<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://cozumpark.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Fortinet</title><link>http://cozumpark.com/blogs/fortigate/default.aspx</link><description /><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Debug Build: 61120.2)</generator><item><title>Fortigate Firewall Transparent Mod Yapılandırılması</title><link>http://cozumpark.com/blogs/fortigate/archive/2008/07/19/fortigate-firewall-transparent-mod-yap-land-r-lmas.aspx</link><pubDate>Sat, 19 Jul 2008 14:11:22 GMT</pubDate><guid isPermaLink="false">36acb80b-3ae7-4dda-bbe8-b4ae2f1fa947:31465</guid><dc:creator>Fatih KARAALİOGLU</dc:creator><slash:comments>5</slash:comments><comments>http://cozumpark.com/blogs/fortigate/comments/31465.aspx</comments><wfw:commentRss>http://cozumpark.com/blogs/fortigate/commentrss.aspx?PostID=31465</wfw:commentRss><description>&lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Daha &amp;#246;nceden yayınlamış olduğumuz Fortigate makalelerimizde Firewallımızı NAT modda yapılandırmış ve network&amp;#252;m&amp;#252;ze NAT modulunde kullanıma hazır hale getirmiştik. &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Fortigate firewallımız NAT mod haricinde &lt;b style="mso-bidi-font-weight:normal;"&gt;Route ve Transparent&lt;/b&gt; modda da kullanılabilmektedir. &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Fortigate Firewall&amp;#8217; ımız NAT ve Route Mod&amp;#8217;unda Layer3 &amp;#246;zelliklerinide kullanarak &amp;#231;alışmaktadır. Firewallımız NAT ve Route modunda yapılandırıldığı zaman farklı interfacelerindeki farklı IP ve Subnet Masklara sahip networkleri &amp;#252;zerinden gerekli işlemleri (yasak, izin, s&amp;#252;zme vb.) yaparak ge&amp;#231;irmektedir. Normal şartlar altında Fortigate cihazımızın ( aslında bir bir firewallın ) kullanıma hazır hale getirilmesi bu şekildedir. &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Fakat bazı &amp;#246;zel durumlar vardır ki firewallımızı NAT ve Route Modunda networkumuz i&amp;#231;in kullanıma hazır hale getiremeyebiliriz. Bunların nedenlerini &amp;#246;rnek vermemiz gerekirse; &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;İki veya daha fazla noktası farklı &amp;#252;r&amp;#252;nler ile IPSEC VPN,&lt;span style="mso-spacerun:yes;"&gt;&amp;#160; &lt;/span&gt;Vpn, VOIP vb.. &amp;#252;r&amp;#252;nler bulunan ve network yapısına dahil edilecek olan başka bir &amp;#252;r&amp;#252;n ile uyumsuzluk yapacak olan networklerde, mevcut yapıyı bozmak, değiştirmek i&amp;#231;in, bazen ise &amp;#231;ok daha pahalı ve iş y&amp;#252;k&amp;#252; getirecek durumlar da Transparent Mod bir &amp;#231;&amp;#246;z&amp;#252;m oluşturacaktır. &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Veya potansiyel bir m&amp;#252;şterimiz i&amp;#231;in firewall ihtiyacını karşılamak adına M&amp;#252;şterimizin network&amp;#252;ne DEMO ama&amp;#231;lı olarak &amp;#252;r&amp;#252;n&amp;#252;m&amp;#252;z&amp;#252; bırakacağız. Demo s&amp;#252;resi i&amp;#231;erisinde mevcut network yapısını değiştirmektense Trasnparent Modda yapılandırıp, demo sonrasında &amp;#252;r&amp;#252;n&amp;#252; networkden &amp;#231;ıkartabiliriz ve Mevcut yapıda herhangi bir değişiklik yapmamış olabiliriz. &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Transparent Mode yapılandırılmasında, mevcut Layer 3 yapılandırılmasını değiştirmiyoruz. Transparent mod yapılandırılmasında Fortigate Firewallımız mevcut networkun i&amp;#231;ine, mevcut networkde ki boşta bulunan bir IP adresi atamamız ile dahil etmiş oluyoruz. Tabirde yanlışlık olmadığını varsayarsak Bridge mod olarak yapılandırdığımızı s&amp;#246;yleyebiliriz. &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#220;r&amp;#252;n&amp;#252;m&amp;#252;z Transparent Modda iken Nat ve Route Modda yapmış olduğu gibi, &amp;#252;zerinden ge&amp;#231;en b&amp;#252;t&amp;#252;n trafiğin, paketlerin virus ve attack taramasını, web filter uygulamasını, mail content filtrelemesini vb. işlemlerini ger&amp;#231;ekleştirmektedir. &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image001.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="306" alt="image001" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image001_thumb.jpg" width="670" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Yukarıda ki topolojide 10.10.10.54/24 Ipadresine sahip clientimiz &amp;#252;zerinde Transparent Mod yapılandırılmasını ger&amp;#231;ekleştireceğiz. Ve bu topolojide b&amp;#252;t&amp;#252;n yapılandırmamızdan sadece ama sadece 10.10.10.54 IP adresine sahip clientimiz etkilenecek. &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Yukarıda ki topolojide ki gibi bağlantıları ger&amp;#231;ekleştirdikten sonra yapılandırmamıza başlıyoruz. &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image003.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="225" alt="image003" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image003_thumb.jpg" width="631" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;İlk olarak firewallımızın System Information b&amp;#246;l&amp;#252;m&amp;#252; altında ki &lt;b style="mso-bidi-font-weight:normal;"&gt;Operation Mode&lt;/b&gt; b&amp;#246;l&amp;#252;m&amp;#252;n&amp;#252; g&amp;#246;r&amp;#252;yoruz. Default olarak NAT modunda olup, &lt;b style="mso-bidi-font-weight:normal;"&gt;Chance&lt;/b&gt; butonu ile modunu değiştiriyoruz. &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image004.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="174" alt="image004" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image004_thumb.jpg" width="506" border="0" /&gt;&lt;/a&gt;&amp;#160;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Mod b&amp;#246;l&amp;#252;m&amp;#252;nde Transparent b&amp;#246;l&amp;#252;m&amp;#252;ne getirdikten sonra Managment IP/Netmask b&amp;#246;l&amp;#252;m&amp;#252;ne i&amp;#231; networkumuzden, firewallımızı y&amp;#246;netmek i&amp;#231;in bir IP ataması ger&amp;#231;ekleştiriyoruz. Default Gateway b&amp;#246;l&amp;#252;m&amp;#252;ne ise sahip olduğumuz internet &amp;#231;ıkışını ger&amp;#231;ekleştiren Routerimizin IP adresini yazıyoruz. &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image005.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="222" alt="image005" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image005_thumb.jpg" width="628" border="0" /&gt;&lt;/a&gt;&amp;#160;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Modumuzu değiştirdikten sonra atamış olduğumuz IP adresinden firewallımıza ulaşıyoruz ve modunun Transparent olduğunu g&amp;#246;rebiliyoruz.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Firewallımızın modunu Trasnparent olarak değiştirdikten sonra NAT/Route moduna g&amp;#246;re değişen &amp;#246;zellikleri;&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image006.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="300" alt="image006" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image006_thumb.jpg" width="274" border="0" /&gt;&lt;/a&gt;&amp;#160;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Firewallımızın &lt;b style="mso-bidi-font-weight:normal;"&gt;Router &amp;#246;zelliği artık Yok&lt;/b&gt;.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image008.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="167" alt="image008" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image008_thumb.jpg" width="264" border="0" /&gt;&lt;/a&gt;&amp;#160;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;System sekmesi altında &lt;b style="mso-bidi-font-weight:normal;"&gt;DHCP ve Certificates&lt;/b&gt; b&amp;#246;l&amp;#252;mlerinin gittiğini g&amp;#246;rebilmekteyiz.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image010.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="149" alt="image010" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image010_thumb.jpg" width="269" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Firewall sekmesi altında &lt;b style="mso-bidi-font-weight:normal;"&gt;Virtual IP&lt;/b&gt; b&amp;#246;l&amp;#252;m&amp;#252; yok. &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image012.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="89" alt="image012" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image012_thumb.jpg" width="266" border="0" /&gt;&lt;/a&gt;&amp;#160;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;VPN b&amp;#246;l&amp;#252;m&amp;#252; sekmesinde &lt;b style="mso-bidi-font-weight:normal;"&gt;PPTP ve SSL VPN&lt;/b&gt; &amp;#246;zellikleri artık yok. &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&lt;/span&gt;    &lt;p&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image014.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="88" alt="image014" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image014_thumb.jpg" width="268" border="0" /&gt;&lt;/a&gt;&amp;#160; &lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Intrusion Protection sekmesinde &lt;b style="mso-bidi-font-weight:normal;"&gt;DoS Sensor&lt;/b&gt; &amp;#246;zelliğimizde artık yoktur.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image016.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="138" alt="image016" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image016_thumb.jpg" width="633" border="0" /&gt;&lt;/a&gt;&amp;#160;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;NAT/Route yapılandırılmasında , &lt;b style="mso-bidi-font-weight:normal;"&gt;Firewall / Policy sekmesi altında bulunan default kuralımız&lt;/b&gt; yukarıda ki gibi olup, &lt;b style="mso-bidi-font-weight:normal;"&gt;internaldan &amp;#8211; wan1&amp;#8217;e b&amp;#252;t&amp;#252;n portlar a&amp;#231;ıktır.&lt;/b&gt;&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image017.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="170" alt="image017" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image017_thumb.jpg" width="634" border="0" /&gt;&lt;/a&gt;&amp;#160;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Transparent Mod yapılandırılmasında ise , Firewall / Policy sekmesi altında bulunan default kuralımız &lt;b style="mso-bidi-font-weight:normal;"&gt;Internaldan &amp;#8211; Wan1&amp;#8217;e ve Wan1&amp;#8217;den &amp;#8211; İnternal&amp;#8217;a t&amp;#252;m portlar a&amp;#231;ık&lt;/b&gt; olacak şekilde değişmektedir. &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Kurallarımızı diğer modlarda olduğu gibi Edit b&amp;#246;l&amp;#252;m&amp;#252;nden d&amp;#252;zenleyebiliyoruz.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt; &lt;/span&gt;    &lt;p&gt;&amp;#160;&lt;/p&gt;   &lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image018.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="484" alt="image018" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image018_thumb.jpg" width="588" border="0" /&gt;&lt;/a&gt;&amp;#160;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Kuralımızın , policymizin i&amp;#231;ine girdiğimiz zaman Source Interface (kaynak) ve Destination İnterface (hedef) b&amp;#246;l&amp;#252;mleri haricinde gerekli değişiklikleri yapabiliyoruz.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Yapacak olduğumuz ilk eylem Service ksımında &lt;b style="mso-bidi-font-weight:normal;"&gt;ANY (hep şey)&lt;/b&gt; olan protokol&amp;#252;m&amp;#252;z&amp;#252;, ihtiya&amp;#231;larımız doğrultusunda değiştirmek &amp;#252;zere &lt;b style="mso-bidi-font-weight:normal;"&gt;MULTIPLE &lt;/b&gt;(&amp;#231;oklu) olarak d&amp;#252;zenliyoruz.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;D&amp;#252;zenlememiz sonrasında &lt;b style="mso-bidi-font-weight:normal;"&gt;Protection Profile&lt;/b&gt; kısmında daha &amp;#246;nceden oluşturmuş olduğumuz Protection Profilemizi Kuralımıza atıyoruz.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Protection Profile yapılandırılması i&amp;#231;in &lt;/span&gt;&lt;a href="http://cozumpark.com/blogs/fortigate/archive/2008/03/30/fortigate-utm-firewall-zerinde-web-filter-uygulamas.aspx"&gt;Fortigate UTM Firewall uzerinde WEB Filter Uygulaması&lt;/a&gt; makalesinden yararlanabilirsiniz.&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image020.