<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>跟小編一起學-FortiGate防火牆-設定「網路位址」物件(web設定方式) &#8211; 21點情報網</title>
	<atom:link href="https://ailog.tw/lifelog/tag/%E8%B7%9F%E5%B0%8F%E7%B7%A8%E4%B8%80%E8%B5%B7%E5%AD%B8-fortigate%E9%98%B2%E7%81%AB%E7%89%86-%E8%A8%AD%E5%AE%9A%E3%80%8C%E7%B6%B2%E8%B7%AF%E4%BD%8D%E5%9D%80%E3%80%8D%E7%89%A9%E4%BB%B6web%E8%A8%AD/feed/" rel="self" type="application/rss+xml" />
	<link>https://ailog.tw/lifelog</link>
	<description></description>
	<lastBuildDate>Sat, 23 Jan 2021 06:14:58 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>
	<item>
		<title>跟小編一起學-FortiGate防火牆-設定「網路位址」物件(web設定方式)</title>
		<link>https://ailog.tw/lifelog/2021/01/16/fortigate-address-objects/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sat, 16 Jan 2021 09:18:20 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[40F]]></category>
		<category><![CDATA[60B]]></category>
		<category><![CDATA[60D]]></category>
		<category><![CDATA[60E]]></category>
		<category><![CDATA[80C]]></category>
		<category><![CDATA[Address]]></category>
		<category><![CDATA[Address Group]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[物件]]></category>
		<category><![CDATA[網路位址]]></category>
		<category><![CDATA[網路位址群組]]></category>
		<category><![CDATA[跟小編一起學-FortiGate防火牆-設定「網路位址」物件(web設定方式)]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=6235</guid>

					<description><![CDATA[今天小編要介紹的單元是設定FortiGate防火牆的「網路位址」物件，「網路位址」被使用在防火牆規則與VPN的 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/01/16/fortigate-address-objects/" class="more-link">閱讀全文<span class="screen-reader-text">〈跟小編一起學-FortiGate防火牆-設定「網路位址」物件(web設定方式)〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>今天小編要介紹的單元是設定FortiGate防火牆的「網路位址」物件，「網路位址」被使用在防火牆規則與VPN的設定過程，趕快跟著小編一起來了解吧。<span id="more-6235"></span></p>
<p>介紹的內容為<br />
透過web管理畫面：<br />
(1)、建立IP型態的網路位址物件<br />
(2)、建立FQDN型態的網路位址物件<br />
(3)、建立IP範圍區段的網路位址物件<br />
(4)、建立國家地區型態的網路位址物件<br />
(5)、建立網路位址群組</p>
<p>[web管理畫面]<br />
(1)、登入系統<br />
<img fetchpriority="high" decoding="async" class="alignnone wp-image-5823 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-LOGIN-08.jpg" alt="" width="381" height="235" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-LOGIN-08.jpg 381w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-LOGIN-08-300x185.jpg 300w" sizes="(max-width: 381px) 100vw, 381px" /></p>
<p>(2)、切換至網路位址物件設定畫面<br />
點選「Policy &amp; Objects」→「Addresses」<br />
<img decoding="async" class="alignnone wp-image-6240 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-01.jpg" alt="" width="251" height="247" /></p>
<p>(2)、新增網路位址物件<br />
點選「Create New」→「Address」<br />
<img decoding="async" class="alignnone size-medium wp-image-6244" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-02-300x95.jpg" alt="" width="300" height="95" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-02-300x95.jpg 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-02.jpg 346w" sizes="(max-width: 300px) 100vw, 300px" /></p>
<p>(3)、網路位址設定畫面功能介紹<br />
<strong>Name：</strong>定義「網路位址」物件的名稱，方便日後引用的識別性。<br />
<strong>Color：</strong>設定「網路位址」物件的顯示顏色。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6246 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-03.jpg" alt="" width="497" height="111" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-03.jpg 497w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-03-300x67.jpg 300w" sizes="auto, (max-width: 497px) 100vw, 497px" /></p>
<p><strong>Type：</strong>定義「網路位址」物件的型態，共有下列5種類型。<br />
(a)、FQDN：Domain Name的定義方式(例如：tw.yahoo.com)。</p>
<p>(b)、Geography：國家地區(例如：Taiwan)。</p>
<p>(c)、IP Range：IP範圍區段(例如：192.168.1.1-192.168.1.254)。</p>
<p>(d)、Subnet：單一IP(例如：192.168.1.1/32)或是網段(例如：192.168.1.0/24)。</p>
<p>(e)、Fabric Connector Address：SDN(Software-Defined Networking，軟體定義網路)，支援下列廠商。<br />
●Application Centric Infrastructure (ACI)<br />
●Amazon Web Services (AWS)<br />
●Microsoft Azure<br />
●VMware NSX<br />
●Nuage Virtualized Services Platform<br />
●Oracle Cloud Infrastructure (OCI)<br />
●OpenStack (Horizon)<br />
●Google Cloud Platform (GCP)</p>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-6247 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-04.jpg" alt="" width="502" height="138" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-04.jpg 502w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-04-300x82.jpg 300w" sizes="auto, (max-width: 502px) 100vw, 502px" /></p>
<p><strong>Interface：</strong>定義「網路位址」物件所屬介面，當「網路位址」定義在某個介面上，在其他介面就看不到該「網路位址」，通常會用來區分內部網路及外部網路「網路位址，避免再設定防火牆規則時誤選「網路位址」，預設有下列6種介面。<br />
(a)、Internal：內部網路介面。<br />
(b)、SSL-VPN：SSL VPN介面。<br />
(c)、dmz：非軍事區域介面。<br />
(d)、wan1：外部網路介面1<br />
(e)、wan2：外部網路介面2<br />
