auto, (max-width: 537px) 100vw, 537px" /></p>
<p>g.輸入「next」接著按下enter送出指令，即可接續設定下一個「網路位置」物件<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6334 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-07-7.jpg" alt="" width="335" height="44" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-07-7.jpg 335w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-07-7-300x39.jpg 300w" sizes="auto, (max-width: 335px) 100vw, 335px" /></p>
<p>四、離開網路位址物件設定模式<br />
輸入「end」接著按下enter送出指令，即可離開網路位址物件設定模式<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6335 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-08.jpg" alt="" width="339" height="66" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-08.jpg 339w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-08-300x58.jpg 300w" sizes="auto, (max-width: 339px) 100vw, 339px" /></p>
<p>五、切換至網路位址群組物件設定模式<br />
輸入「config firewall addrgrp」接著按下enter送出指令，即可進入網路位址群組物件設定模式。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6337 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-09.jpg" alt="" width="438" height="81" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-09.jpg 438w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-09-300x55.jpg 300w" sizes="auto, (max-width: 438px) 100vw, 438px" /></p>
<p>六、新增網路位址群組物件<br />
(1)、輸入「edit &#8220;Yahoo-WEB&#8221;」接著按下enter送出指令，即可產生一個名稱為「Yahoo-WEB」的「網路位址群組」物件。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6338 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-10-1.jpg" alt="" width="459" height="56" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-10-1.jpg 459w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-10-1-300x37.jpg 300w" sizes="auto, (max-width: 459px) 100vw, 459px" /></p>
<p>(2)、輸入「set member &#8220;TW-Yahoo-FQDN&#8221; &#8220;TW-Yahoo-IP&#8221;」接著按下enter送出指令，即可將「TW-Yahoo-FQDN」與「TW-Yahoo-IP」這兩個網路位址物件綁定在該群組。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6339 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-10-2.jpg" alt="" width="554" height="43" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-10-2.jpg 554w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-10-2-300x23.jpg 300w" sizes="auto, (max-width: 554px) 100vw, 554px" /></p>
<p>(3)、輸入「set comment &#8220;台灣YAHOO網頁&#8221;」接著按下enter送出指令，即可定義該物件的注解為「台灣YAHOO網頁」，在Conosle畫面輸入中文會有亂碼畫面，但只要是採用UTF-8編碼是不影響設定結果。<br />
<span style="font-size: 12pt; color: #ff6600;">※在Console輸入中文的技巧為，先把要設定的指令在筆記本輸入好後再將指令複製進Console<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6340 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-10-3.jpg" alt="" width="816" height="45" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-10-3.jpg 816w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-10-3-300x17.jpg 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-10-3-768x42.jpg 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /><br />
</span></p>
<p>(4)、輸入「show」接著按下enter送出指令，即可查看設定結果<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6342 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-10-4.jpg" alt="" width="540" height="177" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-10-4.jpg 540w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-10-4-300x98.jpg 300w" sizes="auto, (max-width: 540px) 100vw, 540px" /></p>
<p>(5)、輸入「next」接著按下enter送出指令，即可接續設定下一個「網路位置群組」物件<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6344 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-10-5.jpg" alt="" width="358" height="76" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-10-5.jpg 358w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-10-5-300x64.jpg 300w" sizes="auto, (max-width: 358px) 100vw, 358px" /></p>
<p>六、離開網路位址群組物件設定模式<br />
輸入「end」接著按下enter送出指令，即可離開網路位址群組物件設定模式<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6345 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-11.jpg" alt="" width="349" height="69" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-11.jpg 349w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-cmd-11-300x59.jpg 300w" sizes="auto, (max-width: 349px) 100vw, 349px" /></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>跟小編一起學-FortiGate防火牆-設定「網路位址」物件(web設定方式)</title>
		<link>https://ailog.tw/lifelog/2021/01/16/fortigate-address-objects/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sat, 16 Jan 2021 09:18:20 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[40F]]></category>