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="375" alt="image020" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image020_thumb.jpg" width="606" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Multiple b&amp;#246;l&amp;#252;m&amp;#252; i&amp;#231;erisinde internet &amp;#231;ıkışımız i&amp;#231;in ihtiya&amp;#231; duyulan portları &lt;b style="mso-bidi-font-weight:normal;"&gt;Available Services&lt;/b&gt; b&amp;#246;l&amp;#252;m&amp;#252; i&amp;#231;inden (ust kısımdan), &lt;b style="mso-bidi-font-weight:normal;"&gt;Members b&amp;#246;l&amp;#252;m&amp;#252;&lt;/b&gt; i&amp;#231;ine (alt kısım) taşıyoruz ve Members b&amp;#246;l&amp;#252;m&amp;#252; i&amp;#231;inde olan ANY&amp;#8217;i Available Services b&amp;#246;l&amp;#252;m&amp;#252;ne taşıyoruz. &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Bu d&amp;#252;zenleme ile kuralımız sadece internet erişimine izin verecektir.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image021.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="186" alt="image021" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image021_thumb.jpg" width="636" border="0" /&gt;&lt;/a&gt;&amp;#160;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;D&amp;#252;zenlememizden sonra kuralımız yukarıda ki hali alıp, web ve mail trafiğine izin vermektedir.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image022.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="579" alt="image022" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image022_thumb.jpg" width="670" border="0" /&gt;&lt;/a&gt;&amp;#160;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;VE firewallımız arkasında bulunan Clientimiz yasaklı olan bir web sayfasına girememekte olup, izin verilen diğer web sayfasına iletişimde bulunmaktadır.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image023.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="459" alt="image023" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image023_thumb.jpg" width="670" border="0" /&gt;&lt;/a&gt;&amp;#160;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Clientimiz &amp;#252;zerinden hangi yollar izlenilerek web sayfasına ulaştığını kontrol ettiğimizde ise, ilk gitmiş olduğu Hop (hedef), İnternet iletişimimizi ger&amp;#231;ekleştirmiş olduğumuz Router (ADSL Modemimiz) olduğunu g&amp;#246;rebilmekteyiz. &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Firewallımız transparent mod i&amp;#231;inde olduğu i&amp;#231;in g&amp;#246;r&amp;#252;lememektedir.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Not :&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:10pt;font-family:;"&gt; Tracert komutunu yani gidilen hopları g&amp;#246;rebilmek adına Internaldan Wan1&amp;#8217;e olan 3 numaralı ID&amp;#8217;ye sahip Policymiz i&amp;#231;ine Tracert protokol&amp;#252;n&amp;#252;de ekledim. Eklemeseydim bu b&amp;#246;l&amp;#252;mde istek zaman aşımına uğradığı uyarısı karşımıza gelecekti.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image024.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="414" alt="image024" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image024_thumb.jpg" width="592" border="0" /&gt;&lt;/a&gt;&amp;#160;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;İ&amp;#231;eriden dışarıya (Internaldan WAN1&amp;#8217;e ) kuralımızdan sonra, dışarıdan i&amp;#231;eriye (WAN1&amp;#8217;den Internal&amp;#8217;a) kuralımızı d&amp;#252;zenleyeceğiz.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Not : &lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:10pt;font-family:;"&gt;10.10.10.54 IP adresli Clientimizin 10.10.10.3 numaralı Terminal Serverimiza Uzakmasa&amp;#252;st&amp;#252; iletişimi yapabilmesi i&amp;#231;in TCP IP 3390 (TS default portu değiştirilmiştir) numaralı, portu Internaldan Wan1&amp;#8217;e olan 3 numaralı ID&amp;#8217;ye sahip Policymiz i&amp;#231;ine RDP ALLOW olarak oluşturduğum &amp;#246;zelleştirilmiş protokol&amp;#252;n&amp;#252; ekledim&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Gerekli ayarlar yapıldıktan sonra 10.10.10.54 numaralı clientimiz, 10.10.10.3 numaralı Terminal Serverimiza gidiyor ve TS serverimizda clientimiza 3389 numaralı RDP portu ile gelebilmektedir.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Terminal Serverimizin Clientimiza gelebilmesi i&amp;#231;in herhangi bir eylem ger&amp;#231;ekleştirmiyorum sebebi ise zaten WAN1&amp;#8217;den Internal&amp;#8217;a t&amp;#252;m portlarımız (ANY) olarak izinlidir.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image025.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="414" alt="image025" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image025_thumb.jpg" width="592" border="0" /&gt;&lt;/a&gt;&amp;#160;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Yukarıda ki resimden de anlaşılacağı &amp;#252;zere Terminal Serverimiz Clientimiz ile her t&amp;#252;rl&amp;#252; istekde bulunabilmektedir.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&lt;/span&gt;    &lt;p&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image026.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="481" alt="image026" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image026_thumb.jpg" width="587" border="0" /&gt;&lt;/a&gt;&amp;#160; &lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Wan1&amp;#8217; den internal&amp;#8217;a gelen istekleri d&amp;#252;zenlemek adına iki numaralı ID&amp;#8217; ye sahip policymizi editliyoruz. &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Policymizin i&amp;#231;inde Service b&amp;#246;l&amp;#252;m&amp;#252; altında ihtyia&amp;#231; duyulan servisleri Multiple olarak se&amp;#231;ip izin verebileceğimiz gibi sadece ilgili bir protokolede izin verebiliriz. Eğer ihtiya&amp;#231; duyulan servisimiz Firewallımız i&amp;#231;inde ki tanımlı servislerde yok ise Create NEW b&amp;#246;l&amp;#252;m&amp;#252; ile &amp;#246;zel bir servis atayabiliriz.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt; &lt;/span&gt;    &lt;p&gt;&lt;/p&gt;   &lt;span style="font-size:10pt;font-family:;"&gt;RDP protokol&amp;#252;n&amp;#252; eklemek adıan Create NEW butonuna tıklıyoruz.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image027.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="220" alt="image027" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image027_thumb.jpg" width="603" border="0" /&gt;&lt;/a&gt;&amp;#160;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;New Custom Service B&amp;#246;l&amp;#252;m&amp;#252;nde 3389 Protokolomuzu ekliyoruz. &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Add b&amp;#246;l&amp;#252;m&amp;#252; ile birden fazla servisi aynı grup altına toplayabiliriz.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image028.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="139" alt="image028" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image028_thumb.jpg" width="735" border="0" /&gt;&lt;/a&gt;&amp;#160;&lt;span style="font-size:10pt;font-family:;"&gt; &lt;/span&gt;    &lt;p&gt;&amp;#160;&lt;/p&gt;   &lt;span style="font-size:10pt;font-family:;"&gt;Kuralımızı d&amp;#252;zenleyip, uyguladıktan sonra 2 numaralı ID&amp;#8217; ye sahip Wan1&amp;#8217; den Internal&amp;#8217;a olan kuralımızın Service b&amp;#246;l&amp;#252;m&amp;#252;nde sadece ama sadece &lt;b style="mso-bidi-font-weight:normal;"&gt;RDP ALLOW&lt;/b&gt; servisine izin verildiğini g&amp;#246;rebilmekteyiz.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image029.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="568" alt="image029" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image029_thumb.jpg" width="645" border="0" /&gt;&lt;/a&gt;&amp;#160;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Kuralımız uygulandıktan sonra Terminal Serverimiz, Clientimiza Uzakmasa &amp;#252;st&amp;#252; protokol&amp;#252; ile bağlandığını ama izin verilmediği i&amp;#231;in ping isteklerinin bloklandığını g&amp;#246;rebilmekteyiz.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image033.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="516" alt="image033" src="http://cozumpark.com/mklresim/FortigateFirewallTransparentModYaplandrl_F100/image033_thumb.jpg" width="508" border="0" /&gt;&lt;/a&gt;&amp;#160;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Firewall yapılandırmamızı tamamladıktan sonra Firewallımızı Transparent Mod olarak network&amp;#252;m&amp;#252;ze konuşlandırabiliriz. &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Eğer firewallımızı Demo ama&amp;#231;lı olarak bir networke konuşlandıracaksak, mevcut networkde internet kesintisinin algılanmasını minimum seviyede tutmak adına Firewallımızın elektiriğini verip WAN1 portu bağlantısını ger&amp;#231;ekleştirmeden Servislerinin geldiğini ve a&amp;#231;ıldığını g&amp;#246;relim. Servisler geldikten sonra Modem ile SW arasında ki kabloyu &amp;#231;ıkartıp Firewallımızın WAN1 poruna hızlı bir şekilde bağlarsak internet kesintisi sadece ama sadece kabloyu &amp;#231;ıkart tak daki hızımıza bağlı olarak değişecektir. Yani saniyelik bir olaydır.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Farklı Fortigate Transparent Mod topolojilerini ve network diyagramları i&amp;#231;in aşağıda ki linkten yararlanabilirsiniz. &lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;a href="http://kc.forticare.com/redirfile.asp?id=183&amp;amp;SID"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;http://kc.forticare.com/redirfile.asp?id=183&amp;amp;SID&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0pt;line-height:normal;text-align:justify;"&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="font-size:13pt;font-family:;"&gt;Fa&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:10pt;font-family:;"&gt;tih &lt;/span&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="font-size:13pt;font-family:;"&gt;KA&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:10pt;font-family:;"&gt;RAALİOĞLU &lt;/span&gt;&lt;/p&gt;&lt;img src="http://cozumpark.com/aggbug.aspx?PostID=31465" width="1" height="1"&gt;</description><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/VPN/default.aspx">VPN</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/IPSec/default.aspx">IPSec</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortigate/default.aspx">Fortigate</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortigate+Firewall+Fortigate+Sip+Server/default.aspx">Fortigate Firewall Fortigate Sip Server</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortinet+Fortigate+Firewall+Profosyonel+Loglama+Cihaz_3101_+Fortianalyzer/default.aspx">Fortinet Fortigate Firewall Profosyonel Loglama Cihazı Fortianalyzer</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortinet+Fortigate+ile+SSL+VPN+Nas_3101_l+Yap_3101_l_3101_r+Vpn+G_26002300_252_3B00_venli_1F01_i+Ssl+Makale/default.aspx">Fortinet Fortigate ile SSL VPN Nasıl Yapılır Vpn G&amp;#252;venliği Ssl Makale</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortinet+Fortigate+_3001_le+One+to+One+Nat+Nas_3101_l+Yap_3101_l_3101_r/default.aspx">Fortinet Fortigate İle One to One Nat Nasıl Yapılır</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortinet+Fortigate+ANTISPAM+Servisi+Nas_3101_l+Kullan_3101_l_3101_r/default.aspx">Fortinet Fortigate ANTISPAM Servisi Nasıl Kullanılır</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Firewall/default.aspx">Firewall</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortinet/default.aspx">Fortinet</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortigate+Sip+Server/default.aspx">Fortigate Sip Server</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+firewall/default.aspx">fortigate firewall</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+antispam/default.aspx">fortigate antispam</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+ayarlar/default.aspx">fortigate ayarlar</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+d_31015F01_ardan+eri_5F01_im/default.aspx">fortigate dışardan erişim</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+utm/default.aspx">fortigate utm</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+temel/default.aspx">fortigate