<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>fortigate &#8211; 21點情報網</title>
	<atom:link href="https://ailog.tw/lifelog/tag/fortigate/feed/" rel="self" type="application/rss+xml" />
	<link>https://ailog.tw/lifelog</link>
	<description></description>
	<lastBuildDate>Mon, 27 Oct 2025 02:41:01 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>
	<item>
		<title>FortiGate防火牆如何自訂認證服務port</title>
		<link>https://ailog.tw/lifelog/2025/10/27/fgt-auth-port/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Mon, 27 Oct 2025 02:41:01 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[auth]]></category>
		<category><![CDATA[fortigate]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=18188</guid>

					<description><![CDATA[FortiGate防火牆預設支援進行認證的服務port有「https、http、telnet、ftp」等，但有 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2025/10/27/fgt-auth-port/" class="more-link">閱讀全文<span class="screen-reader-text">〈FortiGate防火牆如何自訂認證服務port〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>FortiGate防火牆預設支援進行認證的服務port有「https、http、telnet、ftp」等，但有些服務的port比較特殊，因此就得另外設定，快跟著小編一起來了解如何設定吧!</p>
<p><span id="more-18188"></span></p>
<p><span style="color: #0000ff;">一、FortiGate防火牆預設支援進行認證的服務Port</span><br />
<img fetchpriority="high" decoding="async" class="alignnone wp-image-18191 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2025/10/fgt-auth-port-01.png" alt="" width="910" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2025/10/fgt-auth-port-01.png 910w, https://ailog.tw/lifelog/wp-content/uploads/2025/10/fgt-auth-port-01-300x132.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2025/10/fgt-auth-port-01-768x338.png 768w" sizes="(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p><span style="color: #0000ff;"><strong>二、透過「Console或SSH」登入防火牆</strong></span></p>
<p><strong><span style="color: #0000ff;">三、新增自訂服務port</span></strong><br />
(1)、進入使用者設定模式 (User Setting)</p>
<pre><span style="font-family: verdana, geneva;">config user setting</span></pre>
<p>(2)、進入認證埠號設定 (Auth-Ports)</p>
<pre><span style="font-family: verdana, geneva;">config auth-ports</span></pre>
<p>(3)、新增一個設定，指定您的自訂埠號</p>
<pre><span style="font-family: verdana, geneva;">edit 1</span>
<span style="font-family: verdana, geneva;">set type http</span>
<span style="font-family: verdana, geneva;">set port 20001</span>
<span style="font-family: verdana, geneva;">next</span></pre>
<p>※如果該服務是https，則設定「<span style="font-family: verdana, geneva;"><span class="hljs-built_in">set</span> <span class="hljs-built_in">type</span> <span style="color: #ff0000;">https</span></span>」</p>
<p>(4)、在防火牆規則中，使用對應的服務port並且設定需要帳號認證，即可順利啟用</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FortiGate使用7.4.1韌體還原出場預設值後SSL VPN功能消失了?</title>
		<link>https://ailog.tw/lifelog/2025/01/18/fortigate7-4-1-sslvpn/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sat, 18 Jan 2025 12:54:13 +0000</pubDate>
				<category><![CDATA[好康相報]]></category>
		<category><![CDATA[7.4.1]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[sslvpn]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=17875</guid>

					<description><![CDATA[FortiGate在韌體7.4.1版本開始，針對硬體設備記憶體2G(含)以下的機種功能有所調整，因此如果新的F &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2025/01/18/fortigate7-4-1-sslvpn/" class="more-link">閱讀全文<span class="screen-reader-text">〈FortiGate使用7.4.1韌體還原出場預設值後SSL VPN功能消失了?〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>FortiGate在韌體7.4.1版本開始，針對硬體設備記憶體2G(含)以下的機種功能有所調整，因此如果新的FortiGate設備使用7.4.1韌體或是在7.4.1韌體的模式下恢復原廠預設值，那將看不到SSL VPN的功能選項，老天~~~~~<br />
快跟著小編一起了解是怎麼回事吧!</p>
<p><span id="more-17875"></span></p>
<p>FortiGate的FortiOS隨著功能越來越強大，韌體檔案跟所使用的硬體資源也越來越大，因此記憶體較小的機種從7.4.1韌體版本連功能都開始被閹割了。</p>
<p>FortiGate不採計授權人數的SSL VPN功能，相信是大家相當喜歡的一個功能，但該SSL VPN功能是不支援硬體加速的，因此可連線多少人是完全依賴硬體的效能，因此記憶體較小的機種，從韌體7.4.1開始預設會將SSL VPN關閉，但如果升級前就已啟動SSL VPN的話，會保持可運作。</p>
<p>FortiOS 7.4.1韌體開始，預設只能看的到IPsec VPN功能。<br />
<img decoding="async" class="alignnone wp-image-17880 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate7-4-4-sslvpn-02.png" alt="" width="571" height="521" srcset="https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate7-4-4-sslvpn-02.png 571w, https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate7-4-4-sslvpn-02-300x274.png 300w" sizes="(max-width: 571px) 100vw, 571px" /></p>
<p>升級韌體後功能表現：<br />
<img decoding="async" class="alignnone wp-image-17878 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate7-4-4-sslvpn-01-1.png" alt="" width="1180" height="285" srcset="https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate7-4-4-sslvpn-01-1.png 1180w, https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate7-4-4-sslvpn-01-1-300x72.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate7-4-4-sslvpn-01-1-1024x247.png 1024w, https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate7-4-4-sslvpn-01-1-768x185.png 768w" sizes="(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>原廠手冊說明：<br />
<a href="https://docs.fortinet.com/document/fortigate/7.4.0/new-features/233856/update-ssl-vpn-default-behavior-and-visibility-in-the-gui-7-4-1">https://docs.fortinet.com/document/fortigate/7.4.0/new-features/233856/update-ssl-vpn-default-behavior-and-visibility-in-the-gui-7-4-1</a></p>
<p>但如果還是需要SSL VPN功能，還是可以透過指令模式開啟該功能的，請參考下列方式進行：</p>
<p>啟用<strong>[網頁功能選項]</strong>顯示，在console或SSH模式下輸入以下<span style="font-family: verdana, geneva; font-size: 1rem;">指令語法：</span></p>
<pre>config system settings
set gui-sslvpn disable
end</pre>
<p>啟用[SSL VPN Web模式]，在console或SSH模式下輸入以下<span style="font-family: verdana, geneva; font-size: 1rem;">指</span><span style="font-family: verdana, geneva; font-size: 1rem;">令語法：</span></p>
<pre>config system global
set sslvpn-web-mode disable
end</pre>
<p>執行以上兩個指令後，SSL VPN就完全開啟瞜。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-17883 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate7-4-4-sslvpn-03.png" alt="" width="576" height="506" srcset="https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate7-4-4-sslvpn-03.png 576w, https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate7-4-4-sslvpn-03-300x264.png 300w" sizes="auto, (max-width: 576px) 100vw, 576px" /></p>
<p>但在畫面上依然有奉勸各位，盡早放棄SSL VPN改用IPsec或ZTNA才是長久之計，不知道是針對小記憶體的機種，還是Fortinet已經修補SSL VPN的CVE漏洞修到心累了呢?</p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FortiGate記憶體2GB的機種，7.4.4版本將不再支援代理相關功能。</title>
		<link>https://ailog.tw/lifelog/2025/01/18/fortigate-2g-7-4-4/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sat, 18 Jan 2025 12:15:46 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[2g]]></category>
		<category><![CDATA[7.4.4]]></category>
		<category><![CDATA[fortigate]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=17866</guid>

					<description><![CDATA[FortiGate官方技術手冊指出，在7.4.4韌體版本之後，針對2G記憶體的硬體機種，將會拿掉部分功能，老天 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2025/01/18/fortigate-2g-7-4-4/" class="more-link">閱讀全文<span class="screen-reader-text">〈FortiGate記憶體2GB的機種，7.4.4版本將不再支援代理相關功能。〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>FortiGate官方技術手冊指出，在7.4.4韌體版本之後，針對2G記憶體的硬體機種，將會拿掉部分功能，老天啊~~~~~快來跟小編了解一下有哪些機種會被影響吧!</p>
<p><span id="more-17866"></span></p>
<p>FortiGate硬體2G記憶體的機種有：<br />
FortiGate/FortiWiFi 40F、60E 、60F、80E 和 90E(包含同機種系列，例如4G GSM版本或內建硬碟的61F版本)</p>
<p>怎麼檢查設備記憶體大小：<br />
請參考小編其他的文章說明~<br />
<a href="https://ailog.tw/lifelog/2025/01/18/fortigate-route-max/">https://ailog.tw/lifelog/2025/01/18/fortigate-route-max/</a></p>
<p>官方文件：<br />
<a href="https://docs.fortinet.com/document/fortigate/7.4.0/new-features/291852/memory-usage-reduced-on-fortigate-models-with-2-gb-ram-7-4-2">https://docs.fortinet.com/document/fortigate/7.4.0/new-features/291852/memory-usage-reduced-on-fortigate-models-with-2-gb-ram-7-4-2</a></p>