		<category><![CDATA[60B]]></category>
		<category><![CDATA[60D]]></category>
		<category><![CDATA[60E]]></category>
		<category><![CDATA[80C]]></category>
		<category><![CDATA[Address]]></category>
		<category><![CDATA[Address Group]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[物件]]></category>
		<category><![CDATA[網路位址]]></category>
		<category><![CDATA[網路位址群組]]></category>
		<category><![CDATA[跟小編一起學-FortiGate防火牆-設定「網路位址」物件(web設定方式)]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=6235</guid>

					<description><![CDATA[今天小編要介紹的單元是設定FortiGate防火牆的「網路位址」物件，「網路位址」被使用在防火牆規則與VPN的 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/01/16/fortigate-address-objects/" class="more-link">閱讀全文<span class="screen-reader-text">〈跟小編一起學-FortiGate防火牆-設定「網路位址」物件(web設定方式)〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>今天小編要介紹的單元是設定FortiGate防火牆的「網路位址」物件，「網路位址」被使用在防火牆規則與VPN的設定過程，趕快跟著小編一起來了解吧。<span id="more-6235"></span></p>
<p>介紹的內容為<br />
透過web管理畫面：<br />
(1)、建立IP型態的網路位址物件<br />
(2)、建立FQDN型態的網路位址物件<br />
(3)、建立IP範圍區段的網路位址物件<br />
(4)、建立國家地區型態的網路位址物件<br />
(5)、建立網路位址群組</p>
<p>[web管理畫面]<br />
(1)、登入系統<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5823 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-LOGIN-08.jpg" alt="" width="381" height="235" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-LOGIN-08.jpg 381w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-LOGIN-08-300x185.jpg 300w" sizes="auto, (max-width: 381px) 100vw, 381px" /></p>
<p>(2)、切換至網路位址物件設定畫面<br />
點選「Policy &amp; Objects」→「Addresses」<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6240 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-01.jpg" alt="" width="251" height="247" /></p>
<p>(2)、新增網路位址物件<br />
點選「Create New」→「Address」<br />
<img loading="lazy" decoding="async" class="alignnone size-medium wp-image-6244" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-02-300x95.jpg" alt="" width="300" height="95" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-02-300x95.jpg 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-02.jpg 346w" sizes="auto, (max-width: 300px) 100vw, 300px" /></p>
<p>(3)、網路位址設定畫面功能介紹<br />
<strong>Name：</strong>定義「網路位址」物件的名稱，方便日後引用的識別性。<br />
<strong>Color：</strong>設定「網路位址」物件的顯示顏色。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6246 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-03.jpg" alt="" width="497" height="111" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-03.jpg 497w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-03-300x67.jpg 300w" sizes="auto, (max-width: 497px) 100vw, 497px" /></p>
<p><strong>Type：</strong>定義「網路位址」物件的型態，共有下列5種類型。<br />
(a)、FQDN：Domain Name的定義方式(例如：tw.yahoo.com)。</p>
<p>(b)、Geography：國家地區(例如：Taiwan)。</p>
<p>(c)、IP Range：IP範圍區段(例如：192.168.1.1-192.168.1.254)。</p>
<p>(d)、Subnet：單一IP(例如：192.168.1.1/32)或是網段(例如：192.168.1.0/24)。</p>
<p>(e)、Fabric Connector Address：SDN(Software-Defined Networking，軟體定義網路)，支援下列廠商。<br />
●Application Centric Infrastructure (ACI)<br />
●Amazon Web Services (AWS)<br />
●Microsoft Azure<br />
●VMware NSX<br />
●Nuage Virtualized Services Platform<br />
●Oracle Cloud Infrastructure (OCI)<br />
●OpenStack (Horizon)<br />
●Google Cloud Platform (GCP)</p>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-6247 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-04.jpg" alt="" width="502" height="138" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-04.jpg 502w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-04-300x82.jpg 300w" sizes="auto, (max-width: 502px) 100vw, 502px" /></p>
<p><strong>Interface：</strong>定義「網路位址」物件所屬介面，當「網路位址」定義在某個介面上，在其他介面就看不到該「網路位址」，通常會用來區分內部網路及外部網路「網路位址，避免再設定防火牆規則時誤選「網路位址」，預設有下列6種介面。<br />
(a)、Internal：內部網路介面。<br />
(b)、SSL-VPN：SSL VPN介面。<br />
(c)、dmz：非軍事區域介面。<br />
(d)、wan1：外部網路介面1<br />
(e)、wan2：外部網路介面2<br />
(f)、any：不限制綁定在任何介面。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6249 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-05.jpg" alt="" width="496" height="211" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-05.jpg 496w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-05-300x128.jpg 300w" sizes="auto, (max-width: 496px) 100vw, 496px" /></p>