temel</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortianalyzer/default.aspx">fortianalyzer</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+rbl+Command/default.aspx">fortigate rbl Command</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Transparent/default.aspx">Transparent</category></item><item><title>Fortinet Fortigate Firewall ile Syslog Sunucu Kurulumu ve Yapılandırılması</title><link>http://cozumpark.com/blogs/fortigate/archive/2008/04/28/fortinet-fortigate-firewall-ile-syslog-sunucu-kurulumu-ve-yap-land-r-lmas.aspx</link><pubDate>Sun, 27 Apr 2008 21:01:00 GMT</pubDate><guid isPermaLink="false">36acb80b-3ae7-4dda-bbe8-b4ae2f1fa947:15273</guid><dc:creator>Savas Demir</dc:creator><slash:comments>7</slash:comments><comments>http://cozumpark.com/blogs/fortigate/comments/15273.aspx</comments><wfw:commentRss>http://cozumpark.com/blogs/fortigate/commentrss.aspx?PostID=15273</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;Ağımızda kullanmış olduğumuz bilgisayarların yaptıkları içerden dışarı ya da dışarıdan içeri olan hareketlerinin izlenmesi işlemine loglama denilir. Loglama yapacak donanım yâda yazılım üzerinden geçen tcp yâda udp paketleri decode ederek source (kaynak)isteklerini, kullandıkları tcp/udp port servislerinin almış olduğu cevabı kısacası yapılan bir isteğe ve verilen cevabın tümünü bu işlem ile görebiliriz. Artık günümüzde yapılan bilinçli yâda bilinçsiz saldırıların % 70 iç networklerden olmaktadır. Art niyetli bir kullanım ile dışarıdan içeri, içeriden dışarı olan istekleri loglamak günümüzde şirketlerin olmazsa olmazlarından biri olmuştur. Bilgi işlem sorumluları yâda bilgisayar hizmeti aldığımız kişilerin bu loglamayı bilgisayar kullanıcılarına duyurarak yapması gerekmektedir. Art niyet olmadan yapılan kötü niyetli işlemler şirket bütçesine verilen maddi zararın % 30 ını oluşturduğu bilinmektedir. Art niyetlice tamamen kar – zarar gözeterek yapılan zararın % 40 ı bulması firmaların bir kez daha loglama ve raporlama durumu hakkındaki düşüncelerini etkilemiştir. Masum ve korunmasız ağlar sayesinde kırıcı dediğimiz kişiler yönetimini ele geçirdikleri bilgisayarlar ile zombi attack’ları yapmaktadır. Bilinçsiz kullanıcı hiç bir şeyin farkında değilken Türkiye’nin her hangi bir ilinden İngiltere deki kumar sitelerine kendi bilgisayarı ile saldırı yapmaktadır. Şu an internet üzerinden yapılan bu saldırılar beraberinde bir ticaret kapısı açmış bulunmaktadır. Yasa dışı olan bu ticaret uyuşturucu, terör ve kumar gelirlerinden daha fazla para kazandırmaktadır. Yapılan işlem kısaca bir kırıcı (bootnet) 10.000 ile 100.000 bilgisayarın idaresini başka bir art niyetli kişi yâda kuruma kiralar. Zombi bilgisayarlar üzerinden yapılan attack, phishing, spam, virüs gibi işlemler ile para kazanmak, zarar vermek amaçlanmaktadır. Doğruluğu kanıtlanmamış İngiltere’de bir kaç büyük bahis sitesinin bu Bootnet’lerden korunmak için onlara belli bir para ödediğidir. Klasik firewalllarımızdaki yapı aşağıdaki resimdeki gibidir.     &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;span style="font-size:10pt;"&gt;&lt;br&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;      &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateFirewallileSyslogSunucu_21/clip_image001.jpg"&gt;&lt;img src="http://cozumpark.com/mklresim/FortinetFortigateFirewallileSyslogSunucu_21/clip_image001_thumb.jpg" style="border:0px none;" alt="clip_image001" border="0" height="455" width="604"&gt;&lt;/a&gt;      &lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;Görmüş olduğunuz resimde yapılan hareketleri geçmişte kullanmış olduğumuz firewall’lar ile engelleyebiliyorduk. Değişen günümüzdeki teknoloji ile geçmişteki firewall, modem yâda routerlarımız bugün ki tehlikeleri korumakta yetersiz kalmaktadır. Tamamen sistemlerimizdeki güvenlik açıkları ile bize saldırmak için bekleyen art niyetli kişiler aşağıdaki resimdeki gibi yöntemler ile günümüzde saldırılarını yapmaktadır.     &lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;span style="font-size:10pt;"&gt;&lt;br&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateFirewallileSyslogSunucu_21/clip_image002.jpg"&gt;&lt;img src="http://cozumpark.com/mklresim/FortinetFortigateFirewallileSyslogSunucu_21/clip_image002_thumb.jpg" style="border:0px none;" alt="clip_image002" border="0" height="403" width="604"&gt;&lt;/a&gt;      &lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;Resimde görüldüğü gibi tehditler artık günümüzde tümleşik olarak ağımıza girmeye yâda ağımızdan dışarı çıkmaya çalışmaktadır. Yapılması gereken öncelikle bu tehditleri engellemek ve engellediğimiz network hareketlerini loglayıp raporlamaktır.     &lt;br&gt;      &lt;br&gt;Loglama Yöntemleri;      &lt;br&gt;      &lt;br&gt;&lt;u&gt;Hardware Loglama;&lt;/u&gt;       &lt;p&gt;&amp;nbsp;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;&lt;a href="http://cozumpark.com/blogs/fortigate/archive/2008/03/30/fortinet-fortigate-firewall-profosyonel-loglama-cihaz-fortianalyzer-resimleri.aspx"&gt;Daha önceki makalemizde Fortianalyzer ile ilgili bilgi vermiştik. Bu konuya değinmeye gerek yok. İlgili makale sitemizde yayındadır.&lt;/a&gt;Tıklayarak erişmeniz mümkün.      &lt;br&gt;Software Loglama ;      &lt;br&gt;&lt;u&gt;Lisanslı Software (Yazılım) Loglama;&lt;/u&gt;       &lt;p&gt;&amp;nbsp;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;Bu konuda firewall, router, modem, switch üreticilerinin log&amp;amp;report yazılımları mevcuttur. Detaylı bilgi bir sonraki makalemizde yayınlanacaktır.     &lt;br&gt;&lt;u&gt;Lisans Bedeli Gerektirmeyen Ücretsiz Yazılım;&lt;/u&gt;      &lt;p&gt;&amp;nbsp;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;Lisans bedeli gerektirmeyen bildiğim 2 tane yazılım mevcuttur. Bunlardan birisi 3Com Firmasının 3cdaemon yazılımı bir diğeri ise Kiwi Loglama yazılımıdır.     &lt;br&gt;Ben bu makalemizde 3cdaemon yazılımını anlatacağım.      &lt;br&gt;      &lt;br&gt;3cDaemon yazılım free (ücretsiz) bir syslog yazılımıdır. Syslog ne demektir sorusuna kısaca networkumuzdaki tüm gelen giden istekleri ileten yâda iletilenleri yorumlayan yazılım yâda donanım sunucusuna denir. Syslog Sunucu günümüzdeki tüm güvenlik duvarlarının dışında dsl modemlerimizde, routerlarımız da, yönetilebilir switchlerimizde olmaz ise olmazlardan biridir.      &lt;br&gt;3Cdaemon yazılımını yüklemek için üreticinin web sitesini ziyaret ediniz.Yüklemek için      &lt;br&gt;http://support.3com.com/yazılım/3cdv2r10.zip linkini kullanabilirsiniz. Syslog sunucusu port tcp/udp 514 ü kullanır portumuzun kullanılmadığından emin olmamız gerekir. Netstat –a komutu ile sorgulamak mümkün. Yazılımın kurulacağı bilgisayarın 7/24 açık olması gerekmektedir.      &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;Kurulum; Yukarıdaki adresten 3CDaemon vers 2.0 rev 10 - a TFTP, FTP, Syslog server and TFTP client for Win32 yazılımını indiriyoruz.     &lt;br&gt;Tipik kurduğumuz yazılımlar gibi next next devam ediyoruz.         &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;br&gt;&lt;span style="font-size:10pt;"&gt;Kurulum tamamlanınca aşağıdaki gibi ekran alırız.        &lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;Resim 1        &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:12pt;"&gt;&lt;span style="font-size:10pt;"&gt;Burada loglama yaparken seçilecek dosya yapısı önemli. Lütfen tek dosyaya loglama yapmayınız.        &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateFirewallileSyslogSunucu_21/clip_image003.jpg"&gt;&lt;img src="http://cozumpark.com/mklresim/FortinetFortigateFirewallileSyslogSunucu_21/clip_image003_thumb.jpg" style="border:0px none;" alt="clip_image003" border="0" height="348" width="604"&gt;&lt;/a&gt;      &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br&gt;&lt;span style="font-size:10pt;"&gt;Resimde görüldüğü üzere syslog server seçilir. Log alınacak dizin seçilir.     &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;Resim 2         &lt;/span&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;      &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;Fortigate Syslog sunucu ayarlarını bu şekilde yapıyoruz.        &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateFirewallileSyslogSunucu_21/clip_image004.jpg"&gt;&lt;img src="http://cozumpark.com/mklresim/FortinetFortigateFirewallileSyslogSunucu_21/clip_image004_thumb.jpg" style="border:0px none;" alt="clip_image004" border="0" height="368" width="604"&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br&gt;&lt;span style="font-size:10pt;"&gt;Resim 3     &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;Pc’mize yüklediğimiz program istediğimiz dizin altında aşağıdaki dosyaları oluşturuyor.        &lt;/span&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateFirewallileSyslogSunucu_21/clip_image005.jpg"&gt;&lt;img src="http://cozumpark.com/mklresim/FortinetFortigateFirewallileSyslogSunucu_21/clip_image005_thumb.jpg" style="border:0px none;" alt="clip_image005" border="0" height="358" width="604"&gt;&lt;/a&gt;      &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;Yukarıya aşağıdaki gibi satır satır loglar düşmeye başlayacaktır. Yorumlamak gerçekten uzmanlık ister.     &lt;br&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;Bir satırlık örnek;     &lt;br&gt;         &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;04-26-2008&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 23:52:59&amp;nbsp; Local7.Notice192.168.1.99&amp;nbsp;&amp;nbsp;&amp;nbsp; date=2008-04-26,time=&lt;br&gt;23:52:11,devname=FGT-603907516772,device_id=&lt;/b&gt;&lt;b&gt;&lt;br&gt;FGT03907516772,log_id=0021010001,type=traffic,subtype=allowed,pri&lt;/b&gt;&lt;b&gt;=     &lt;br&gt;notice,vd=root,SN=361541,duration=70,user=N/A,group=N/A,policyid=1,proto=&lt;br&gt;6,service=80/tcp,app_type=      &lt;br&gt;&lt;/b&gt;&lt;b&gt;N/A,status=accept,src=192.168.1.51,srcname=&lt;br&gt;192.168.1.51,dst=84.53.182.49,dstname=84.53.182.49,src_int=     &lt;br&gt;&lt;/b&gt;&lt;b&gt;internal,dst_int=wan1,sent=648,rcvd=364,sent_pkt=5,rcvd_pkt=3,src_port=&lt;br&gt;4543,dst_port=80,vpn=N/A,tran_ip=     &lt;br&gt;&lt;/b&gt;&lt;b&gt;192.168.2.10,tran_port=47907,dir_disp=org,tran_disp=snat,&lt;/b&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;&lt;br&gt;Kısaca cihaz hangi tarihte, hangi saatte, hangi ip ile hangi cihaz üzerinden, hangi log id ile kullandığı trafik tipi, sürekliliği, user name, group name kullandığı policy id protokolü kullandığı tcp servisi, gittiği ip adresi vs vs gibi değerleri alırsınız.     &lt;br&gt;      &lt;br&gt;Bir sonraki makalede görüşmek dileği ile.      &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;"&gt;Lütfen sorularınızı &lt;a href="http://cozumpark.com/forums/80/ShowForum.aspx"&gt;http://cozumpark.com/forums/80/ShowForum.aspx&lt;/a&gt; kısmından sorunuz.