<p>那被拿掉的功能有哪些呢?<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-17869 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate-2g-7-4-4-01.png" alt="" width="648" height="419" srcset="https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate-2g-7-4-4-01.png 648w, https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate-2g-7-4-4-01-300x194.png 300w" sizes="auto, (max-width: 648px) 100vw, 648px" /></p>
<p>官方文件說明：<br />
<a href="https://docs.fortinet.com/document/fortigate/7.4.0/new-features/519079/proxy-related-features-no-longer-supported-on-fortigate-2-gb-ram-models-7-4-4">https://docs.fortinet.com/document/fortigate/7.4.0/new-features/519079/proxy-related-features-no-longer-supported-on-fortigate-2-gb-ram-models-7-4-4</a></p>
<p>總之網友們要升級7.4.4版本時務必先了解目前有用到那些Proxy模式的防護功能，避免升級上去後防護結果不如原本的規劃。</p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FortiGate防火牆動態路由上限筆數</title>
		<link>https://ailog.tw/lifelog/2025/01/18/fortigate-route-max/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sat, 18 Jan 2025 11:35:51 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[dynamic routes]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[FortiOS]]></category>
		<category><![CDATA[max value]]></category>
		<category><![CDATA[memory size]]></category>
		<category><![CDATA[OSPF]]></category>
		<category><![CDATA[RIP]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=17859</guid>

					<description><![CDATA[在路由器或L3 Switch的規格表中，通常可以很簡單的找到路由上限筆數(max value)，但FortiG &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2025/01/18/fortigate-route-max/" class="more-link">閱讀全文<span class="screen-reader-text">〈FortiGate防火牆動態路由上限筆數〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>在路由器或L3 Switch的規格表中，通常可以很簡單的找到路由上限筆數(max value)，但FortiGate從官方文件只能發現FortiOS的靜態路由的相關限制，動態路由則無參考值，那到底會是什麼答案呢?</p>
<p><span id="more-17859"></span></p>
<p>官網FortiOS max value參考：<br />
<a href="https://docs.fortinet.com/max-value-table">https://docs.fortinet.com/max-value-table</a></p>
<p>FortiOS是採用ZebOS路由引擎，因此無硬體上的限制，決於硬體可用的系統記憶體 ，因此當有較多的動態路由學習的情境，記得要規劃大台一點的設備。</p>
<p><strong>[查看FortiGate硬體有多少記憶體]</strong><br />
在console或SSH模式下輸入以下<span style="font-family: verdana, geneva; font-size: 1rem;">指令語法：</span></p>
<pre>diagnose hardware sysinfo conserve</pre>
<p>範例圖示：<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-17863 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate-route-max-01.png" alt="" width="938" height="208" srcset="https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate-route-max-01.png 938w, https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate-route-max-01-300x67.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate-route-max-01-768x170.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" />本範例中的設備硬體具有8G的記憶體</p>
<p><strong>[查看系統目前剩下多少記憶體可用]</strong><br />
在console或SSH模式下輸入以下<span style="font-family: verdana, geneva; font-size: 1rem;">指令語法：</span></p>
<pre>get hardware memory</pre>
<p>範例圖示：<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-17864 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate-route-max-02.png" alt="" width="382" height="103" srcset="https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate-route-max-02.png 382w, https://ailog.tw/lifelog/wp-content/uploads/2025/01/fortigate-route-max-02-300x81.png 300w" sizes="auto, (max-width: 382px) 100vw, 382px" /><br />
本範例中大約還有4.8G的記憶體可用。</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FortiGate防火牆-設備產品生命週期(2022-10-15更新)</title>
		<link>https://ailog.tw/lifelog/2022/10/15/fortigate-life-cycle2022/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sat, 15 Oct 2022 09:22:11 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[EOO]]></category>
		<category><![CDATA[EOS]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[保固]]></category>
		<category><![CDATA[停產]]></category>
		<category><![CDATA[防火牆]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=13946</guid>

					<description><![CDATA[Product Life Cycle就是設備產品生命週期，選購資訊產品時應該要注意一下這個資訊，避免購買到即將 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2022/10/15/fortigate-life-cycle2022/" class="more-link">閱讀全文<span class="screen-reader-text">〈FortiGate防火牆-設備產品生命週期(2022-10-15更新)〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p class="gray"><span style="font-size: 12pt;">Product Life Cycle就是設備產品生命週期，選購資訊產品時應該要注意一下這個資訊，避免購買到即將停止服務或更新的產品，尤其是資安設備(小編就吃過一次虧&#8230;.買完隔年就EOS了&gt;&lt;)。</span></p>
<p><span id="more-13946"></span></p>
<p>EOO(End of Order Date)：<br />
中止接受訂單日期，不過這是原廠的日期，通常SI或代理商會把日期往前推，避免遇到無法出貨的狀況。</p>
<p>LSED(Last Service Extension Date)：<br />
最後服務展延日期，指的是如果有購買維護合約這是日期是最後可以下單的日期，且購買的延伸保固服務日期不得超過EOS日期。</p>
<p>EOS(End of Support Date)：<br />
產品服務中止日期，也就是宣告這個產品的中止了，如果遇到設備故障或有Bug，那就只能重新採購新產品而無法得到相關服務了。</p>
<p>FortiGate防火牆設備產品生命週期(2022-10-15更新)<br />
※如資訊有誤以原廠資訊為主</p>
<table width="756">
<tbody>
<tr>
<td width="316"><strong><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate產品型號</span></strong></td>
<td width="147"><strong><span style="font-size: 10pt; font-family: verdana, geneva;">可接受訂單日期</span></strong></td>
<td width="182"><strong><span style="font-size: 10pt; font-family: verdana, geneva;">訂閱服務最後日期</span></strong></td>
<td width="111"><strong><span style="font-size: 10pt; font-family: verdana, geneva;">中止服務日期</span></strong></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-60D</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2018-09-23</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2022-09-23</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2023-09-23</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-60E</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2021-12-29</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2025-12-29</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2026-12-29</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-70D</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2017-07-16</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2021-07-16</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2022-07-16</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-80D</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2018-04-16</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2022-04-16</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2023-04-16</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-80E</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2021-08-17</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2025-08-17</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2026-08-17</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-90D</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2018-10-14</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2022-10-14</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2023-10-14</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-90E</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2020-04-15</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2024-04-15</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2025-04-15</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-100D</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2018-07-26</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2022-07-26</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2023-07-26</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-100E</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2021-08-17</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2025-08-17</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2026-08-17</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-200D</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2018-05-22</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2022-05-22</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2023-05-22</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-300D</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2018-10-11</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2022-10-11</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2023-10-11</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-300E</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2021-07-15</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2025-07-15</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2026-07-15</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-500D</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2018-05-08</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2022-05-08</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2023-05-08</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-500E</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2021-07-15</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2025-07-15</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2026-07-15</span></td>
