TechclickTechclick Simulator All labs

FortiGate configure a firewall policy

The FortiGate lab is a FortiOS 7.4 style CLI. Firewall policy is a table. You enter it with config firewall policy, pick a row with edit, set the fields, store the row with next, and leave with end. The example on the lab page edits policy 2, sets srcintf port1, dstintf port2, and action deny.

Before you add the policy, read what is already there with show firewall policy. get system status confirms you are on the practice FortiOS 7.4 prompt. Interface address changes use config system interface, and a static route uses config router static. Those three trees are the config work this shell actually accepts.

This lab does not configure IPsec or SSL VPN. There is no phase1 or phase2 command. If the task you wanted was a tunnel, use this page for the policy path the simulator can run, and keep VPN practice on a real lab or the topology builder's Palo Alto site-to-site scenario. Nothing here reaches a FortiGate appliance.

Open the FortiGate CLI lab Simulator home

Do it in the lab

  1. Open the FortiGate lab in guest mode.
  2. show firewall policy
  3. config firewall policy, then edit 2
  4. set srcintf port1, set dstintf port2, set action deny, then next and end
  5. show firewall policy again and confirm policy 2.