&lt;br&gt;&lt;br&gt;ÇözümPark ta çözülmeyecek sorun yok &lt;/span&gt;&lt;/p&gt;&lt;img src="http://cozumpark.com/aggbug.aspx?PostID=15273" width="1" height="1"&gt;</description><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Draytek/default.aspx">Draytek</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortigate/default.aspx">Fortigate</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Firewall/default.aspx">Firewall</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortinet/default.aspx">Fortinet</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Syslog/default.aspx">Syslog</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+kurulum/default.aspx">draytek kurulum</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/one+to+one+nat/default.aspx">one to one nat</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/foritgate+ssl+vpn/default.aspx">foritgate ssl vpn</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+antispam+fortigate+dnsbl/default.aspx">fortigate antispam fortigate dnsbl</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortigate+Sip+Server/default.aspx">Fortigate Sip Server</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+firewall/default.aspx">fortigate firewall</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+e_1F01_itim/default.aspx">fortigate eğitim</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+temel/default.aspx">draytek temel</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+antispam/default.aspx">fortigate antispam</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+bilgi/default.aspx">draytek bilgi</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+ayarlar/default.aspx">fortigate ayarlar</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+d_31015F01_ardan+eri_5F01_im/default.aspx">fortigate dışardan erişim</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+vpn/default.aspx">draytek vpn</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+utm/default.aspx">fortigate utm</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+temel/default.aspx">fortigate temel</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+makale/default.aspx">fortigate makale</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortianalyzer/default.aspx">fortianalyzer</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+rbl+Command/default.aspx">fortigate rbl Command</category></item><item><title>Fortigate ile Draytek arasında IPSec VPN Konfigurasyonu</title><link>http://cozumpark.com/blogs/fortigate/archive/2008/04/19/fortigate-ile-draytek-aras-nda-_3101_psec-vpn-konfig-rasyonu.aspx</link><pubDate>Sat, 19 Apr 2008 17:48:00 GMT</pubDate><guid isPermaLink="false">36acb80b-3ae7-4dda-bbe8-b4ae2f1fa947:13615</guid><dc:creator>Savas Demir</dc:creator><slash:comments>1</slash:comments><comments>http://cozumpark.com/blogs/fortigate/comments/13615.aspx</comments><wfw:commentRss>http://cozumpark.com/blogs/fortigate/commentrss.aspx?PostID=13615</wfw:commentRss><description>&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Fortinet Fortigate Firewall ile Draytek Vigor dsl modemimizi ip sec vpn yapmamız için adım adım kurulum ve ayarları anlatalım. Aşağıdaki yapı bir gibi sistemimiz mevcut. Her iki tarafa da Fortigate koymak istemiyorsak. Fortigate ile dsl modemi ip sec görüştürme olanağımız mevcut. Adım adım resimleri takip ediniz.&lt;/SPAN&gt;&lt;SPAN&gt; 
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal align=center&gt;&lt;SPAN&gt;&lt;A href="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image001.jpg"&gt;&lt;IMG style="BORDER-TOP:0px;BORDER-LEFT:0px;BORDER-BOTTOM:0px;" height=174 alt=clip_image001 src="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image001_thumb.jpg" width=492 border=0&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt; 
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;BR&gt;Yapılması Gerekenler &lt;BR&gt;Modem Network Ayarlarımız Vigor LAN range: 172.16.1.0/255.255.255.0 &lt;BR&gt;Firewall Modem Ayarlarımız&amp;nbsp; Fortigate LAN range: 192.168.198.0/255.255.255.0 &lt;BR&gt;Vigor as dial-out side, dial to Fortigate router/firewall. &lt;BR&gt;In this example, we just test &lt;B&gt;Aggressive mode&lt;/B&gt;. &lt;BR&gt;&lt;BR&gt;&lt;B&gt;Vigor tarafındaki Ayarları &lt;/B&gt;&lt;BR&gt;&lt;BR&gt;1.Resimde görülen&amp;nbsp; 211.152.185.106 Fortigate Wan İp adresi &lt;BR&gt;&lt;BR&gt;“IKE Pre-Shared key” buraya tıklayarak bir şifre giriyoruz. Aynı şifre karşı tarafta da olmalı&lt;/SPAN&gt;&lt;SPAN&gt; 
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal align=center&gt;&lt;SPAN&gt;&lt;A href="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image002.jpg"&gt;&lt;IMG style="BORDER-TOP:0px;BORDER-LEFT:0px;BORDER-BOTTOM:0px;" height=476 alt=clip_image002 src="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image002_thumb.jpg" width=604 border=0&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt; 
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal align=center&gt;&lt;SPAN&gt;&lt;A href="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image003.jpg"&gt;&lt;IMG style="BORDER-TOP:0px;BORDER-LEFT:0px;BORDER-BOTTOM:0px;" height=252 alt=clip_image003 src="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image003_thumb.jpg" width=553 border=0&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt; 
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;BR&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;SPAN&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal align=center&gt;&lt;SPAN&gt;&lt;A href="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image004.jpg"&gt;&lt;IMG style="BORDER-TOP:0px;BORDER-LEFT:0px;BORDER-BOTTOM:0px;" height=203 alt=clip_image004 src="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image004_thumb.jpg" width=571 border=0&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt; 
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;BR&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;SPAN&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal align=center&gt;&lt;SPAN&gt;&lt;A href="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image005.jpg"&gt;&lt;IMG style="BORDER-TOP:0px;BORDER-LEFT:0px;BORDER-BOTTOM:0px;" height=380 alt=clip_image005 src="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image005_thumb.jpg" width=604 border=0&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt; 
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal align=center&gt;&lt;SPAN&gt;&lt;A href="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image006.jpg"&gt;&lt;IMG style="BORDER-TOP:0px;BORDER-LEFT:0px;BORDER-BOTTOM:0px;" height=405 alt=clip_image006 src="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image006_thumb.jpg" width=601 border=0&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt; 
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;BR&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;SPAN&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal align=center&gt;&lt;SPAN&gt;&lt;A href="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image007.jpg"&gt;&lt;IMG style="BORDER-TOP:0px;BORDER-LEFT:0px;BORDER-BOTTOM:0px;" height=133 alt=clip_image007 src="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image007_thumb.jpg" width=563 border=0&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt; 
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal align=center&gt;&lt;SPAN&gt;&lt;A href="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image008.jpg"&gt;&lt;IMG style="BORDER-TOP:0px;BORDER-LEFT:0px;BORDER-BOTTOM:0px;" height=419 alt=clip_image008 src="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image008_thumb.jpg" width=589 border=0&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt; 
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal align=center&gt;&lt;SPAN&gt;&lt;A href="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image009.jpg"&gt;&lt;IMG style="BORDER-TOP:0px;BORDER-LEFT:0px;BORDER-BOTTOM:0px;" height=146 alt=clip_image009 src="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image009_thumb.jpg" width=577 border=0&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt; 
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal align=center&gt;&lt;SPAN&gt;&lt;A href="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image010.jpg"&gt;&lt;IMG style="BORDER-TOP:0px;BORDER-LEFT:0px;BORDER-BOTTOM:0px;" height=146 alt=clip_image010 src="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image010_thumb.jpg" width=577 border=0&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt; 
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal align=center&gt;&lt;SPAN&gt;&lt;A href="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image011.jpg"&gt;&lt;IMG style="BORDER-TOP:0px;BORDER-LEFT:0px;BORDER-BOTTOM:0px;" height=120 alt=clip_image011 src="http://cozumpark.com/mklresim/FortigateileDraytekarasndaIPSecVPNKonfig_12497/clip_image011_thumb.jpg" width=604 border=0&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt; 
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal align=center&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;Bir sonraki makalede görüşmek üzere. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;&lt;BR&gt;Draytek resmi sayfasından alıntıdır. &lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://cozumpark.com/aggbug.aspx?PostID=13615" width="1" height="1"&gt;</description><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Draytek/default.aspx">Draytek</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/VPN/default.aspx">VPN</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/IPSec/default.aspx">IPSec</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortigate/default.aspx">Fortigate</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Firewall/default.aspx">Firewall</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortinet/default.aspx">Fortinet</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Syslog/default.aspx">Syslog</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+kurulum/default.aspx">draytek kurulum</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/one+to+one+nat/default.aspx">one to one nat</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/foritgate+ssl+vpn/default.aspx">foritgate ssl vpn</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+antispam+fortigate+dnsbl/default.aspx">fortigate antispam fortigate dnsbl</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortigate+Sip+Server/default.aspx">Fortigate Sip Server</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+firewall/default.aspx">fortigate firewall</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+e_1F01_itim/default.aspx">fortigate eğitim</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+temel/default.aspx">draytek temel</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+antispam/default.aspx">fortigate antispam</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+bilgi/default.aspx">draytek bilgi</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+ayarlar/default.aspx">fortigate ayarlar</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+d_31015F01_ardan+eri_5F01_im/default.aspx">fortigate dışardan erişim</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+vpn/default.aspx">draytek vpn</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+utm/default.aspx">fortigate utm</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+temel/default.aspx">fortigate temel</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+makale/default.aspx">fortigate makale</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortianalyzer/default.aspx">fortianalyzer</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+rbl+Command/default.aspx">fortigate rbl Command</category></item><item><title>Fortinet Fortigate Firewall Profosyonel Loglama Cihazı Fortianalyzer Resimleri</title><link>http://cozumpark.com/blogs/fortigate/archive/2008/03/30/fortinet-fortigate-firewall-profosyonel-loglama-cihaz-fortianalyzer-resimleri.aspx</link><pubDate>Sun, 30 Mar 2008 20:17:00 GMT</pubDate><guid isPermaLink="false">36acb80b-3ae7-4dda-bbe8-b4ae2f1fa947:8168</guid><dc:creator>Savas Demir</dc:creator><slash:comments>4</slash:comments><comments>http://cozumpark.com/blogs/fortigate/comments/8168.aspx</comments><wfw:commentRss>http://cozumpark.com/blogs/fortigate/commentrss.aspx?PostID=8168</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;  &lt;p&gt;Bu cihaz ile tüm trafiğimizi,trafiğimizin içeriğini loglama şansına sahibiz.Bunun yanı sıra Forensic Report ile eskiye ait bir sorgulamayı çok basit bir şekilde yapmamıza izin vermektedir.Diğer tercih edilmesindeki sebeblerden biride bir nevi backup görevi görmesi.İçerden dışarı dışardan içeri tüm mailleri arşivleye bilmektedir.Active Directory ile senkronize çalışabilmektedir.Fazla lafa gerek yokYaptıkları aşağıda resimlerde mevcut.