</tr>
</tbody>
</table>
<p>原廠產品生命週期查詢網頁(需要登入帳號才可查詢)<br />
<a href="https://support.fortinet.com/Information/ProductLifeCycle.aspx">https://support.fortinet.com/Information/ProductLifeCycle.aspx</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>透過Fortigate VPN建立VXLAN讓分隔異地的兩端使用相同的區域網路</title>
		<link>https://ailog.tw/lifelog/2021/10/31/fortigate-vxlan/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sun, 31 Oct 2021 09:39:09 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[L2]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[VXLAN]]></category>
		<category><![CDATA[專線]]></category>
		<category><![CDATA[相同網段]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=11473</guid>

					<description><![CDATA[人生真的是充滿了挑戰，小編最近處理了一個透過Fortigate建立VXLAN讓分隔兩地的網路可以串連在一起，並 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/10/31/fortigate-vxlan/" class="more-link">閱讀全文<span class="screen-reader-text">〈透過Fortigate VPN建立VXLAN讓分隔異地的兩端使用相同的區域網路〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-size: 14pt; font-family: verdana, geneva;">人生真的是充滿了挑戰，小編最近處理了一個透過Fortigate建立VXLAN讓分隔兩地的網路可以串連在一起，並且形成同一個內部網路，效果就跟點對點(point to point network)L2專線一樣，雖然反應速度略遜專線，但價格差距可是相當驚人，因此就可以了解為何會有企業想這樣做了吧!<span id="more-11473"></span></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">一、情境說明</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">(1)、IDC及DR兩端各有一台Fortigate防火牆，設備韌體均採用6.4.4(1803)，希望透過VPN VXLAN技術，讓分隔兩端的網路形成一個虛擬的L2內網。</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(2)、情境架構圖：<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-11479 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/10/fortigate-vxlan-00.jpg" alt="" width="836" height="699" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/10/fortigate-vxlan-00.jpg 836w, https://ailog.tw/lifelog/wp-content/uploads/2021/10/fortigate-vxlan-00-300x251.jpg 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/10/fortigate-vxlan-00-768x642.jpg 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /><br />
</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">(3)、本範例設定過程均採用Conosle模式<br />
(4)、VXLAN<span style="font-weight: 400;">該功能只支援FortOS 5.4版本以上，但5.6以上功能較為完善。<br />
(5)、該功能是透過IPSec VPN架構進行，但無法透過加速晶片進行加速，因此如果流量過大，請注意設備等級及效能。<br />
(6)、本範例防火牆相關資訊<br />
Wan interface：wan1<br />
Lan interface：internal1<br />
IDC防火牆Wan端真實IP：192.192.205.1<br />
DR防火牆Wan端真實IP：192.192.209.1<br />
VPN psksecret：0800080080</span></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><span style="font-weight: 400;"><br />
</span>二、設定步驟<br />
(1)、IDC端的Fortigate設定WAN端IP及預設閘道<br />
指令：</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">config system interface</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">edit &#8220;wan1&#8221;</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set vdom &#8220;root&#8221;</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set ip <span style="color: #ff0000;">192.192.205.1 255.255.255.0</span></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set allowaccess ping</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set type physical</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set role wan</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set snmp-index 1</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">next<br />
end</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">config router static</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">edit 1</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set gateway <span style="color: #ff0000;">192.192.205.254</span></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set device &#8220;wan1&#8221;</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">next</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">end</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(2)、DR端的Fortigate設定WAN端IP及預設閘道<br />
指令：<br />
config system interface<br />
edit &#8220;wan1&#8221;<br />
set vdom &#8220;root&#8221;<br />
set ip <span style="color: #ff0000;">192.192.209.1 255.255.255.0</span><br />
set allowaccess ping<br />
set type physical<br />
set role wan<br />
set snmp-index 1<br />
next<br />
end</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">config router static</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">edit 1</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set gateway <span style="color: #ff0000;">192.192.209.254</span></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set device &#8220;wan1&#8221;</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">next</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">end</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(3)、IDC端的Fortigate建立VXLAN VPN<br />
指令：<br />
config vpn ipsec phase1-interface</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">edit VXLAN</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set interface wan1</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set peertype any</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set proposal aes256-sha1</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set encapsulation vxlan</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set encapsulation-address ipv4</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set encap-local-gw4 <span style="color: #ff0000;">192.192.205.1</span></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set encap-remote-gw4 <span style="color: #ff0000;">192.192.209.1</span></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set remote-gw <span style="color: #ff0000;">192.192.209.1</span></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set psksecret <span style="font-weight: 400; color: #ff0000;">0800080080</span></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">next</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">end</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">config vpn ipsec phase2-interface</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">edit VXLAN_ph2</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set phase1name VXLAN</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set proposal aes256-sha1</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set auto-negotiate enable</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">next</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">end</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(4)、DR端的Fortigate建立VXLAN VPN<br />
指令：<br />