(f)、any：不限制綁定在任何介面。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6249 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-05.jpg" alt="" width="496" height="211" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-05.jpg 496w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-05-300x128.jpg 300w" sizes="auto, (max-width: 496px) 100vw, 496px" /></p>
<p><strong>Show in Address List：</strong>是否顯示在「網路位址」清單，有些情境會透過該設定來隱藏「網路位址」不顯示在候選設定清單內，避免干擾設定、增加選取「網路位址」的複雜度，但通常都還是採用預設的顯示設定狀態。<img loading="lazy" decoding="async" class="alignnone size-full wp-image-6251" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-06.jpg" alt="" width="214" height="36" /></p>
<p><strong>Static Route Configuration：</strong>顯示在靜態路由的「網路位址」候選清單。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6252 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-07.jpg" alt="" width="221" height="27" /></p>
<p><strong>Comments：</strong>定義「網路位址」物件的注釋說明，用途跟「Name」有異曲同工之處，但這個欄位可以輸入的字元較無限制，可以更清楚的紀錄該「網路位址」的用途。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6253 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-08.jpg" alt="" width="514" height="39" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-08.jpg 514w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-08-300x23.jpg 300w" sizes="auto, (max-width: 514px) 100vw, 514px" /></p>
<p><strong>Tag：</strong>定義「網路位址」物件的標籤，當設定值很多時，可以透過標籤的屬性來快速區分，但在實務上小編還沒遇過這樣複雜的狀況，需要透過標籤來分類。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6254 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-09.jpg" alt="" width="318" height="75" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-09.jpg 318w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-09-300x71.jpg 300w" sizes="auto, (max-width: 318px) 100vw, 318px" /></p>
<p>(4)、建立IP型態的「網路位址」物件<br />
Name：輸入「TW-Yahoo-IP」方便在選取「網路位址」時快速辨別。<br />
Type：選擇「Subnet」<br />
Subnet / IP Range：輸入IP或網段位址，本範例輸入「180.222.102.201」。<br />
Interface：選擇「wan1」<br />
Comments：輸入注解說明，本範例輸入「台灣Yahoo網頁IP」。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6256 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-10.jpg" alt="" width="684" height="450" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-10.jpg 684w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-10-300x197.jpg 300w" sizes="auto, (max-width: 684px) 100vw, 684px" /></p>
<p>(5)、建立FQDN型態的網路位址<br />
Name：輸入「TW-Yahoo-FQDN」方便在選取「網路位址」時快速辨別。<br />
Type：選擇「FQDN」<br />
FQDN：本範例輸入「tw.yahoo.com」。<br />
Interface：選擇「wan1」<br />
Comments：輸入注解說明，本範例輸入「台灣Yahoo網頁Doamin Name」。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6258 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-11.jpg" alt="" width="674" height="458" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-11.jpg 674w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-11-300x204.jpg 300w" sizes="auto, (max-width: 674px) 100vw, 674px" /></p>
<p>(6)、建立IP範圍區段的網路位址<br />
Name：輸入「Home-1F-Range」方便在選取「網路位址」時快速辨別。<br />
Type：選擇「 IP Range」<br />
Subnet / IP Range：本範例輸入「192.168.1.1-192.168.1.30」。<br />
Interface：選擇「Internal」<br />
Comments：輸入注解說明，本範例輸入「家裡1樓所使用IP範圍」。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6260 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-12.jpg" alt="" width="672" height="421" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-12.jpg 672w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-12-300x188.jpg 300w" sizes="auto, (max-width: 672px) 100vw, 672px" /></p>
<p>(7)、建立國家地區型態的網路位址<br />
Name：輸入「Taiwan」方便在選取「網路位址」時快速辨別。<br />
Type：選擇「 Geography」<br />
Country/Region：本範例輸入「Taiwan」。<br />
Interface：選擇「wan1」<br />
Comments：輸入注解說明，本範例輸入「台灣來源IP」。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6263 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-13.jpg" alt="" width="679" height="423" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-13.jpg 679w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-13-300x187.jpg 300w" sizes="auto, (max-width: 679px) 100vw, 679px" /></p>
<p>(8)、建立網路位址群組物件<br />
點選「Create New」→「Address Group」<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-6266" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-14.jpg" alt="" width="227" height="114" /></p>
<p>Group Name：輸入「Yahoo-WEB」方便在選取「網路位址群組」時快速辨別。<br />
Members：選取想要綁定在一起的「網路位址」，本範例選取了「TW-Yahoo-FQDN」、「TW-Yahoo-IP」。<br />
Comments：輸入注解說明，本範例輸入「台灣YAHOO網頁」。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6268 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-15.jpg" alt="" width="801" height="541" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-15.jpg 801w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-15-300x203.jpg 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Address-15-768x519.jpg 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