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;   &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;Resim 1&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateFirewallProfosyonelLogl_14757/clip_image002.jpg"&gt;&lt;img src="http://cozumpark.com/mklresim/FortinetFortigateFirewallProfosyonelLogl_14757/clip_image002_thumb.jpg" style="border:0px none;" alt="clip_image002" border="0" height="415" width="604"&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;   &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;Resim 2&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateFirewallProfosyonelLogl_14757/clip_image004.jpg"&gt;&lt;img src="http://cozumpark.com/mklresim/FortinetFortigateFirewallProfosyonelLogl_14757/clip_image004_thumb.jpg" style="border:0px none;" alt="clip_image004" border="0" height="220" width="604"&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;   &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;Resim 3 &lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateFirewallProfosyonelLogl_14757/clip_image006.jpg"&gt;&lt;img src="http://cozumpark.com/mklresim/FortinetFortigateFirewallProfosyonelLogl_14757/clip_image006_thumb.jpg" style="border:0px none;" alt="clip_image006" border="0" height="265" width="604"&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;   &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;Resim 4&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateFirewallProfosyonelLogl_14757/clip_image008.jpg"&gt;&lt;img src="http://cozumpark.com/mklresim/FortinetFortigateFirewallProfosyonelLogl_14757/clip_image008_thumb.jpg" style="border:0px none;" alt="clip_image008" border="0" height="259" width="604"&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;   &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;Resim 5&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateFirewallProfosyonelLogl_14757/clip_image010.jpg"&gt;&lt;img src="http://cozumpark.com/mklresim/FortinetFortigateFirewallProfosyonelLogl_14757/clip_image010_thumb.jpg" style="border:0px none;" alt="clip_image010" border="0" height="263" width="604"&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;   &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;Resim 6&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateFirewallProfosyonelLogl_14757/clip_image012.jpg"&gt;&lt;img src="http://cozumpark.com/mklresim/FortinetFortigateFirewallProfosyonelLogl_14757/clip_image012_thumb.jpg" style="border:0px none;" alt="clip_image012" border="0" height="270" width="604"&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;   &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;   &lt;/p&gt;&lt;p&gt;&lt;span style="font-size:10pt;"&gt;Bir sonraki makalede görüşmek 
dileği ile. Çözümde Çözüm Bulursunuz&lt;/span&gt; &lt;/p&gt;&lt;img src="http://cozumpark.com/aggbug.aspx?PostID=8168" width="1" height="1"&gt;</description><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Draytek/default.aspx">Draytek</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortigate/default.aspx">Fortigate</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortinet+Fortigate+Firewall+Profosyonel+Loglama+Cihaz_3101_+Fortianalyzer/default.aspx">Fortinet Fortigate Firewall Profosyonel Loglama Cihazı Fortianalyzer</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Firewall/default.aspx">Firewall</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortinet/default.aspx">Fortinet</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Syslog/default.aspx">Syslog</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+kurulum/default.aspx">draytek kurulum</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/one+to+one+nat/default.aspx">one to one nat</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/foritgate+ssl+vpn/default.aspx">foritgate ssl vpn</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+antispam+fortigate+dnsbl/default.aspx">fortigate antispam fortigate dnsbl</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortigate+Sip+Server/default.aspx">Fortigate Sip Server</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+firewall/default.aspx">fortigate firewall</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+e_1F01_itim/default.aspx">fortigate eğitim</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+temel/default.aspx">draytek temel</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+antispam/default.aspx">fortigate antispam</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+bilgi/default.aspx">draytek bilgi</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+ayarlar/default.aspx">fortigate ayarlar</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+d_31015F01_ardan+eri_5F01_im/default.aspx">fortigate dışardan erişim</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+vpn/default.aspx">draytek vpn</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+utm/default.aspx">fortigate utm</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+temel/default.aspx">fortigate temel</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+makale/default.aspx">fortigate makale</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortianalyzer/default.aspx">fortianalyzer</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+rbl+Command/default.aspx">fortigate rbl Command</category></item><item><title>Fortinet FortiGate Temel Kurulum Versiyon 3 MR6</title><link>http://cozumpark.com/blogs/fortigate/archive/2008/03/30/fortinet-fortigate-temel-kurulum-versiyon-3-mr6.aspx</link><pubDate>Sun, 30 Mar 2008 19:55:56 GMT</pubDate><guid isPermaLink="false">36acb80b-3ae7-4dda-bbe8-b4ae2f1fa947:8156</guid><dc:creator>Savas Demir</dc:creator><slash:comments>5</slash:comments><comments>http://cozumpark.com/blogs/fortigate/comments/8156.aspx</comments><wfw:commentRss>http://cozumpark.com/blogs/fortigate/commentrss.aspx?PostID=8156</wfw:commentRss><description>&lt;p&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;1 &amp;#8211; System - Ana Men&amp;#252;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;2 &amp;#8211; Router - Y&amp;#246;nlendirme&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;3 &amp;#8211; Firewall - G&amp;#252;venlik Tanımlamaları &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;4 &amp;#8211; Vpn - &amp;#214;zel Ağ Yapılandırması (Ipsec, Pptp, Ssl)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;5 &amp;#8211; Ips&amp;amp;Idp - Saldırı Tespiti Ve Durdurma&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;6 &amp;#8211; Web Filter - Web Ve İ&amp;#231;erik kısıtlamalar&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;7 &amp;#8211; AntiVirus &amp;amp; File Block - Vir&amp;#252;s Koruması-Dosya Engelleme - Grayware Koruması&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;8 &amp;#8211; AntiSpam BWL List - İstenmeyen Maillerden Kurtulma&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:12pt;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;9 &amp;#8211; Log - Report İzleme ve Raporlama&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;10-Fortinet Ek Donanım&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Merhaba;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Fortinet &amp;#220;r&amp;#252;nlerinden FortiGate U.T.M. ile ilgili temel kurulum bilgilerini aktaracağım.     &lt;br /&gt;Kuruluma başlamadan bilinmesi gereken bazı konular var. &amp;#214;nce bunlara cevap verelim.      &lt;br /&gt;U.T.M. Nedir? &lt;span style="color:black;"&gt;Unified Threat Management &amp;#8211; B&amp;#252;t&amp;#252;nleşik Tehdit Y&amp;#246;netimi&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;U.T.M. Neden Tercih Ediliyor? G&amp;#252;n&amp;#252;m&amp;#252;z bilgisayar teknolojileri fazlası ile ilerledi. Sadece bir firewall y&amp;#226;da AntiVirus sistemi korumamızda g&amp;#252;&amp;#231;s&amp;#252;z kalıyor. &amp;#199;oklu tehditler her an karsımıza &amp;#231;ıkabilir. &amp;#214;rneğin bir web sayfasından bulasan vir&amp;#252;s bu esnada sisteme gelen bir trojan ihtiva eden elektronik posta sistemimizin bozulmasına &amp;#231;eşitli kayıplara sebebe olmaktadır. Tehlikeler ağ girişinde daha ağa girmeden tespit edilip savuşturulabilir. Gereksiz yere bilgi kaybı, zaman kaybı ve firmaların maddi kayıpları bu sayede&amp;#160; engellenmektedir. Fortinet bu konuda firewall, ips&amp;amp;idp, antivirus (malware, spyware, grayware),Web Category Filter, Antispam Koruması, IM&amp;amp;P2P Koruması, Vpn Desteği (SSL, IPSEC, PPTP) ile g&amp;#252;n&amp;#252;m&amp;#252;z kullanıcılarına en &amp;#252;st seviyede g&amp;#252;venlik &amp;#231;&amp;#246;z&amp;#252;m&amp;#252; sağlamaktadır.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Kurulum &amp;#8211; Giriş&amp;#160; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;SYSTEM &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;     &lt;br /&gt;Fortigate cihazımız fabrika değeri olarak 192.168.1.99 ip adresi ile set edilmiştir.Cihaza ulaşmak i&amp;#231;in HTTP,HTTPS,TELNET,SSH,SNMP ile erişebilir y&amp;#246;netimini ve ayarlarını yapabiliriz.&amp;#214;ncelikle bilgisayarımızın ip adresini 192.168.1.250 veriyoruz.Web Browser adres kısmına &lt;a href="https://192.168.1.99/"&gt;https://192.168.1.99&lt;/a&gt; yazıyoruz.Sertifika uyarısına devam ederek kullanıcı adi admin password kısmını bos bırakarak cihaza giriyoruz.Karsımıza gelen ana ekran aşağıdaki gibidir.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortiGateTemelKurulumVersiyon3MR_14253/clip_image001.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="319" alt="clip_image001" src="http://cozumpark.com/mklresim/FortinetFortiGateTemelKurulumVersiyon3MR_14253/clip_image001_thumb.jpg" width="604" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Resimde g&amp;#246;r&amp;#252;len cihaz register edilmiş t&amp;#252;m servisleri kullanılan bir cihazdır.Cihazımızı &amp;#246;ncelikle &lt;a href="https://support.fortinet.com/Login/UserRegistration.aspx"&gt;https://support.fortinet.com/Login/UserRegistration.aspx&lt;/a&gt;&amp;#160; linkinden kayıt ediyoruz.Kurulum bitene kadar resimdeki gibi servislerimizin &amp;#252;zerinde yeşil check işreti olacaktır.Register edildikten sonra 15 ile 30 dk arasında servisler aktif olur.Kısaca men&amp;#252;ler hakkında bilgi vermek gerekirse      &lt;br /&gt;Status Ekranı =&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;* Sessionlar &amp;#8211;&amp;#160;&amp;#160; Cihazımız &amp;#252;zerinden gecen networktaki gelen giden tcp, udp paketlerini g&amp;#246;rebiliriz.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;* İstatistik bilgileri &amp;#8211; Saldırılar, vir&amp;#252;sler, spamlar ve yapılan itekleri g&amp;#246;rebiliriz.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;* Lisans Durumu &amp;#8211; Cihazımızın register başlangı&amp;#231; ve bitiş suresini servis durumunu g&amp;#246;rebiliriz.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;* Tarih zaman &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;* Log bilgileri&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;* Komut satiri y&amp;#246;netimi &amp;#8211; Web ara y&amp;#252;z&amp;#252;nden yapamadığımız işlemler i&amp;#231;in kullandığımız alan.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;* Memory ve Cpu durumunu g&amp;#246;rebiliriz. Resimdeki versiyon FORTI OS MR 6 .&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Network Ekranı = Ağ ge&amp;#231;idi ip adresimiz ,Wan bağlantılarımız,Dns ayarımız,vlan trunk oluşturma,Secondary Ip yapılandırma,Y&amp;#246;netim portlari (https,http,telnet vs) Bu kısımdan modemimizi bridge moduna alarak internet bağlantılarımızı sağlarız.Dikkat edilmesi gereken husus Over ride internal dns ve Retrive default gateway from server kutucuklarının dolu olması gerekmektedir.Dışarıdan cihaza bağlanıp y&amp;#246;netim yapılacaksa http,https e izin vermek gerekir.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#214;rnek Resim&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortiGateTemelKurulumVersiyon3MR_14253/clip_image002.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="356" alt="clip_image002" src="http://cozumpark.com/mklresim/FortinetFortiGateTemelKurulumVersiyon3MR_14253/clip_image002_thumb.jpg" width="604" border="0" /&gt;&lt;/a&gt;      &lt;br /&gt;Dhcp sunucu yapılandırma &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Config - Bu bol&amp;#252;mden mesajların i&amp;#231;eriğine m&amp;#252;dahale edebiliriz.Default İngilizcedir.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Admin &amp;#8211; Bu kısımdan admin veya user yaratarak cihaza girişleri kontrol altına alırız.     &lt;br /&gt;Certificates &amp;#8211; Kısmından cihazımızın sertifika &amp;#252;retmesini sağlarız.      &lt;br /&gt;Maintanance kısmından backup,restore ve fortiguard antivirus,AntiSpam ve web category filter servisimizi aktif ederiz.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Router      &lt;br /&gt;Statick ve Policy Route yaptığımız kısım.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#214;rnek Resim&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:12pt;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortiGateTemelKurulumVersiyon3MR_14253/clip_image003.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="304" alt="clip_image003" src="http://cozumpark.com/mklresim/FortinetFortiGateTemelKurulumVersiyon3MR_14253/clip_image003_thumb.jpg" width="471" border="0" /&gt;&lt;/a&gt;      &lt;br /&gt;      &lt;br /&gt;Ben daha &amp;#231;ok Policy &amp;#252;zerinde duracağım.Bu y&amp;#252;zden diğer kısımlar i&amp;#231;in yakin zamanda yeni makaleler hazırlayacağım.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Policy &amp;#8211; Kural     &lt;br /&gt;Sistemimizdeki kullanıcıların hangi haklar ile hangi servise erişeceğine karar verdiğimiz kısımdır.      &lt;br /&gt;Aşağıdaki ekranda g&amp;#246;rebileceğiniz gibi &amp;#231;eşitli senaryolar uygulayabiliriz.      &lt;br /&gt;&amp;#214;rnek : Finansman,Muhasebe,Y&amp;#246;netim guruplarımız var.      &lt;br /&gt;Kullanıcı Hakları Hakkında Bilgi      &lt;br /&gt;&lt;b&gt;&lt;u&gt;Finansman Hakları :&lt;/u&gt;&lt;/b&gt; gov.tr,org.tr,net.tr,edu.tr sitelerde filtre uygulanmayacak. ips,idp koruması sağlanacak.Antivirus (Malware,spyware,grayware) koruması olacak.2 mb &amp;#252;zerindeki dosyaları ftp den ge&amp;#231;ebilirken,mail veya web ara y&amp;#252;z&amp;#252;nden 2 mb &amp;#252;zeri dosyalar engellenecek.Zip,Rar i&amp;#231;in hi&amp;#231; bir kısıtlama engel olmayacak.Web filter uygulanarak istenmeyen siteler engellenecek.Msn den dosya transferi engellenirken P2P Programlarda download engellenecek veya Limit verilecek.Bu kullanıcıların banka ve finans sitelerine erişimlerinde garanti olarak 30 kb hız verilecek,mail vs diğer web sitelerinde 10 kb &amp;#252;zerine &amp;#231;ıkamayacak.Http,https,pop3,SMTP,ntp,im portlari,acık olacak.Diğer t&amp;#252;m portlara erişimi kapatılacak.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Kelime engellenecek &amp;#246;rneğin google&amp;#8217;da &amp;#231;ocuk pornosu gibi.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:12pt;"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Muhasebe Hakları :&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style="font-size:10pt;font-family:;"&gt; gov.tr,org.tr sitelerde filtre uygulanmayacak.Antivirus (Malware,spyware,grayware) koruması olacak.1 mb &amp;#252;zerindeki dosyaları web,ftp,pop3,SMTP den engellenecek. Web filter uygulanarak t&amp;#252;m web siteleri engellenecek.Msn,icq,aol,yahoo gibi IM&amp;#8217;ler engellenirken P2P Programlarda engellenecek.Sadece &amp;#246;ğlen tatilinde 30 dk im,p2p veya izin verilen t&amp;#252;m siteler a&amp;#231;ılacak.ips,idp koruması sağlanacak. Http,https,pop3,SMTP,ntp,im portlari,acık olacak.     &lt;br /&gt;&lt;b&gt;&lt;u&gt;Y&amp;#246;netim Hakları :&lt;/u&gt;&lt;/b&gt; Her turlu siteye erişim olacak.Antivirus koruması sağlanarak Malware,spyware,grayware&amp;#8217;ler engellenecek.Kandırmaca şifre sayfaları engellenecek.IM,P2P acık olacak.IM &amp;#8217; de gelen giden dosyalarda vir&amp;#252;s taraması sağlanacak.Ips,idp koruması sağlanacak.T&amp;#252;m portlar izinli olacak.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortiGateTemelKurulumVersiyon3MR_14253/clip_image004.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="285" alt="clip_image004" src="http://cozumpark.com/mklresim/FortinetFortiGateTemelKurulumVersiyon3MR_14253/clip_image004_thumb.jpg" width="604" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Bu kurallarımız i&amp;#231;erden dışarı &amp;#231;alışacak.Mail serverımız kendi ofisimizde ise y&amp;#226;da terminal server bağlantımız var ise yapılması gerekenler.Dışarıdan i&amp;#231;eri Policy oluşturulmalı.Sabit portlar kullanılmamalı.&amp;#214;rneğin Uzak masa ustu i&amp;#231;in 3389 kullanılır.Bunun yerine dışarıdan 45345 isteklerini i&amp;#231;eriye 3389 olarak al ve Terminal Server&amp;#8217;a y&amp;#246;nlendir demeliyiz.Fortigate firewall da en &amp;#246;nemli yer Protection Profile (Koruma Profili) kısmıdır.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortiGateTemelKurulumVersiyon3MR_14253/clip_image005.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="397" alt="clip_image005" src="http://cozumpark.com/mklresim/FortinetFortiGateTemelKurulumVersiyon3MR_14253/clip_image005_thumb.jpg" width="604" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Aklımıza gelen her turlu kısıtlama bu b&amp;#246;l&amp;#252;mden yapılır.&amp;#214;rneğin proxyleri,web Chat sitelerini,youtube tarzı muti medya download sitelerini,hacking ile ilgili siteleri gibi bir&amp;#231;ok siteyi engelleyebiliriz.Su an d&amp;#252;nya &amp;#252;zerinde 98.000.000 web sitesi bulunmaktadır.Fortinet firması Fortiguard Center&amp;#8217;da 49.000.000 web sitesini kategorize etmiş durumda.Antivirus koruması http,https,ftp,SMTP,pop3,IM,imap,Nntp koruması ve dosya transferi engelleme yapabiliriz.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortiGateTemelKurulumVersiyon3MR_14253/clip_image006.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="278" alt="clip_image006" src="http://cozumpark.com/mklresim/FortinetFortiGateTemelKurulumVersiyon3MR_14253/clip_image006_thumb.jpg" width="604" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Kullanıcıların web,antivirus,ips,idp,fileblock gibi haklarını tamamen bu kısımdan ayarlarız.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Fortigate firewall Ipsec,Ssl,Pptp vpn&amp;#8217;de de vir&amp;#252;s koruması,port engellemesi gibi g&amp;#252;venlik sağlar.Şayet istenirse authentication yapılabilinir.Token cihazlar ile t&amp;#252;mleşik &amp;#231;alışabilir.Aktive directory ile birlikte &amp;#231;alışabilir.     &lt;br /&gt;Gelecek Makale Fortigate &amp;#252;zerinde spam ayarları,dmz mail server kullanmak,dnsbl,rbl,email bwl,ip bwl,banned word konuları hakkında bilgi vereceğim. &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Bir sonraki makalede g&amp;#246;r&amp;#252;şmek dileği ile.&amp;#199;&amp;#246;z&amp;#252;mde &amp;#199;&amp;#246;z&amp;#252;m Bulursunuz.     &lt;br /&gt;Selamlar&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-size:10.0pt;"&gt;     &lt;p&gt;&amp;#160;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;&lt;img src="http://cozumpark.com/aggbug.aspx?PostID=8156" width="1" height="1"&gt;</description><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Draytek/default.aspx">Draytek</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortigate/default.aspx">Fortigate</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortinet+FortiGate+Temel+Kurulum+Versiyon+3+MR6/default.aspx">Fortinet FortiGate Temel Kurulum Versiyon 3 MR6</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Firewall/default.aspx">Firewall</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortinet/default.aspx">Fortinet</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Syslog/default.aspx">Syslog</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+kurulum/default.aspx">draytek kurulum</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/one+to+one+nat/default.aspx">one to one nat</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/foritgate+ssl+vpn/default.aspx">foritgate ssl vpn</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+antispam+fortigate+dnsbl/default.aspx">fortigate antispam fortigate dnsbl</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortigate+Sip+Server/default.aspx">Fortigate Sip Server</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+firewall/default.aspx">fortigate firewall</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+e_1F01_itim/default.aspx">fortigate eğitim</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+temel/default.aspx">draytek temel</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+antispam/default.aspx">fortigate antispam</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+bilgi/default.aspx">draytek bilgi</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+ayarlar/default.aspx">fortigate ayarlar</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+d_31015F01_ardan+eri_5F01_im/default.aspx">fortigate dışardan erişim</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+vpn/default.aspx">draytek vpn</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+utm/default.aspx">fortigate utm</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+temel/default.aspx">fortigate temel</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+makale/default.aspx">fortigate makale</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortianalyzer/default.aspx">fortianalyzer</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+rbl+Command/default.aspx">fortigate rbl Command</category></item><item><title>Fortinet Fortigate Cihazımıza Dışardan Erişim Guvenliği</title><link>http://cozumpark.com/blogs/fortigate/archive/2008/03/30/fortinet-fortigate-cihaz-m-za-d-ardan-eri-im-g-venli-i.aspx</link><pubDate>Sun, 30 Mar 2008 19:48:00 GMT</pubDate><guid isPermaLink="false">36acb80b-3ae7-4dda-bbe8-b4ae2f1fa947:8151</guid><dc:creator>Savas Demir</dc:creator><slash:comments>4</slash:comments><comments>http://cozumpark.com/blogs/fortigate/comments/8151.aspx</comments><wfw:commentRss>http://cozumpark.com/blogs/fortigate/commentrss.aspx?PostID=8151</wfw:commentRss><description>&lt;P class=MsoNormal&gt;Neden ihtiyaç duyarız sorusuna cevap verelim öncelikle.Cihazımızı yapılandırdık.Ağımızda web sunucumuz var,mail sunucumuz var.Dışardan web sunucumuza bağlanmak için 80 (Http) portunu yönlendirerek kullanıyoruz.Mail servera dışarıdan web arayüzünden bağlanıp kullanıcıların maillerinide görmesini istiyoruz.Bunun için de 443 (Https) portunu yönlendirerek çalıştırdık.Peki biz dışarıdan cihazımıza direk nasıl bağlanabiliriz.İşte bu sorunuzun cevabı bu makalede.Resim olarak takip ederseniz çözümün çok basit olduğunu göreceksiniz.&lt;/P&gt;
&lt;P class=MsoNormal&gt;Resim 1&lt;/P&gt;
&lt;P class=MsoNormal&gt;Gördüğünüz gibi resimde http 80 portundan giriş yaptık &lt;BR style="mso-special-character:line-break;"&gt;&lt;BR style="mso-special-character:line-break;"&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;A href="http://cozumpark.com/mklresim/FortinetFortigateCihazmzaDardanEriimGven_140A1/clip_image002.jpg"&gt;&lt;IMG style="BORDER-TOP:0px;BORDER-LEFT:0px;BORDER-BOTTOM:0px;" height=565 alt=clip_image002 src="http://cozumpark.com/mklresim/FortinetFortigateCihazmzaDardanEriimGven_140A1/clip_image002_thumb.jpg" width=604 border=0&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;Resim 2&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;A href="http://cozumpark.com/mklresim/FortinetFortigateCihazmzaDardanEriimGven_140A1/clip_image004.jpg"&gt;&lt;IMG style="BORDER-TOP:0px;BORDER-LEFT:0px;BORDER-BOTTOM:0px;" height=172 alt=clip_image004 src="http://cozumpark.com/mklresim/FortinetFortigateCihazmzaDardanEriimGven_140A1/clip_image004_thumb.jpg" width=604 border=0&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;Resim 3 &lt;BR style="mso-special-character:line-break;"&gt;&lt;BR style="mso-special-character:line-break;"&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;İstersek cihazımıza sadece belli ip lerin bağlanmasına izin veririz.Aşağıdaki resim örneği Bu arada 44443 nolu port ile cihazımıza bağlandık.