config vpn ipsec phase1-interface</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">edit VXLAN</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set interface wan1</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set peertype any</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set proposal aes256-sha1</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set encapsulation vxlan</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set encapsulation-address ipv4</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set encap-local-gw4 <span style="color: #ff0000;">192.192.209.1</span></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set encap-remote-gw4 <span style="color: #ff0000;">192.192.205.1</span></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set remote-gw <span style="color: #ff0000;">192.192.205.1</span></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set psksecret <span style="font-weight: 400; color: #ff0000;">0800080080</span></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">next</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">end</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">config vpn ipsec phase2-interface</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">edit VXLAN_ph2</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set phase1name VXLAN</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set proposal aes256-sha1</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set auto-negotiate enable</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">next</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">end</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(5)、在IDC及DR兩端的Fortigate設定VPN介面採用L2傳遞模式<br />
指令：<br />
config system interface<br />
edit VXLAN<br />
<span style="color: #ff0000;">set l2forward enable<br />
<span style="font-weight: 400;">set mtu-override enable</span></span><br />
next<br />
end<br />
</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(6)、在IDC及DR兩端的Fortigate建立虛擬Switch<br />
指令：<br />
config system switch-interface<br />
edit VXLAN-SWITCH<br />
set vdom root<br />
set member <span style="color: #ff0000;">internal1 VXLAN</span><br />
next<br />
end<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-11480 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/10/fortigate-vxlan-01.jpg" alt="" width="1370" height="103" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/10/fortigate-vxlan-01.jpg 1370w, https://ailog.tw/lifelog/wp-content/uploads/2021/10/fortigate-vxlan-01-300x23.jpg 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/10/fortigate-vxlan-01-1024x77.jpg 1024w, https://ailog.tw/lifelog/wp-content/uploads/2021/10/fortigate-vxlan-01-768x58.jpg 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /><br />
備註說明：建立完畢虛擬SWITCH後的網頁畫面</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">(7)、在IDC及DR兩端的Fortigate設定<br />
config system global<br />
<span style="color: #ff0000;">set honor-df disable</span><br />
end<br />
備註說明：<br />
<span style="font-size: 12pt;">FortiOS does not send back an ICMP “destination unreachable, fragmentation needed and DF set” to the source when an IP packet with the DF bit set and a size greater than the tunnel MTU cannot be forwarded inside the VxLAN-IPsec tunne</span><br />
</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">三、實測<br />
(1)、在IDC端Fortigate防火牆的<span style="color: #ff0000;">internal1<span style="color: #000000;">接上一台電腦，並把IP設定為<span style="color: #ff0000;">192.168.100.1</span>/24。</span></span></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">(2)、在DR端Fortigate防火牆的<span style="color: #ff0000;">internal1</span>接上一台電腦，並把IP設定為<span style="color: #ff0000;">192.168.100.2</span>/24。</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(3)<span style="color: #ff0000;"><span style="color: #000000;">、透過這兩台電腦進行IP互ping的動作(記得關閉電腦上的防火牆限制)，如果可以通那就完成所有設定了。</span></span></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">四、輔助說明</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">設定過程中需要設定<br />
<span style="color: #ff0000;"><span style="font-size: 14pt; font-family: verdana, geneva;">set l2forward enable</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva; color: #000000;">及</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set honor-df disable<br />
</span><span style="color: #000000;">的參考說明：<br />
<a href="https://community.fortinet.com/t5/FortiGate/Technical-Tip-Global-setting-honor-df-explained/ta-p/197002?externalID=FD51964">https://community.fortinet.com/t5/FortiGate/Technical-Tip-Global-setting-honor-df-explained/ta-p/197002?externalID=FD51964</a></span><br />
</span></span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>安裝Firewall Analyzer來收集Fortigate防火牆log</title>
		<link>https://ailog.tw/lifelog/2021/05/20/firewall-analyzer/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Thu, 20 May 2021 10:00:16 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Firewall Analyzer]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[log]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[安裝Firewall Analyzer來收集Fortigate防火牆log]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=8290</guid>

					<description><![CDATA[近期因為疫情的關係，很多公司已有採居家上班的狀況，並透過VPN讓使用者可以連線回公司存取公司的資源，但到底哪些 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/05/20/firewall-analyzer/" class="more-link">閱讀全文<span class="screen-reader-text">〈安裝Firewall Analyzer來收集Fortigate防火牆log〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-size: 14pt;">近期因為疫情的關係，很多公司已有採居家上班的狀況，並透過VPN讓使用者可以連線回公司存取公司的資源，但到底哪些人有VPN連線進來過，怎麼保留連線紀錄呢?很多中小企業在裝設防火牆時是沒有建立log收集的機制的，小編今天要介紹透過Firewall Analyzer來收集防火牆的VPN資訊。<span id="more-8290"></span></span></p>
<p><span style="font-size: 14pt;">考慮到在企業使用盡量不增加授權的成本，本篇小編會介紹以Linux環境安裝的方式。</span></p>
<p><span style="font-size: 14pt;">Firewall Analyzer官方網頁介紹：</span><br />
<span style="font-size: 14pt;"><a href="https://www.manageengine.com/products/firewall/">https://www.manageengine.com/products/firewall/</a></span></p>
<p><strong><span style="font-size: 14pt;">01、安裝好Linux</span></strong><br />
<span style="font-size: 14pt;">安裝步驟可以參考下列文章：<br />
<a href="https://ailog.tw/lifelog/2021/05/15/ubuntu-20-install/">https://ailog.tw/lifelog/2021/05/15/ubuntu-20-install/</a><br />
</span></p>
<p><strong><span style="font-size: 14pt;">02、下載Firewall Analyzer軟體(30天免費授權)<br />
</span></strong><span style="font-size: 14pt;">Linux 32位元下載網址：<br />
<a href="https://www.manageengine.com/products/firewall/61794333/ManageEngine_FirewallAnalyzer.bin">https://www.manageengine.com/products/firewall/61794333/ManageEngine_FirewallAnalyzer.bin</a></span></p>
<p><span style="font-size: 14pt;">Linux 64位元下載網址：<br />
<a href="https://download.manageengine.com/products/firewall/61794333/ManageEngine_FirewallAnalyzer_64bit.bin">https://download.manageengine.com/products/firewall/61794333/ManageEngine_FirewallAnalyzer_64bit.bin</a></span></p>
<p>[直接在Linux系統下載檔案]<br />
指令：<br />
sudo wget https://download.manageengine.com/products/firewall/61794333/ManageEngine_FirewallAnalyzer_64bit.bin<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8292" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-01.png" alt="" width="819" height="339" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-01.png 819w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-01-300x124.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-01-768x318.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p><strong><span style="font-size: 14pt;">03、設定安裝檔成可執行的檔案<br />
</span></strong><span style="font-size: 14pt;">sudo chmod 755 ManageEngine_FirewallAnalyzer_64bit.bin<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8294" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-02.png" alt="" width="876" height="113" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-02.png 876w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-02-300x39.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-02-768x99.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><strong><span style="font-size: 14pt;">04、安裝<strong>Firewall Analyzer軟體</strong><br />
</span></strong><span style="font-size: 14pt;">sudo ./ManageEngine_FirewallAnalyzer_64bit.bin</span><strong><span style="font-size: 14pt;"><br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8298" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-03-1.png" alt="" width="798" height="92" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-03-1.png 798w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-03-1-300x35.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-03-1-768x89.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /><br />
