120
Connected NCT # show full-configuration #config-version=FG200A-4.00-FW-build178-090820:opmode=0:vdom=0 #conf_file_ver=10491300511546348673 #buildno=0178 config system global set access-banner disable set admin-https-pki-required disable set admin-lockout-duration 60 set admin-lockout-threshold 3 set admin-maintainer enable set admin-port 80 set admin-scp disable set admin-server-cert "self-sign" set admin-sport 443 set admin-ssh-port 22 set admin-ssh-v1 disable set admin-telnet-port 23 set admintimeout 5 set anti-replay strict set auth-cert "self-sign" set auth-http-port 1000 set auth-https-port 1003 set auth-keepalive disable set auth-policy-exact-match enable set av-failopen pass set av-failopen-session disable set batch-cmdb enable set cfg-save automatic --More-- set check-protocol-header loose --More-- set check-reset-range disable --More-- set clt-cert-req disable --More-- set daily-restart disable --More-- set detection-summary enable --More-- set dst disable --More-- set endpoint-control-portal-port 8009 --More-- set failtime 5 --More-- set fds-statistics enable --More-- set fsae-burst-size 300 --More-- set fsae-rate-limit 100 --More-- set gui-ipv6 disable --More-- set gui-lines-per-page 50 --More-- set hostname "NCT" --More-- set http-obfuscate modified --More-- set ie6workaround disable --More-- set internal-switch-mode switch --More-- unset internal-switch-speed --More-- set interval 5 --More-- set ip-src-port-range 1024-25000

N_ FortiGate 200a Configuration.txt

Embed Size (px)

DESCRIPTION

Narjan Listing

Citation preview

Page 1: N_ FortiGate 200a Configuration.txt

Connected NCT # show full-configuration#config-version=FG200A-4.00-FW-build178-090820:opmode=0:vdom=0#conf_file_ver=10491300511546348673#buildno=0178config system global set access-banner disable set admin-https-pki-required disable set admin-lockout-duration 60 set admin-lockout-threshold 3 set admin-maintainer enable set admin-port 80 set admin-scp disable set admin-server-cert "self-sign" set admin-sport 443 set admin-ssh-port 22 set admin-ssh-v1 disable set admin-telnet-port 23 set admintimeout 5 set anti-replay strict set auth-cert "self-sign" set auth-http-port 1000 set auth-https-port 1003 set auth-keepalive disable set auth-policy-exact-match enable set av-failopen pass set av-failopen-session disable set batch-cmdb enable set cfg-save automatic--More-- set check-protocol-header loose--More-- set check-reset-range disable--More-- set clt-cert-req disable--More-- set daily-restart disable--More-- set detection-summary enable--More-- set dst disable--More-- set endpoint-control-portal-port 8009--More-- set failtime 5--More-- set fds-statistics enable--More-- set fsae-burst-size 300--More-- set fsae-rate-limit 100--More-- set gui-ipv6 disable--More-- set gui-lines-per-page 50--More-- set hostname "NCT"--More-- set http-obfuscate modified--More-- set ie6workaround disable--More-- set internal-switch-mode switch--More-- unset internal-switch-speed--More-- set interval 5--More-- set ip-src-port-range 1024-25000--More-- set language english--More-- set lcdpin ENC XXVrg9a1cu6os--More-- set lcdprotection disable--More-- set ldapconntimeout 500--More-- set log-user-in-upper disable--More-- set loglocaldeny disable--More-- set management-vdom "root"--More-- set phase1-rekey enable--More-- set radius-port 1812--More-- set refresh 0

Page 2: N_ FortiGate 200a Configuration.txt

--More-- set registration-notification enable--More-- set remoteauthtimeout 5--More-- set reset-sessionless-tcp disable--More-- set send-pmtu-icmp enable--More-- set service-expire-notification enable--More-- set sslvpn-sport 10443--More-- set strong-crypto disable--More-- set tcp-halfclose-timer 120--More-- set tcp-halfopen-timer 60--More-- set tcp-option enable--More-- set tcp-timewait-timer 120--More-- set timezone 04--More-- set tos-based-priority high--More-- set udp-idle-timer 180--More-- set user-server-cert "self-sign"--More-- set vdom-admin disable--More-- set vip-arp-range restricted--More-- set wireless-controller enable--More-- set wireless-controller-port 5246--More-- set fds-statistics-period 60--More-- end--More-- config system accprofile--More-- edit "prof_admin"--More-- set admingrp read-write--More-- set authgrp read-write--More-- set endpoint-control-grp read-write--More-- set fwgrp read-write--More-- set loggrp read-write--More-- unset menu-file--More-- set mntgrp read-write--More-- set netgrp read-write--More-- unset roles--More-- set routegrp read-write--More-- set sysgrp read-write--More-- set updategrp read-write--More-- set utmgrp read-write--More-- set vpngrp read-write--More-- next--More-- end--More-- config system interface--More-- edit "wan1"--More-- set vdom "root"--More-- set mode dhcp--More-- set distance 5--More-- set priority 0--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- unset ip--More-- set allowaccess ping https http--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable

Page 3: N_ FortiGate 200a Configuration.txt

--More-- set stpforward disable--More-- set ips-sniffer-mode disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type physical--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias "NCT"--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set dhcp-client-identifier ''--More-- set idle-timeout 0--More-- set defaultgw enable--More-- set dns-server-override enable--More-- unset macaddr--More-- set speed auto--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy disable--More-- next--More-- edit "wan2"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 0.0.0.0 0.0.0.0--More-- set allowaccess ping--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable

Page 4: N_ FortiGate 200a Configuration.txt

--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable--More-- set ips-sniffer-mode disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type physical--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- unset macaddr--More-- set speed auto--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy disable--More-- next--More-- edit "dmz1"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.10.10.1 255.255.255.0--More-- set allowaccess ping https--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable

Page 5: N_ FortiGate 200a Configuration.txt

--More-- set vlanforward enable--More-- set stpforward disable--More-- set ips-sniffer-mode disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type physical--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- unset macaddr--More-- set speed auto--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy disable--More-- next--More-- edit "dmz2"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 0.0.0.0 0.0.0.0--More-- set allowaccess ping--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable

Page 6: N_ FortiGate 200a Configuration.txt

--More-- set stpforward disable--More-- set ips-sniffer-mode disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type physical--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- unset macaddr--More-- set speed auto--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy disable--More-- next--More-- edit "internal"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.232.3.100 255.255.255.0--More-- set allowaccess ping https http telnet--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable

Page 7: N_ FortiGate 200a Configuration.txt

--More-- set ips-sniffer-mode disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type physical--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- unset macaddr--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy enable--More-- next--More-- edit "modem"--More-- set vdom "root"--More-- unset allowaccess--More-- set dns-query disable--More-- set ips-sniffer-mode disable--More-- set fdp disable--More-- set ddns disable--More-- set spillover-threshold 0--More-- next--More-- edit "ssl.root"--More-- set vdom "root"--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 0.0.0.0 0.0.0.0--More-- unset allowaccess--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable

Page 8: N_ FortiGate 200a Configuration.txt

--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type tunnel--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- set mtu 1500--More-- set explicit-web-proxy disable--More-- next--More-- edit "VLAN_2"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.232.2.100 255.255.255.0--More-- set allowaccess ping https http telnet--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable

Page 9: N_ FortiGate 200a Configuration.txt

--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type vlan--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy enable--More-- set interface "internal"--More-- set vlanid 2--More-- next--More-- edit "VLAN_4"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.232.4.100 255.255.255.0--More-- set allowaccess ping https http telnet--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable--More-- set ident-accept disable--More-- set ipmac disable

Page 10: N_ FortiGate 200a Configuration.txt

--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type vlan--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy enable--More-- set interface "internal"--More-- set vlanid 4--More-- next--More-- edit "VLAN_5"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.232.5.100 255.255.255.0--More-- set allowaccess ping https http telnet--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable

Page 11: N_ FortiGate 200a Configuration.txt

--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type vlan--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy enable--More-- set interface "internal"--More-- set vlanid 5--More-- next--More-- edit "VLAN_6"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.232.6.100 255.255.255.0--More-- set allowaccess ping https http telnet--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable

Page 12: N_ FortiGate 200a Configuration.txt

--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type vlan--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy enable--More-- set interface "internal"--More-- set vlanid 6--More-- next--More-- edit "VLAN_7"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.232.7.100 255.255.255.0--More-- set allowaccess ping https http telnet--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable

Page 13: N_ FortiGate 200a Configuration.txt

--More-- set wins-ip 0.0.0.0--More-- set type vlan--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy enable--More-- set interface "internal"--More-- set vlanid 7--More-- next--More-- edit "VLAN_8"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.232.8.100 255.255.255.0--More-- set allowaccess ping https http telnet--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type vlan

Page 14: N_ FortiGate 200a Configuration.txt

--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy enable--More-- set interface "internal"--More-- set vlanid 8--More-- next--More-- edit "VLAN_9"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.232.9.100 255.255.255.0--More-- set allowaccess ping https http telnet--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type vlan--More-- set tcp-mss 0--More-- set inbandwidth 0