&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;A href="http://cozumpark.com/mklresim/FortinetFortigateCihazmzaDardanEriimGven_140A1/clip_image006.jpg"&gt;&lt;IMG style="BORDER-TOP:0px;BORDER-LEFT:0px;BORDER-BOTTOM:0px;" height=229 alt=clip_image006 src="http://cozumpark.com/mklresim/FortinetFortigateCihazmzaDardanEriimGven_140A1/clip_image006_thumb.jpg" width=604 border=0&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN&gt;Bir sonraki makalede görüşmek dileği ile. Çözümde Çözüm Bulursunuz&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;BR&gt;Selamlar&lt;/P&gt;&lt;img src="http://cozumpark.com/aggbug.aspx?PostID=8151" width="1" height="1"&gt;</description><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Draytek/default.aspx">Draytek</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortigate/default.aspx">Fortigate</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortinet+Fortigate+Cihaz_3101_m_3101_za+D_31015F01_ardan+Eri_5F01_im+G_26002300_252_3B00_venli_1F01_i+Port+Tan_3101_mlama+Port+Access/default.aspx">Fortinet Fortigate Cihazımıza Dışardan Erişim G&amp;#252;venliği Port Tanımlama Port Access</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Firewall/default.aspx">Firewall</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortinet/default.aspx">Fortinet</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Syslog/default.aspx">Syslog</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+kurulum/default.aspx">draytek kurulum</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/one+to+one+nat/default.aspx">one to one nat</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/foritgate+ssl+vpn/default.aspx">foritgate ssl vpn</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+antispam+fortigate+dnsbl/default.aspx">fortigate antispam fortigate dnsbl</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortigate+Sip+Server/default.aspx">Fortigate Sip Server</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+firewall/default.aspx">fortigate firewall</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+e_1F01_itim/default.aspx">fortigate eğitim</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+temel/default.aspx">draytek temel</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+antispam/default.aspx">fortigate antispam</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+bilgi/default.aspx">draytek bilgi</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+ayarlar/default.aspx">fortigate ayarlar</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+d_31015F01_ardan+eri_5F01_im/default.aspx">fortigate dışardan erişim</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+vpn/default.aspx">draytek vpn</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+utm/default.aspx">fortigate utm</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+temel/default.aspx">fortigate temel</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+makale/default.aspx">fortigate makale</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortianalyzer/default.aspx">fortianalyzer</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+rbl+Command/default.aspx">fortigate rbl Command</category></item><item><title>Fortinet Fortigate ile SSL VPN Nasıl Yapılır</title><link>http://cozumpark.com/blogs/fortigate/archive/2008/03/30/fortinet-fortigate-ile-ssl-vpn-nas-l-yap-l-r.aspx</link><pubDate>Sun, 30 Mar 2008 19:16:40 GMT</pubDate><guid isPermaLink="false">36acb80b-3ae7-4dda-bbe8-b4ae2f1fa947:8136</guid><dc:creator>Savas Demir</dc:creator><slash:comments>4</slash:comments><comments>http://cozumpark.com/blogs/fortigate/comments/8136.aspx</comments><wfw:commentRss>http://cozumpark.com/blogs/fortigate/commentrss.aspx?PostID=8136</wfw:commentRss><description>&lt;p&gt;&lt;span style="font-size:10pt;font-family:;"&gt;     &lt;br /&gt;&amp;#214;ncelikle ssl vpn&amp;#8217;e neden ihtiya&amp;#231; duyulur bunu anlatalım. Kurumlar eğer ipsec vpn mimarisi kullanamıyor ise genelde Mobil kullanıcılar i&amp;#231;in Ssl vpn &amp;#231;&amp;#246;z&amp;#252;m&amp;#252;ne gider. Fortigate Firewall SSL VPN Yapılandırılması (Fortigate Firewall SSL VPN Configuration)&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Makalemizde uygulayacak olduğumuz SSL VPN uygulaması daha &amp;#246;nce yayınlamış olduğumuz PPTP VPN bağlantısına nazaran daha g&amp;#252;venli olmasının yanında, uygulamalarımızda yaşayacak olduğumuz yavaşlıkla eşdeğer boyuttadır.     &lt;br /&gt;PPTP VPN ile SSL VPN arasında ki tek farkımız hız ve g&amp;#252;venlik olup, şirketimizde uygulayacak olduğumuz uygulamalar ve g&amp;#252;venlik anlayışınıza, uygulamalarınıza ve ihtiyacınıza g&amp;#246;re sizlere bırakılacaktır.&lt;/span&gt;&lt;/p&gt;  &lt;p style="text-align:justify;"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Fortigate SSL VPN uygulaması, internet &amp;#252;zerinden şirketimiz i&amp;#231;erisinde bulunan serverlarımıza, web tarayıcımız &amp;#252;zerinden giden &amp;#8211; gelen verileri şifreleyerek, g&amp;#252;venli bir şekilde bağlanmamızı sağlayan bir uygulamadır. Fortigate Firewall&amp;#8217;ımız; SSL uygulamalarında diğer yazılımsal veya Donanımsal firewalllara nazaran &lt;strong&gt;&lt;span style="font-family:;"&gt;Dial-up connectons&amp;#8217;da yapılan şifreleme metodunu uygulamayıp,&lt;/span&gt;&lt;/strong&gt;      &lt;br /&gt;&lt;strong&gt;&lt;span style="font-family:;"&gt;internet tabanlı şifreleme metodunu kullanmaktadır. Fortigate SSL VPN &lt;/span&gt;&lt;/strong&gt;uygulamaların da dial-up bağlantısı oluşturulmadığı i&amp;#231;in bire bir bağlantıyı kuran kullanıcı ile bağlantıyı kurulan network arasında iletişim sağlanmamaktadır.&lt;b&gt;       &lt;br /&gt;&lt;/b&gt;Sadece ama sadece FORTIOS işletim sistemi i&amp;#231;erisinde bulunan web tabanlı uygulamalar ile iletişim ger&amp;#231;ekleştirilecektir. İzin verilen uygulamalar;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left:36pt;"&gt;&lt;strong&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Http / Https&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:10pt;font-family:;"&gt; &lt;strong&gt;&lt;span style="font-family:;"&gt;Telnet Rdp Ftp &lt;/span&gt;&lt;/strong&gt;b &lt;strong&gt;&lt;span style="font-family:;"&gt;Vnc &lt;/span&gt;&lt;/strong&gt;bağlantıları&amp;#8217; dır.&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Yukarıda bahsetmiş olduğumuz uygulamaları, kullanıcılarımızın kullanabilmeleri i&amp;#231;in&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left:36pt;"&gt;&lt;strong&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Internet Explorer Netscape&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:10pt;font-family:;"&gt; &lt;strong&gt;&lt;span style="font-family:;"&gt;Mozilla/Firefox &lt;/span&gt;&lt;/strong&gt;web browserları olmak zorundadır.&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Diğer ihtiya&amp;#231; duyulan yazılım ise Sun Java uygulama programıdır. Eğer kullanıcımızın bilgisayarında ihtiya&amp;#231; duyulan JAVA programı yok ise, bilgisayarına y&amp;#252;kleyebilmesi i&amp;#231;in gerekli siteye otomatik olarak y&amp;#246;nlendirilecektir.&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Temel bilgileri verdikten sonra yapılandırmamıza başlamak &amp;#252;zere &lt;strong&gt;&lt;span style="font-family:;"&gt;WEB&lt;/span&gt;&lt;/strong&gt;      &lt;br /&gt;&lt;strong&gt;&lt;span style="font-family:;"&gt;CONFIG \ Vpn \ SSL \ SSL-VPN&lt;/span&gt;&lt;/strong&gt; Settings b&amp;#246;l&amp;#252;m&amp;#252;ne gelip;      &lt;br /&gt;      &lt;br /&gt;Resim 1&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-size:10pt;font-family:;"&gt;     &lt;br /&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateileSSLVPNNaslYaplr_1391D/clip_image001.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="377" alt="clip_image001" src="http://cozumpark.com/mklresim/FortinetFortigateileSSLVPNNaslYaplr_1391D/clip_image001_thumb.jpg" width="604" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="text-align:justify;"&gt;&lt;strong&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Enable SSL VPN&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:10pt;font-family:;"&gt; kutusunu dolduruyoruz.&lt;/span&gt;&lt;/p&gt;  &lt;p style="text-align:justify;"&gt;&lt;strong&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Login Port&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:10pt;font-family:;"&gt; varsayılan olarak &lt;strong&gt;&lt;span style="font-family:;"&gt;10443&lt;/span&gt;&lt;/strong&gt; olup isteğe bağlı olarak erişim portunu değiştirebilmekteyiz.&lt;/span&gt;&lt;/p&gt;  &lt;p style="text-align:justify;"&gt;&lt;strong&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Tunnel IP Range &lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:10pt;font-family:;"&gt;b&amp;#246;l&amp;#252;m&amp;#252;nde SSL VPN Clientlar i&amp;#231;in bağlantıları sağlanacak olan IP t&amp;#252;nelini belirliyoruz.&lt;/span&gt;&lt;/p&gt;  &lt;p style="text-align:justify;"&gt;&lt;strong&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Require Client Certficate&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:10pt;font-family:;"&gt; b&amp;#246;l&amp;#252;m&amp;#252;n&amp;#252; aktif hale getirirsek bağlantıyı sağlayan client bilgisayarlardan, Forigate firewallımıza tanımlamış olduğumuz sertifikaların isteneceğini şart koşuyoruz. Eğer client tarafında bu sertifika olmazsa bağlantı ger&amp;#231;ekleşmeyecektir.&lt;/span&gt;&lt;/p&gt;  &lt;p style="text-align:justify;"&gt;&lt;strong&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Encryption Key Algorithm&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:10pt;font-family:;"&gt; b&amp;#246;l&amp;#252;m&amp;#252;nde ise fortigate firewall ile bağlantıyı ger&amp;#231;ekleştiren SSL VPN client arasında ki g&amp;#252;venlik seviyesini belirliyoruz&lt;/span&gt;&lt;/p&gt;  &lt;p style="text-align:justify;"&gt;&lt;strong&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Idle Timeout&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:10pt;font-family:;"&gt; b&amp;#246;l&amp;#252;m&amp;#252; de ise bağlantıyı ger&amp;#231;ekleştiren SSL VPN Client herhangi bir işlem yapmadığı zaman, bağlantının boşta kalma s&amp;#252;resini tayin ediyoruz. Belirttiğimiz s&amp;#252;re sonunda kullanıcımız bir işlem yapmazsa bağlantı tekrardan kimlik bilgilerimizi doğrulatana kadar sağlanmayacaktır.&lt;/span&gt;&lt;/p&gt;  &lt;p style="text-align:justify;"&gt;&lt;strong&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Portal Message&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:10pt;font-family:;"&gt; b&amp;#246;l&amp;#252;m&amp;#252;nde ise bağlantıyı ger&amp;#231;ekleştiren SSL VPN Client kullanıcılarımıza iletilecek mesajı yazıyoruz.&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-size:10pt;font-family:;"&gt;SSL VPN ayarlarımızı yapılandırıp, bağlantıyı ger&amp;#231;ekleştirmek i&amp;#231;in firewallımızı ayarladıktan sonra diğer yapılandırma işlemlerimize devam edebiliriz.     &lt;br /&gt;      &lt;br /&gt;Resim 2&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateileSSLVPNNaslYaplr_1391D/clip_image002.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="244" alt="clip_image002" src="http://cozumpark.com/mklresim/FortinetFortigateileSSLVPNNaslYaplr_1391D/clip_image002_thumb.jpg" width="604" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Resim 3&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateileSSLVPNNaslYaplr_1391D/clip_image003.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="226" alt="clip_image003" src="http://cozumpark.com/mklresim/FortinetFortigateileSSLVPNNaslYaplr_1391D/clip_image003_thumb.jpg" width="604" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Resim 4&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Yaptığımız ssl vpn ayarlarını policy ile ilişkilendiriyoruz.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateileSSLVPNNaslYaplr_1391D/clip_image004.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="190" alt="clip_image004" src="http://cozumpark.com/mklresim/FortinetFortigateileSSLVPNNaslYaplr_1391D/clip_image004_thumb.jpg" width="604" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Resim 5     &lt;br /&gt;Policy id 8&amp;#8217;i inceliyoruz.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateileSSLVPNNaslYaplr_1391D/clip_image005.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="394" alt="clip_image005" src="http://cozumpark.com/mklresim/FortinetFortigateileSSLVPNNaslYaplr_1391D/clip_image005_thumb.jpg" width="604" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Resim 6&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;SSL VPN hazır. Şimdi ip adresimize bağlanacağız.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Web Gezginimizde adres kısmına&amp;#160; &lt;a href="https://ipadresimiz:10443/"&gt;https://ipadresimiz:10443&lt;/a&gt; yazıyoruz.