</span></strong></p>
<p><strong><span style="font-size: 14pt;">05、同意軟體授權</span></strong><br />
按下鍵盤「enter」進入同意相關授權步驟<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8296" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-04.png" alt="" width="818" height="158" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-04.png 818w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-04-300x58.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-04-768x148.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>過程持續按鍵盤「enter」<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8299" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-05.png" alt="" width="488" height="195" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-05.png 488w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-05-300x120.png 300w" sizes="auto, (max-width: 488px) 100vw, 488px" /></p>
<p>最後按下「Y」接受授權<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8300" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-06.png" alt="" width="742" height="197" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-06.png 742w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-06-300x80.png 300w" sizes="auto, (max-width: 706px) 89vw, (max-width: 767px) 82vw, 740px" /></p>
<p>06、是否註冊技術支援服務<br />
本範例選：N<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8301" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-07.png" alt="" width="883" height="145" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-07.png 883w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-07-300x49.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-07-768x126.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>07、軟體安裝路徑<br />
採用預設安裝路徑，按下Enter即可<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8302" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-08.png" alt="" width="703" height="194" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-08.png 703w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-08-300x83.png 300w" sizes="auto, (max-width: 703px) 100vw, 703px" /></p>
<p>08、設定web連線服務Port<br />
本範例採用預設值：8060<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8303" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-09.png" alt="" width="579" height="134" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-09.png 579w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-09-300x69.png 300w" sizes="auto, (max-width: 579px) 100vw, 579px" /></p>
<p>09、確認安裝資訊<br />
按下「ENTER」繼續安裝<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8305" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-10.png" alt="" width="568" height="342" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-10.png 568w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-10-300x181.png 300w" sizes="auto, (max-width: 568px) 100vw, 568px" /><br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8306" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-11.png" alt="" width="828" height="195" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-11.png 828w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-11-300x71.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-11-768x181.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>10、安裝完成畫面<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8307" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-12.png" alt="" width="871" height="427" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-12.png 871w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-12-300x147.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-12-768x377.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>11、將<strong><span style="font-size: 14pt;">Firewall Analyzer安裝成Service型態<br />
</span></strong>cd /opt/ManageEngine/OpManager/bin<br />
sudo sh linkAsService.sh<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8310" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-13.png" alt="" width="937" height="382" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-13.png 937w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-13-300x122.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-13-768x313.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>12、啟動<strong><span style="font-size: 14pt;">Firewall Analyzer軟體<br />
</span></strong><span style="font-size: 14pt;">sudo systemctl start OpManager.service</span><strong><span style="font-size: 14pt;"><br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8311" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-14.png" alt="" width="703" height="49" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-14.png 703w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-14-300x21.png 300w" sizes="auto, (max-width: 703px) 100vw, 703px" /><br />
</span></strong></p>
<p>13、檢查服務Port是否有啟動<br />
ss -an | grep 8060<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8312" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-15.png" alt="" width="929" height="67" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-15.png 929w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-15-300x22.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-15-768x55.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>14、登入Fortigate防火牆設定log server<br />
透過SSH或Console登入，輸入下令指令：<br />
(1)、啟動syslog並指定傳送到Firewall Analyzer主機上，範例中的192.168.5.243為小編的Firewall Analyzer Server IP，請自行更改為自己相對應的IP。<br />
config log syslogd setting<br />
set status enable<br />
set server <span style="color: #ff0000;">192.168.5.243</span><br />
set port 1514<br />
end</p>
<p>(2)、設定要傳送什麼loh內容<br />
config log syslogd filter<br />
set severity information<br />
set forward-traffic enable<br />
set local-traffic enable<br />
set anomaly enable</p>
<p>15、透過瀏覽器登入系統<br />
預設帳號：admin<br />
預設密碼：admin<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8313" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-16.png" alt="" width="506" height="479" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-16.png 506w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-16-300x284.png 300w" sizes="auto, (max-width: 506px) 100vw, 506px" /></p>
<p>16、點選「Dashboard」→「VPN」即可看到防火牆的VPN相關的狀態<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8316" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-17.png" alt="" width="196" height="265" /></p>
<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8317" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-18.png" alt="" width="752" height="360" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-18.png 752w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-18-300x144.png 300w" sizes="auto, (max-width: 706px) 89vw, (max-width: 767px) 82vw, 740px" /></p>
<p>17、查看VPN歷史報表<br />
點選「Reports」 → 「VPN Reports」即可觀看VPN的歷史紀錄<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8320" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-19.png" alt="" width="299" height="397" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-19.png 299w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-19-226x300.png 226w" sizes="auto, (max-width: 299px) 100vw, 299px" /></p>
<p>18、變更系統介面語系<br />
(1)、點選右上角齒輪圖示<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8482" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-22.png" alt="" width="275" height="212" /></p>
<p>(2)、選擇左邊的「Language Selector」，接著選擇右邊的「Chinese(Traditional)繁体中文」<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8484" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-23.png" alt="" width="439" height="440" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-23.png 439w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-23-300x300.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-23-150x150.png 150w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-23-100x100.png 100w" sizes="auto, (max-width: 439px) 100vw, 439px" /></p>