Page 15: N_ FortiGate 200a Configuration.txt

--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy enable--More-- set interface "internal"--More-- set vlanid 9--More-- next--More-- edit "VLAN_10"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.232.10.100 255.255.255.0--More-- set allowaccess ping https http telnet--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type vlan--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0

Page 16: N_ FortiGate 200a Configuration.txt

--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy enable--More-- set interface "internal"--More-- set vlanid 10--More-- next--More-- edit "VLAN_11"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.232.11.100 255.255.255.0--More-- set allowaccess ping https http telnet--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type vlan--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''

Page 17: N_ FortiGate 200a Configuration.txt

--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy enable--More-- set interface "internal"--More-- set vlanid 11--More-- next--More-- edit "VLAN_12"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.232.12.100 255.255.255.0--More-- set allowaccess ping https http telnet--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type vlan--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable

Page 18: N_ FortiGate 200a Configuration.txt

--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy enable--More-- set interface "internal"--More-- set vlanid 12--More-- next--More-- edit "VLAN_13"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.232.13.100 255.255.255.0--More-- set allowaccess ping https http telnet--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type vlan--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess

Page 19: N_ FortiGate 200a Configuration.txt

--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy enable--More-- set interface "internal"--More-- set vlanid 13--More-- next--More-- edit "VLAN_14"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.232.14.100 255.255.255.0--More-- set allowaccess ping https http telnet--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type vlan--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0

Page 20: N_ FortiGate 200a Configuration.txt

--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy enable--More-- set interface "internal"--More-- set vlanid 14--More-- next--More-- edit "VLAN_15"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.232.15.100 255.255.255.0--More-- set allowaccess ping https http telnet--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type vlan--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable

Page 21: N_ FortiGate 200a Configuration.txt

--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy enable--More-- set interface "internal"--More-- set vlanid 15--More-- next--More-- edit "VLAN_16"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.232.16.100 255.255.255.0--More-- set allowaccess ping https http telnet--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type vlan--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198

Page 22: N_ FortiGate 200a Configuration.txt

--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy enable--More-- set interface "internal"--More-- set vlanid 16--More-- next--More-- edit "VLAN_17"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.232.17.100 255.255.255.0--More-- set allowaccess ping https http telnet--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type vlan--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0

Page 23: N_ FortiGate 200a Configuration.txt

--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy enable--More-- set interface "internal"--More-- set vlanid 17--More-- next--More-- edit "VLAN_18"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.232.18.100 255.255.255.0--More-- set allowaccess ping https http telnet--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type vlan--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable

Page 24: N_ FortiGate 200a Configuration.txt

--More-- end--More-- set idle-timeout 0--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy enable--More-- set interface "internal"--More-- set vlanid 18--More-- next--More-- edit "VLAN_19"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.232.19.100 255.255.255.0--More-- set allowaccess ping https http telnet--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type vlan--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0

Page 25: N_ FortiGate 200a Configuration.txt

--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy enable--More-- set interface "internal"--More-- set vlanid 19--More-- next--More-- edit "VLAN_20"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.232.20.100 255.255.255.0--More-- set allowaccess ping https http telnet--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type vlan--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- set mtu-override disable--More-- set wccp disable

Page 26: N_ FortiGate 200a Configuration.txt

--More-- set explicit-web-proxy enable--More-- set interface "internal"--More-- set vlanid 20--More-- next--More-- edit "ALL_VLANS"--More-- set vdom "root"--More-- set mode static--More-- set dhcp-relay-service disable--More-- unset dhcp-relay-ip--More-- set dhcp-relay-type regular--More-- set ip 10.231.255.0 255.255.0.0--More-- unset allowaccess--More-- set gwdetect disable--More-- unset detectserver--More-- set detectprotocol ping--More-- set ha-priority 0--More-- set dns-query disable--More-- set pptp-client disable--More-- set arpforward enable--More-- set broadcast-forward disable--More-- set bfd global--More-- set l2forward disable--More-- set icmp-redirect enable--More-- set vlanforward enable--More-- set stpforward disable--More-- set ident-accept disable--More-- set ipmac disable--More-- set subst disable--More-- set log disable--More-- set fdp disable--More-- set ddns disable--More-- set status up--More-- set netbios-forward disable--More-- set wins-ip 0.0.0.0--More-- set type vlan--More-- set tcp-mss 0--More-- set inbandwidth 0--More-- set outbandwidth 0--More-- set spillover-threshold 0--More-- set description ''--More-- set alias ''--More-- config ipv6--More-- set autoconf disable--More-- set ip6-address ::/0--More-- unset ip6-allowaccess--More-- set ip6-default-life 1800--More-- set ip6-hop-limit 0--More-- set ip6-link-mtu 0--More-- set ip6-manage-flag disable--More-- set ip6-max-interval 600--More-- set ip6-min-interval 198--More-- set ip6-other-flag disable--More-- set ip6-reachable-time 0--More-- set ip6-retrans-time 0--More-- set ip6-send-adv disable--More-- end--More-- set idle-timeout 0--More-- set mtu-override disable--More-- set wccp disable--More-- set explicit-web-proxy enable--More-- set interface "dmz1"