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateileSSLVPNNaslYaplr_1391D/clip_image006.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="332" alt="clip_image006" src="http://cozumpark.com/mklresim/FortinetFortigateileSSLVPNNaslYaplr_1391D/clip_image006_thumb.jpg" width="604" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Fortios Version 3.xx Mr 5 ile SSL VPN&amp;#8217;de sanki kendimiz o networkteymiş gibi &amp;#231;alışabiliriz. Bunun i&amp;#231;in &lt;span style="color:red;"&gt;activate ssl vpn tunnel mode &lt;/span&gt;dememiz yeterli      &lt;br /&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateileSSLVPNNaslYaplr_1391D/clip_image007.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="328" alt="clip_image007" src="http://cozumpark.com/mklresim/FortinetFortigateileSSLVPNNaslYaplr_1391D/clip_image007_thumb.jpg" width="604" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;G&amp;#246;rd&amp;#252;ğ&amp;#252;n&amp;#252;z gibi ssl vpn ile merkez ipimize bağlandık ve sistemde gibi &amp;#231;alışıyoruz.     &lt;br /&gt;P&amp;#252;f nokta ilgili policy ye mutlaka protection profile atanmalıdır.      &lt;br /&gt;Fatih Karalialioğlu arkadaşımızın yazılarını kısmen de olsa aldım. Kendisine canı g&amp;#246;n&amp;#252;lden teşekk&amp;#252;r&amp;#252; bir bor&amp;#231; bilirim.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10pt;font-family:;"&gt;Bir sonraki makalede g&amp;#246;r&amp;#252;şmek dileği ile. &amp;#199;&amp;#246;z&amp;#252;mde &amp;#199;&amp;#246;z&amp;#252;m Bulursunuz.     &lt;br /&gt;Selamlar&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-size:10.0pt;"&gt;     &lt;p&gt;&amp;#160;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;&lt;img src="http://cozumpark.com/aggbug.aspx?PostID=8136" width="1" height="1"&gt;</description><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Draytek/default.aspx">Draytek</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortigate/default.aspx">Fortigate</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortinet+Fortigate+ile+SSL+VPN+Nas_3101_l+Yap_3101_l_3101_r+Vpn+G_26002300_252_3B00_venli_1F01_i+Ssl+Makale/default.aspx">Fortinet Fortigate ile SSL VPN Nasıl Yapılır Vpn G&amp;#252;venliği Ssl Makale</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Firewall/default.aspx">Firewall</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortinet/default.aspx">Fortinet</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Syslog/default.aspx">Syslog</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+kurulum/default.aspx">draytek kurulum</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/one+to+one+nat/default.aspx">one to one nat</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/foritgate+ssl+vpn/default.aspx">foritgate ssl vpn</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+antispam+fortigate+dnsbl/default.aspx">fortigate antispam fortigate dnsbl</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortigate+Sip+Server/default.aspx">Fortigate Sip Server</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+firewall/default.aspx">fortigate firewall</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+e_1F01_itim/default.aspx">fortigate eğitim</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+temel/default.aspx">draytek temel</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+antispam/default.aspx">fortigate antispam</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+bilgi/default.aspx">draytek bilgi</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+ayarlar/default.aspx">fortigate ayarlar</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+d_31015F01_ardan+eri_5F01_im/default.aspx">fortigate dışardan erişim</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+vpn/default.aspx">draytek vpn</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+utm/default.aspx">fortigate utm</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+temel/default.aspx">fortigate temel</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+makale/default.aspx">fortigate makale</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortianalyzer/default.aspx">fortianalyzer</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+rbl+Command/default.aspx">fortigate rbl Command</category></item><item><title>Fortinet Fortigate İle One to One Nat Nasıl Yapılır</title><link>http://cozumpark.com/blogs/fortigate/archive/2008/03/30/fortinet-fortigate-le-one-to-one-nat-nas-l-yap-l-r.aspx</link><pubDate>Sun, 30 Mar 2008 19:13:42 GMT</pubDate><guid isPermaLink="false">36acb80b-3ae7-4dda-bbe8-b4ae2f1fa947:8135</guid><dc:creator>Savas Demir</dc:creator><slash:comments>5</slash:comments><comments>http://cozumpark.com/blogs/fortigate/comments/8135.aspx</comments><wfw:commentRss>http://cozumpark.com/blogs/fortigate/commentrss.aspx?PostID=8135</wfw:commentRss><description>&lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Merhaba &amp;#246;ncelikle one to one nata neden ihtiya&amp;#231; duyulur sorusuna cevap verelim.1. olarak reel ip kullan b&amp;#252;y&amp;#252;k networkler kullanıcıların tek ip &amp;#252;zerinden &amp;#231;ıkmasını istemez. Dolayısı ile b&amp;#252;y&amp;#252;k bir ip bloğunu rezerve ederler. B&amp;#246;ylelikle kullanıcılara atanan ip ile ilgili sorumluluk tamamen kullanıcıya ait olacaktır. Raporlama yapmak ile uğraşmayacaksanız bir ip bloğuna sahip olmanız gerekmekte.2. olarak k&amp;#252;&amp;#231;&amp;#252;k bir networkumuz var ama bir ka&amp;#231; adet ip adresimiz bulunmakta. Mail server i&amp;#231;in farklı bir ip web sunucumuz i&amp;#231;in farklı bir ip i&amp;#231;eride internet kullanan kullanıcılarımız i&amp;#231;in ise farklı bir ip kullanmak istiyoruz. Bu Sebenlerden dolayı one to one Nat ihtiya&amp;#231; duyarız.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Ben Fortinet Fortigate Firewall Tarafında yapılması gereken işlemleri anlatacağım.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;#160;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;#214;rnek Resim 1   &lt;br /&gt;G&amp;#246;rm&amp;#252;ş olduğunuz resimde wan1 tarafında 128 adet ip ellerinde bulunmakta    &lt;br /&gt;    &lt;br /&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateleOnetoOneNatNaslYaplr_1387B/clip_image001.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="141" alt="clip_image001" src="http://cozumpark.com/mklresim/FortinetFortigateleOnetoOneNatNaslYaplr_1387B/clip_image001_thumb.jpg" width="604" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;#160;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;#214;rnek Resim 2&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;#160;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateleOnetoOneNatNaslYaplr_1387B/clip_image002.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="193" alt="clip_image002" src="http://cozumpark.com/mklresim/FortinetFortigateleOnetoOneNatNaslYaplr_1387B/clip_image002_thumb.jpg" width="604" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;#160;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;#214;rnek Resim 3   &lt;br /&gt;Bu resimde one to one nasıl yapılır onu g&amp;#246;receğiz. Aslında yukarıdaki resimde mevcut ama i&amp;#231;eriğini g&amp;#246;rmek a&amp;#231;ısından bunu g&amp;#246;ndermek istedim. Bu one to one nat'ta sadece 25 (smtp) isteklerini mail servera y&amp;#246;nlendiriyoruz.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Şayet t&amp;#252;m trafiği y&amp;#246;nlendireceksek Port Forwarding işaretini kaldırınız. Bu şekilde mevcut ip yerine rezerve olan bir ip yi mil serverımıza kullandıracağız.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateleOnetoOneNatNaslYaplr_1387B/clip_image003.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="307" alt="clip_image003" src="http://cozumpark.com/mklresim/FortinetFortigateleOnetoOneNatNaslYaplr_1387B/clip_image003_thumb.jpg" width="604" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;#160;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;#160;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Bu kısımdan sonra yapılması gereken bu işlemi bir policy ile ilişkilendirmek.   &lt;br /&gt;    &lt;br /&gt;&amp;#214;rnek Resim 4&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;#160;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateleOnetoOneNatNaslYaplr_1387B/clip_image004.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="217" alt="clip_image004" src="http://cozumpark.com/mklresim/FortinetFortigateleOnetoOneNatNaslYaplr_1387B/clip_image004_thumb.jpg" width="604" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;#160;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;#214;rnek Resim 5&lt;/p&gt;  &lt;p class="MsoNormal"&gt;   &lt;br /&gt;Dışarıdan i&amp;#231;eri Natımızı yaptık. Şimdi bilgisayarımıza bu nat ipsini nasıl vereceğiz. Onu resimde inceleyelim&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a href="http://cozumpark.com/mklresim/FortinetFortigateleOnetoOneNatNaslYaplr_1387B/clip_image005.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="437" alt="clip_image005" src="http://cozumpark.com/mklresim/FortinetFortigateleOnetoOneNatNaslYaplr_1387B/clip_image005_thumb.jpg" width="604" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&amp;#160;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Bu şekilde mail serverımız dışarıdan erişim ip adresi ile i&amp;#231;erden dışarı olan ip adresi aynı ip olacaktır. Bu da bizim&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:12pt;"&gt;Spam listelerine girmemize engel olacaktır.   &lt;br /&gt;Bir sonraki makalede g&amp;#246;r&amp;#252;şmek dileği ile. &amp;#199;&amp;#246;z&amp;#252;mde &amp;#199;&amp;#246;z&amp;#252;m Bulursunuz.    &lt;br /&gt;Selamlar&lt;/p&gt;&lt;img src="http://cozumpark.com/aggbug.aspx?PostID=8135" width="1" height="1"&gt;</description><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Draytek/default.aspx">Draytek</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortigate/default.aspx">Fortigate</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortinet+Fortigate+_3001_le+One+to+One+Nat+Nas_3101_l+Yap_3101_l_3101_r/default.aspx">Fortinet Fortigate İle One to One Nat Nasıl Yapılır</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Firewall/default.aspx">Firewall</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortinet/default.aspx">Fortinet</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Syslog/default.aspx">Syslog</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+kurulum/default.aspx">draytek kurulum</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/one+to+one+nat/default.aspx">one to one nat</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/foritgate+ssl+vpn/default.aspx">foritgate ssl vpn</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+antispam+fortigate+dnsbl/default.aspx">fortigate antispam fortigate dnsbl</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/Fortigate+Sip+Server/default.aspx">Fortigate Sip Server</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+firewall/default.aspx">fortigate firewall</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+e_1F01_itim/default.aspx">fortigate eğitim</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+temel/default.aspx">draytek temel</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+antispam/default.aspx">fortigate antispam</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+bilgi/default.aspx">draytek bilgi</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+ayarlar/default.aspx">fortigate ayarlar</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+d_31015F01_ardan+eri_5F01_im/default.aspx">fortigate dışardan erişim</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/draytek+vpn/default.aspx">draytek vpn</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+utm/default.aspx">fortigate utm</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+temel/default.aspx">fortigate temel</category><category domain="http://cozumpark.com/blogs/fortigate/archive/tags/fortigate+makale/default.aspx">fortigate makale</categ