<p>(3)、網頁會自動重新整理，接著就可以看到中文網頁了<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8485" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-24.png" alt="" width="582" height="170" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-24.png 582w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-24-300x88.png 300w" sizes="auto, (max-width: 582px) 100vw, 582px" /></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FortiOS 7.0已開放下載</title>
		<link>https://ailog.tw/lifelog/2021/04/01/fortios-7-0/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Thu, 01 Apr 2021 14:32:12 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[7.0]]></category>
		<category><![CDATA[download]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[FortiOS]]></category>
		<category><![CDATA[FortiOS 7.0已開放下載]]></category>
		<category><![CDATA[hardware]]></category>
		<category><![CDATA[mode]]></category>
		<category><![CDATA[下載]]></category>
		<category><![CDATA[升級]]></category>
		<category><![CDATA[更新]]></category>
		<category><![CDATA[硬體]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=7682</guid>

					<description><![CDATA[FortiOS 7.0強調本次新增了 300項功能，資安防禦全面升級，於2021年3月30日登入官方服務網頁後 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/04/01/fortios-7-0/" class="more-link">閱讀全文<span class="screen-reader-text">〈FortiOS 7.0已開放下載〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-size: 14pt;">FortiOS 7.0強調本次新增了 300項功能，資安防禦全面升級，於2021年3月30日登入官方服務網頁後即可下載，快來感受全新的FortiOS吧。<span id="more-7682"></span></span></p>
<p><span style="font-size: 14pt;">韌體下載網頁：</span><br />
<span style="font-size: 14pt;"><a href="https://support.fortinet.com/SSO/login.ashx">https://support.fortinet.com/SSO/login.ashx</a></span></p>
<p><span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-7683" src="https://ailog.tw/lifelog/wp-content/uploads/2021/04/FortiOS7-01.png" alt="" width="667" height="92" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/04/FortiOS7-01.png 667w, https://ailog.tw/lifelog/wp-content/uploads/2021/04/FortiOS7-01-300x41.png 300w" sizes="auto, (max-width: 667px) 100vw, 667px" /></span></p>
<p><span style="font-size: 14pt;">韌體更新順序查詢：<br />
記得先查閱一下官方的更新順序建議，避免更新過程導致設定異常</span><br />
<span style="font-size: 14pt;"><a href="https://ailog.tw/lifelog/2020/01/06/fortinet-upgrade-tool/">https://ailog.tw/lifelog/2020/01/06/fortinet-upgrade-tool/</a></span></p>
<p><span style="font-size: 14pt;">官方線上手冊：</span><br />
<span style="font-size: 14pt;"><a href="https://docs.fortinet.com/product/fortigate/7.0">https://docs.fortinet.com/product/fortigate/7.0</a></span></p>
<p><span style="font-size: 14pt;">新版重點功能：</span><br />
<span style="color: #0000ff; font-size: 14pt;"><strong>零信任存取(Zero Trust Access)</strong></span><br />
<span style="font-size: 14pt;">管理遠端存取與應用程式的零信任網路存取</span></p>
<p><span style="color: #0000ff; font-size: 14pt;"><strong>安全驅動型網路(Security-Driven Networking)</strong></span><br />
<span style="font-size: 14pt;">以SASE達成不受地域限制的一致化網路安全</span><br />
<span style="font-size: 14pt;">全新自動修復SD-WAN</span><br />
<span style="font-size: 14pt;">利用5G來擴大LTE邊緣</span></p>
<p><span style="color: #0000ff; font-size: 14pt;"><strong>自適應雲端安全(Adaptive Cloud Security)</strong></span><br />
<span style="font-size: 14pt;">優化多雲部署的效能與安全性</span></p>
<p><span style="color: #0000ff; font-size: 14pt;"><strong>網路營運中心(NOC)與安全營運中心(SOC)</strong></span><br />
<span style="font-size: 14pt;">提高網路營運中心(NOC)和安全營運中心(SOC)的效率</span><br />
<span style="font-size: 14pt;">優化遠距工作的網頁安全</span></p>
<p><span style="font-size: 14pt;">支援FortiOS 7.0的硬體共有69個型號：</span><br />
<span style="font-size: 14pt;">FGR_60F_3G4G</span><br />
<span style="font-size: 14pt;">FGR_60F</span><br />
<span style="font-size: 14pt;">FGT_1000D</span><br />
<span style="font-size: 14pt;">FGT_100EF</span><br />
<span style="font-size: 14pt;">FGT_100E</span><br />
<span style="font-size: 14pt;">FGT_100F</span><br />
<span style="font-size: 14pt;">FGT_101E</span><br />
<span style="font-size: 14pt;">FGT_101F</span><br />
<span style="font-size: 14pt;">FGT_1100E</span><br />
<span style="font-size: 14pt;">FGT_1101E</span><br />
<span style="font-size: 14pt;">FGT_1200D</span><br />
<span style="font-size: 14pt;">FGT_140E_POE</span><br />
<span style="font-size: 14pt;">FGT_140E</span><br />
<span style="font-size: 14pt;">FGT_1500DT</span><br />
<span style="font-size: 14pt;">FGT_1500D</span><br />
<span style="font-size: 14pt;">FGT_2000E</span><br />
<span style="font-size: 14pt;">FGT_200E</span><br />
<span style="font-size: 14pt;">FGT_201E</span><br />
<span style="font-size: 14pt;">FGT_2200E</span><br />
<span style="font-size: 14pt;">FGT_2201E</span><br />
<span style="font-size: 14pt;">FGT_2500E</span><br />
<span style="font-size: 14pt;">FGT_3000D</span><br />
<span style="font-size: 14pt;">FGT_300E</span><br />
<span style="font-size: 14pt;">FGT_301E</span><br />
<span style="font-size: 14pt;">FGT_3100D</span><br />
<span style="font-size: 14pt;">FGT_3200D</span><br />
<span style="font-size: 14pt;">FGT_3300E</span><br />
<span style="font-size: 14pt;">FGT_3301E</span><br />
<span style="font-size: 14pt;">FGT_3400E</span><br />
<span style="font-size: 14pt;">FGT_3401E</span><br />
<span style="font-size: 14pt;">FGT_3600E</span><br />
<span style="font-size: 14pt;">FGT_3601E</span><br />
<span style="font-size: 14pt;">FGT_3700D</span><br />
<span style="font-size: 14pt;">FGT_3800D</span><br />
<span style="font-size: 14pt;">FGT_3960E</span><br />
<span style="font-size: 14pt;">FGT_3980E</span><br />
<span style="font-size: 14pt;">FGT_400E</span><br />
<span style="font-size: 14pt;">FGT_401E</span><br />
<span style="font-size: 14pt;">FGT_40F_3G4G</span><br />
<span style="font-size: 14pt;">FGT_40F</span><br />
<span style="font-size: 14pt;">FGT_5001E1</span><br />
<span style="font-size: 14pt;">FGT_5001E</span><br />
<span style="font-size: 14pt;">FGT_500E</span><br />
<span style="font-size: 14pt;">FGT_501E</span><br />
<span style="font-size: 14pt;">FGT_600E</span><br />
<span style="font-size: 14pt;">FGT_601E</span><br />
<span style="font-size: 14pt;">FGT_60E_DSLJ</span><br />
<span style="font-size: 14pt;">FGT_60E_DSL</span><br />
<span style="font-size: 14pt;">FGT_60E_POE</span><br />
<span style="font-size: 14pt;">FGT_60E</span><br />
<span style="font-size: 14pt;">FGT_60F</span><br />
<span style="font-size: 14pt;">FGT_61E</span><br />
<span style="font-size: 14pt;">FGT_61F</span><br />
<span style="font-size: 14pt;">FGT_800D</span><br />
<span style="font-size: 14pt;">FGT_80E_POE</span><br />
<span style="font-size: 14pt;">FGT_80E</span><br />
<span style="font-size: 14pt;">FGT_81E_POE</span><br />
<span style="font-size: 14pt;">FGT_81E</span><br />
<span style="font-size: 14pt;">FGT_900D</span><br />
<span style="font-size: 14pt;">FGT_90E</span><br />
<span style="font-size: 14pt;">FGT_91E</span><br />
<span style="font-size: 14pt;">FWF_40F_3G4G</span><br />
<span style="font-size: 14pt;">FWF_40F</span><br />
<span style="font-size: 14pt;">FWF_60E_DSLJ</span><br />
<span style="font-size: 14pt;">FWF_60E_DSL</span><br />
<span style="font-size: 14pt;">FWF_60E</span><br />
<span style="font-size: 14pt;">FWF_60F</span><br />
<span style="font-size: 14pt;">FWF_61E</span><br />
<span style="font-size: 14pt;">FWF_61F</span></p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>跟小編一起學-FortiGate防火牆-設定「網路服務」物件(Console設定方式)</title>
		<link>https://ailog.tw/lifelog/2021/01/24/fgt-service-cmd/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sun, 24 Jan 2021 07:28:32 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[40F]]></category>
		<category><![CDATA[60B]]></category>
		<category><![CDATA[60D]]></category>
		<category><![CDATA[60E]]></category>
		<category><![CDATA[80C]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[Group]]></category>
		<category><![CDATA[Service]]></category>