Page 27: N_ FortiGate 200a Configuration.txt

--More-- set vlanid 100--More-- next--More-- end--More-- config system password-policy--More-- set status disable--More-- end--More-- config system admin--More-- edit "admin"--More-- set remote-auth disable--More-- set peer-auth disable--More-- set trusthost1 0.0.0.0 0.0.0.0--More-- set trusthost2 0.0.0.0 0.0.0.0--More-- set trusthost3 0.0.0.0 0.0.0.0--More-- set ip6-trusthost1 ::/0--More-- set ip6-trusthost2 ::/0--More-- set ip6-trusthost3 ::/0--More-- set accprofile "super_admin"--More-- set comments ''--More-- set vdom "root"--More-- unset ssh-public-key1--More-- unset ssh-public-key2--More-- unset ssh-public-key3--More-- set schedule ''--More-- config dashboard--More-- edit "sysinfo"--More-- set column 1--More-- set status open--More-- next--More-- edit "licinfo"--More-- set column 1--More-- set status open--More-- next--More-- edit "jsconsole"--More-- set column 1--More-- set status open--More-- next--More-- edit "sysres"--More-- set column 1--More-- set show-fds-chart enable--More-- set show-fortianalyzer-chart enable--More-- set status close--More-- next--More-- edit "sysop"--More-- set column 2--More-- set status open--More-- next--More-- edit "alert"--More-- set column 2--More-- set show-admin-auth enable--More-- set show-conserve-mode enable--More-- set show-device-update enable--More-- set show-disk-failure enable--More-- set show-fds-quota enable--More-- set show-fds-update enable--More-- set show-firmware-change enable--More-- set show-power-supply enable--More-- set show-system-restart enable--More-- set status open--More-- next--More-- edit "statistics"

Page 28: N_ FortiGate 200a Configuration.txt

--More-- set column 2--More-- set status open--More-- next--More-- end--More-- set password ENC AK1o6qdFS0+PGvFllhXcVgdHe8Qy27Q2iPjQKNYr44bzGQ=--More-- next--More-- end--More-- config system ha--More-- set group-id 0--More-- set group-name "FGT-HA"--More-- set password ENC 3V2ra/8ZscvOB+hqqjjexLcSe5gu0D7d383eT24ILFzmq7QbD93hZ4B0MQqOOE3i33+9rrJp/lLyQpD/e6LsjhA8EMyYhC0jpnJr8q7TnZJh/Cjt--More-- set hbdev "dmz2" 50 "wan2" 50 --More-- set route-ttl 10--More-- set route-wait 0--More-- set route-hold 10--More-- set sync-config enable--More-- set encryption disable--More-- set authentication disable--More-- set hb-interval 2--More-- set hb-lost-threshold 6--More-- set helo-holddown 20--More-- set arps 5--More-- set arps-interval 8--More-- set session-pickup disable--More-- set link-failed-signal disable--More-- set uninterruptable-upgrade enable--More-- set override disable--More-- set priority 128--More-- unset monitor--More-- unset pingserver-monitor-interface--More-- set pingserver-failover-threshold 0--More-- set pingserver-flip-timeout 60--More-- end--More-- config system dns--More-- set primary 212.24.224.14--More-- set secondary 85.194.127.14--More-- set domain ''--More-- set ip6-primary ::--More-- set ip6-secondary ::--More-- set dns-cache-limit 5000--More-- set dns-cache-ttl 1800--More-- set cache-notfound-responses disable--More-- end--More-- config system replacemsg mail "email-block"--More-- set buffer "Potentially Dangerous Attachment Removed. The file \"%%FILE%%\" has been blocked. File quarantined as: \"%%QUARFILENAME%%\"."--More-- set header 8bit--More-- set format text--More-- end--More-- config system replacemsg mail "email-virus"--More-- set buffer "Dangerous Attachment has been Removed. The file \"%%FILE%%\" has been removed because of a virus. It was infected with the \"%%VIRUS%%\" virus. File quarantined as: \"%%QUARFILENAME%%\"."--More-- set header 8bit--More-- set format text--More-- end