<p><strong>Show in Address List：</strong>是否顯示在「網路位址」清單，有些情境會透過該設定來隱藏「網路位址」不顯示在候選設定清單內，避免干擾設定、增加選取「網路位址」的複雜度，但通常都還是採用預設的顯示設定狀態。<img loading="lazy" decoding="async" class="alignnone size-full wp-image-6251" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-06.jpg" alt="" width="214" height="36" /></p>
<p><strong>Static Route Configuration：</strong>顯示在靜態路由的「網路位址」候選清單。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6252 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-07.jpg" alt="" width="221" height="27" /></p>
<p><strong>Comments：</strong>定義「網路位址」物件的注釋說明，用途跟「Name」有異曲同工之處，但這個欄位可以輸入的字元較無限制，可以更清楚的紀錄該「網路位址」的用途。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6253 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-08.jpg" alt="" width="514" height="39" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-08.jpg 514w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-08-300x23.jpg 300w" sizes="auto, (max-width: 514px) 100vw, 514px" /></p>
<p><strong>Tag：</strong>定義「網路位址」物件的標籤，當設定值很多時，可以透過標籤的屬性來快速區分，但在實務上小編還沒遇過這樣複雜的狀況，需要透過標籤來分類。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6254 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-09.jpg" alt="" width="318" height="75" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-09.jpg 318w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-09-300x71.jpg 300w" sizes="auto, (max-width: 318px) 100vw, 318px" /></p>
<p>(4)、建立IP型態的「網路位址」物件<br />
Name：輸入「TW-Yahoo-IP」方便在選取「網路位址」時快速辨別。<br />
Type：選擇「Subnet」<br />
Subnet / IP Range：輸入IP或網段位址，本範例輸入「180.222.102.201」。<br />
Interface：選擇「wan1」<br />
Comments：輸入注解說明，本範例輸入「台灣Yahoo網頁IP」。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6256 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-10.jpg" alt="" width="684" height="450" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-10.jpg 684w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-10-300x197.jpg 300w" sizes="auto, (max-width: 684px) 100vw, 684px" /></p>
<p>(5)、建立FQDN型態的網路位址<br />
Name：輸入「TW-Yahoo-FQDN」方便在選取「網路位址」時快速辨別。<br />
Type：選擇「FQDN」<br />
FQDN：本範例輸入「tw.yahoo.com」。<br />
Interface：選擇「wan1」<br />
Comments：輸入注解說明，本範例輸入「台灣Yahoo網頁Doamin Name」。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6258 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-11.jpg" alt="" width="674" height="458" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-11.jpg 674w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-11-300x204.jpg 300w" sizes="auto, (max-width: 674px) 100vw, 674px" /></p>
<p>(6)、建立IP範圍區段的網路位址<br />
Name：輸入「Home-1F-Range」方便在選取「網路位址」時快速辨別。<br />
Type：選擇「 IP Range」<br />
Subnet / IP Range：本範例輸入「192.168.1.1-192.168.1.30」。<br />
Interface：選擇「Internal」<br />
Comments：輸入注解說明，本範例輸入「家裡1樓所使用IP範圍」。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6260 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-12.jpg" alt="" width="672" height="421" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-12.jpg 672w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-12-300x188.jpg 300w" sizes="auto, (max-width: 672px) 100vw, 672px" /></p>
<p>(7)、建立國家地區型態的網路位址<br />
Name：輸入「Taiwan」方便在選取「網路位址」時快速辨別。<br />
Type：選擇「 Geography」<br />
Country/Region：本範例輸入「Taiwan」。<br />
Interface：選擇「wan1」<br />
Comments：輸入注解說明，本範例輸入「台灣來源IP」。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6263 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-13.jpg" alt="" width="679" height="423" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-13.jpg 679w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-13-300x187.jpg 300w" sizes="auto, (max-width: 679px) 100vw, 679px" /></p>
<p>(8)、建立網路位址群組物件<br />
點選「Create New」→「Address Group」<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-6266" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-14.jpg" alt="" width="227" height="114" /></p>
<p>Group Name：輸入「Yahoo-WEB」方便在選取「網路位址群組」時快速辨別。<br />
Members：選取想要綁定在一起的「網路位址」，本範例選取了「TW-Yahoo-FQDN」、「TW-Yahoo-IP」。<br />
Comments：輸入注解說明，本範例輸入「台灣YAHOO網頁」。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6268 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-15.jpg" alt="" width="801" height="541" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-15.jpg 801w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-15-300x203.jpg 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-15-768x519.jpg 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