		<category><![CDATA[物件]]></category>
		<category><![CDATA[網路服務]]></category>
		<category><![CDATA[網路服務群組]]></category>
		<category><![CDATA[跟小編一起學-FortiGate防火牆-設定「網路服務」物件(Console設定方式)]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=6497</guid>

					<description><![CDATA[今天小編要介紹的單元是透過Console方式，設定FortiGate防火牆「網路服務」及「網路服務群組」物件， &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/01/24/fgt-service-cmd/" class="more-link">閱讀全文<span class="screen-reader-text">〈跟小編一起學-FortiGate防火牆-設定「網路服務」物件(Console設定方式)〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>今天小編要介紹的單元是透過Console方式，設定FortiGate防火牆「網路服務」及「網路服務群組」物件，該物件常使用在防火牆規則的設定過程，趕快跟著小編一起來了解吧。<span id="more-6497"></span><br />
介紹的內容為<br />
透過Console管理畫面：<br />
(1)、建立服務類別<br />
(2)、建立網路服務物件(一)、(二)<br />
(3)、建立網路服務群組物件</p>
<p><span style="font-size: 14pt;"><strong>[建立服務類別]</strong></span><br />
(1)、登入系統<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6501 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-01.jpg" alt="" width="223" height="123" /><br />
注解說明：輸入帳號及密碼登入防火牆</p>
<p>(2)、切換至「網路服務類別」物件設定模式<br />
指令如下：<br />
config firewall service category<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6500 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-02.jpg" alt="" width="377" height="82" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-02.jpg 377w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-02-300x65.jpg 300w" sizes="auto, (max-width: 377px) 100vw, 377px" /><br />
注解說明：開始網路服務類別設定</p>
<p>(3)、新增「網路服務類別」<br />
指令如下：<br />
edit &#8220;ailog.tw&#8221;<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6502 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-03.jpg" alt="" width="334" height="95" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-03.jpg 334w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-03-300x85.jpg 300w" sizes="auto, (max-width: 334px) 100vw, 334px" /><br />
注解說明：本範例新增了一個名稱為「ailog.tw」的類別</p>
<p>(4)、查看設定<br />
指令如下：<br />
show<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6504 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-04.jpg" alt="" width="338" height="167" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-04.jpg 338w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-04-300x148.jpg 300w" sizes="auto, (max-width: 338px) 100vw, 338px" /><br />
注解說明：查看設定是否正確，有無遺漏項目</p>
<p>(5)、離開「網路服務類別」物件設定模式<br />
指令如下：<br />
end<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-6505" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-05.jpg" alt="" width="221" height="83" /><br />
注解說明：如果要繼續新增其他的類別物件則輸入「next」，要結束類別設定則輸入「end」。</p>
<p><span style="font-size: 14pt;"><strong>[建立網路服務物件](一)<br />
</strong></span>(1)、切換至「網路服務」物件設定模式<br />
指令如下：<br />
config firewall service custom<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6507 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-06.jpg" alt="" width="356" height="88" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-06.jpg 356w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-06-300x74.jpg 300w" sizes="auto, (max-width: 356px) 100vw, 356px" /><br />
注解說明：開始網路服務物件設定</p>
<p>(2)、新增「網路服務」物件<br />
指令如下：<br />
edit &#8220;Synology-Drive&#8221;<br />
set category &#8220;ailog.tw&#8221;<br />
set tcp-portrange 5000-5001<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6508 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-07.jpg" alt="" width="510" height="195" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-07.jpg 510w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-07-300x115.jpg 300w" sizes="auto, (max-width: 510px) 100vw, 510px" /><br />
注解說明：本範例新增了一個名稱為「Synology-Drive」的網路服務，並將類別設定為「ailog.tw」，並定義採用「TCP」協定，服務埠(Port)則為5000與5001兩個。</p>
<p>(3)、查看設定<br />
指令如下：<br />
show<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6509 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-08.jpg" alt="" width="373" height="204" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-08.jpg 373w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-08-300x164.jpg 300w" sizes="auto, (max-width: 373px) 100vw, 373px" /><br />
注解說明：查看設定是否正確，有無遺漏項目</p>
<p>(4)、離開「網路服務」物件設定模式<br />
指令如下：<br />
end<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6510 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-09.jpg" alt="" width="277" height="76" /><br />
注解說明：如果要繼續新增其他的網路服務物件則輸入「next」，要結束類別設定則輸入「end」。</p>
<p><span style="font-size: 14pt;"><strong>[建立網路服務物件](二)</strong></span><br />
(1)、切換至「網路服務」物件設定模式<br />
指令如下：<br />
config firewall service custom<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6507 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-06.jpg" alt="" width="356" height="88" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-06.jpg 356w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-06-300x74.jpg 300w" sizes="auto, (max-width: 356px) 100vw, 356px" /><br />
注解說明：開始網路服務物件設定</p>
<p>(2)、新增「網路服務」物件<br />
指令如下：<br />
edit &#8220;tomcat&#8221;<br />
set category &#8220;ailog.tw&#8221;<br />
set tcp-portrange 8080<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6511 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-10.jpg" alt="" width="381" height="186" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-10.jpg 381w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-10-300x146.jpg 300w" sizes="auto, (max-width: 381px) 100vw, 381px" /><br />
注解說明：本範例新增了一個名稱為「tomcat」的網路服務，並將類別設定為「ailog.tw」，並定義採用「TCP」協定，服務埠(Port)則為8080。</p>
<p>(3)、查看設定<br />
指令如下：<br />
show<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6513 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-10-1.jpg" alt="" width="318" height="162" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-10-1.jpg 318w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-10-1-300x153.jpg 300w" sizes="auto, (max-width: 318px) 100vw, 318px" /><br />
注解說明：查看設定是否正確，有無遺漏項目</p>
<p>(4)、離開「網路服務」物件設定模式<br />
指令如下：<br />
end<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-6512" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-11.jpg" alt="" width="212" height="79" /><br />
注解說明：如果要繼續新增其他的網路服務物件則輸入「next」，要結束類別設定則輸入「end」。</p>
<p>&nbsp;</p>
<p><span style="font-size: 14pt;"><strong>[建立網路服務群組物件]<br />
</strong></span>(1)、切換至「網路服務群組」物件設定模式<br />
指令如下：<br />
config firewall service group<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6514 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-12.jpg" alt="" width="372" height="78" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-12.jpg 372w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-12-300x63.jpg 300w" sizes="auto, (max-width: 372px) 100vw, 372px" /><br />
注解說明：開始網路服務群組物件設定</p>
<p>(2)、設定「網路服務群組」物件<br />
指令如下：<br />
edit &#8220;Ailog.tw-Service&#8221;<br />
set member &#8220;Synology-Drive&#8221; &#8220;tomcat&#8221;<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6515 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-13.jpg" alt="" width="609" height="152" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-13.jpg 609w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-13-300x75.jpg 300w" sizes="auto, (max-width: 609px) 100vw, 609px" /><br />
注解說明：本範例新增了一個名稱為「Ailog.tw-Service」的網路服務群組，並定義群組內包含了「Synology-Drive」、「tomcat」這兩個服務。</p>
<p>(3)、查看設定<br />
指令如下：<br />
show<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6517 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-15.jpg" alt="" width="456" height="180" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-15.jpg 456w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-15-300x118.jpg 300w" sizes="auto, (max-width: 456px) 100vw, 456px" /><br />
注解說明：查看設定是否正確，有無遺漏項目</p>
<p>(4)、離開「網路服務群組」物件設定模式<br />
指令如下：<br />
end<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6516 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-14.jpg" alt="" width="315" height="81" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-14.jpg 315w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-cmd-14-300x77.jpg 300w" sizes="auto, (max-width: 315px) 100vw, 315px" /><br />
注解說明：如果要繼續新增其他的網路服務群組物件則輸入「next」，要結束類別設定則輸入「end」。</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>跟小編一起學-FortiGate防火牆-設定「網路服務」物件(web設定方式)</title>
		<link>https://ailog.tw/lifelog/2021/01/23/fgt-service-web/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Fri, 22 Jan 2021 16:00:24 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[40F]]></category>
		<category><![CDATA[60B]]></category>
		<category><![CDATA[60D]]></category>
		<category><![CDATA[60E]]></category>
		<category><![CDATA[80C]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[Service]]></category>
		<category><![CDATA[物件]]></category>
		<category><![CDATA[網路服務]]></category>
		<category><![CDATA[網路服務群組]]></category>
		<category><![CDATA[跟小編一起學-FortiGate防火牆-設定「網路服務」物件(web設定方式)]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=6400</guid>

					<description><![CDATA[今天小編要介紹的單元是設定FortiGate防火牆的「網路服務」及「網路服務群組」物件，該物件常使用在防火牆規 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/01/23/fgt-service-web/" class="more-link">閱讀全文<span class="screen-reader-text">〈跟小編一起學-FortiGate防火牆-設定「網路服務」物件(web設定方式)〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>今天小編要介紹的單元是設定FortiGate防火牆的「網路服務」及「網路服務群組」物件，該物件常使用在防火牆規則的設定過程，趕快跟著小編一起來了解吧。<span id="more-6400"></span></p>
<p>介紹的內容為<br />
透過web管理畫面：<br />
(1)、建立服務類別<br />
(2)、建立網路服務物件<br />
(3)、建立網路服務群組物件</p>
<p><span style="font-size: 14pt;"><strong>[建立服務類別]</strong></span><br />
(1)、登入系統<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5823 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-LOGIN-08.jpg" alt="" width="381" height="235" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-LOGIN-08.jpg 381w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-LOGIN-08-300x185.jpg 300w" sizes="auto, (max-width: 381px) 100vw, 381px" /></p>
<p>(2)、切換至「網路服務」物件設定畫面<br />
點選「<strong>Policy &amp; Objects</strong>」→「<strong>Services</strong>」<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6401 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-01.jpg" alt="" width="249" height="387" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-01.jpg 249w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-01-193x300.jpg 193w" sizes="auto, (max-width: 249px) 100vw, 249px" /></p>
<p>(3)、新增「網路服務」類別<br />
點選「<strong>Create New</strong>」→「<strong>Category</strong>」<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6402 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-02.jpg" alt="" width="230" height="153" /></p>
<p>(4)、設定「網路服務」類別<br />
<strong>Name</strong>：輸入自訂的類別名稱，本範例輸入「ailog.tw」做為新增的類別名稱，接著點選「OK」完成設定步驟。</p>
<p><strong>Comments</strong>：輸入類別名稱的注解，方便識別類別用途。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6403 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-03.jpg" alt="" width="696" height="223" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-03.jpg 696w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-03-300x96.jpg 300w" sizes="auto, (max-width: 696px) 100vw, 696px" /></p>
<p>(5)、查看設定狀態<br />
返回類別列表畫面可以看見剛剛新增的「ailog.tw」在列表中，代表已順利新增「網路服務」類別。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6404 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-04.jpg" alt="" width="411" height="439" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-04.jpg 411w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-04-281x300.jpg 281w" sizes="auto, (max-width: 411px) 100vw, 411px" /></p>
<p><span style="font-size: 14pt;"><strong>[建立網路服務物件]</strong></span><br />
(1)、新增「網路服務」物件<br />
點選「<strong>Create New</strong>」→「<strong>Service</strong>」<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-6405" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-05.jpg" alt="" width="260" height="154" /></p>
<p>(2)、設定「網路服務」物件<br />
<strong>Name</strong>：輸入自訂的服務物件名稱，建議採用有識別性的名稱，方便日後操作識別用，本範例輸入Synology-Drive。<br />
<strong><br />
Show in Service List</strong>：是否顯示在「網路服務」清單，有些情境會透過該設定來隱藏「網路服務」不顯示在設定的候選清單內，避免干擾設定、增加選取「網路服務」的複雜度，但通常都還是採用預設的顯示設定狀態。<br />
<strong><br />
Category</strong>：類別選取前一步驟所新增的「ailog.tw」<br />
※ailog.tw為本範例的類別名稱，請網友們輸入適當的名稱。</p>
<p><strong>Destination Port</strong>：挑選協定類型「TCP」、「UDP」、「SCTP」，並輸入要定義的服務埠，本範例採用TCP協定的5000~5001兩個服務埠。</p>
<p>輸入以上資訊後接著點選「OK」完成新增「網路服務」物件新增的步驟。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6406 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-06.jpg" alt="" width="690" height="461" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-06.jpg 690w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-06-300x200.jpg 300w" sizes="auto, (max-width: 690px) 100vw, 690px" /></p>
<p>(3)、確認「網路服務」物件狀態<br />
在網路服務列表中可以看見剛剛新增的物件。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6407 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-07.jpg" alt="" width="543" height="433" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-07.jpg 543w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-07-300x239.jpg 300w" sizes="auto, (max-width: 543px) 100vw, 543px" /></p>
<p>(4)、下圖是新增第二個網路服務物件範例。<br />
該範例中名稱定義為「tomcat」，「顯示」在網路服務物件的候選清單內，類別定義在「ailog.tw」，採用TCP協定的8080埠。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6408 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-08.jpg" alt="" width="689" height="462" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-08.jpg 689w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-08-300x201.jpg 300w" sizes="auto, (max-width: 689px) 100vw, 689px" /></p>
<p><span style="font-size: 14pt;"><strong>[建立網路服務群組物件]</strong></span><br />
(1)、建立「網路服務群組」物件<br />
點選「<strong>Create New</strong>」→「<strong>Service Group</strong>」<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6409 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-09.jpg" alt="" width="170" height="129" /></p>
<p>(2)、設定「網路服務群組」物件<br />
<strong>Group Name</strong>：輸入自訂的服務群組物件名稱，建議採用有識別性的名稱，方便日後操作識別用，本範例輸入Ailog.tw-Service。</p>
<p><strong>Comments</strong>：輸入類別名稱的注解，方便識別類別用途。</p>
<p><strong>Color：</strong>設定「服務群組」物件的顯示顏色。</p>
<p><strong>Members</strong>：設定要綑綁在一起的服務。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6410 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-10.jpg" alt="" width="413" height="170" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-10.jpg 413w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-10-300x123.jpg 300w" sizes="auto, (max-width: 413px) 100vw, 413px" /></p>
<p>(3)、選取要綑綁在一起的服務<br />
在網路服務物件列表清單中，選取要綑綁的服務物件項目。<br />
<img loading="lazy" decoding="async" class="alignnone size-medium wp-image-6411" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-11-300x148.jpg" alt="" width="300" height="148" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-11-300x148.jpg 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-11.jpg 303w" sizes="auto, (max-width: 300px) 100vw, 300px" /></p>
<p>(4)、選取服務完成畫面<br />
本範例選取了「Synology-Drive」及「tomcat」<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-6412" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-12.jpg" alt="" width="299" height="135" /></p>
<p>(5)、完成「網路服務群組」物件<br />
點選「OK」完成「網路服務群組」物件新增步驟<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6413 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-13.jpg" alt="" width="688" height="301" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-13.jpg 688w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-13-300x131.jpg 300w" sizes="auto, (max-width: 688px) 100vw, 688px" /></p>
<p>(6)、確認「網路服務群組」物件狀態<br />
在網路服務列表中可以看見剛剛新增的「網路服務」及「網路服務群組」物件。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-6414 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-14.jpg" alt="" width="556" height="298" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-14.jpg 556w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-Service-14-300x161.jpg 300w" sizes="auto, (max-width: 556px) 100vw, 556px" /></p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