Page 29: N_ FortiGate 200a Configuration.txt

--More-- config system replacemsg mail "email-dlp"--More-- set buffer "This email has been blocked. The email message appeared to contain a data leak."--More-- set header 8bit--More-- set format text--More-- end--More-- config system replacemsg mail "email-dlp-subject"--More-- set buffer "Data leak detected!"--More-- set header 8bit--More-- set format text--More-- end--More-- config system replacemsg mail "email-dlp-ban"--More-- set buffer "This email has been blocked because a data leak was detected. Please contact your admin to be re-enabled."--More-- set header 8bit--More-- set format text--More-- end--More-- config system replacemsg mail "email-dlp-ban-sender"--More-- set buffer "This email has been blocked because the sender has sent a data leak. Please contact your admin to be re-enabled."--More-- set header 8bit--More-- set format text--More-- end--More-- config system replacemsg mail "email-filesize"--More-- set buffer "This email has been blocked. The email message is larger than the configured file size limit."--More-- set header 8bit--More-- set format text--More-- end--More-- config system replacemsg mail "partial"--More-- set buffer "Fragmented emails are blocked."--More-- set header 8bit--More-- set format text--More-- end--More-- config system replacemsg mail "smtp-block"--More-- set buffer "The file %%FILE%% has been blocked. File quarantined as: %%QUARFILENAME%%"--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg mail "smtp-virus"--More-- set buffer "The file %%FILE%% has been infected with the virus %%VIRUS%% File quarantined as %%QUARFILENAME%%"--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg mail "smtp-filesize"--More-- set buffer "This message is larger than the configured limit and has been blocked."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg http "bannedword"--More-- set buffer "<HTML><BODY>The page you requested has been blocked because it contains a banned word. URL = http://%%URL%%</BODY></HTML>"--More-- set header http--More-- set format html

Page 30: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config system replacemsg http "url-block"--More-- set buffer "<HTML><BODY>The URL you requested has been blocked. URL = %%URL%%</BODY></HTML>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg http "infcache-block"--More-- set buffer "<HTML><BODY><H2>High security alert!!!</h2><p>The URL you requested was previously found to be infected.</p><p>URL = http://%%URL%%</p></BODY></HTML>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg http "http-block"--More-- set buffer "<HTML> <BODY> <h2>High security alert!!!</h2> <p>You are not permitted to download the file \"%%FILE%%\".</p> <p>URL = http://%%URL%%</p> </BODY> </HTML>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg http "http-virus"--More-- set buffer "<HTML><BODY><h2>High security alert!!!</h2><p>You are not permitted to download the file \"%%FILE%%\" because it is infected with the virus \"%%VIRUS%%\". </p><p>URL = http://%%URL%%</p><p>File quarantined as: %%QUARFILENAME%%.</p></BODY></HTML>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg http "http-filesize"--More-- set buffer "<HTML><BODY> <h2>Attention!!!</h2><p>The file \"%%FILE%%\" has been blocked. The file is larger than the configured file size limit.</p> <p>URL = http://%%URL%%</p> </BODY></HTML>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg http "http-dlp"--More-- set buffer "<HTML><BODY> <h2>Attention!!!</h2><p>The transfer attempted appeared to contain a data leak!</p><p>URL = http://%%URL%%</p> </BODY></HTML>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg http "http-dlp-ban"--More-- set buffer "<HTML><BODY> <h2>Attention!!!</h2><p>Your user authentication or IP address has been banned due to a detected data leak. You need an admin to re-enable your computer</p><p>URL = http://%%URL%%</p> </BODY></HTML>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg http "http-contenttypeblock"--More-- set buffer "<HTML><BODY> <h2>Attention!!!</h2><p>Content-type not permitted.</BODY></HTML>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg http "http-client-block"

Page 31: N_ FortiGate 200a Configuration.txt

--More-- set buffer "<HTML> <BODY> <h2>High security alert!!!</h2> <p>You are not permitted to upload the file \"%%FILE%%\".</p> <p>URL = http://%%URL%%</p> </BODY> </HTML>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg http "http-client-virus"--More-- set buffer "<HTML><BODY><h2>High security alert!!!</h2><p>You are not permitted to upload the file \"%%FILE%%\" because it is infected with the virus \"%%VIRUS%%\". </p><p>URL = http://%%URL%%</p><p>File quarantined as: %%QUARFILENAME%%.</p></BODY></HTML>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg http "http-client-filesize"--More-- set buffer "<HTML><BODY> <h2>Attention!!!</h2><p>Your request has been blocked. The request is larger than the configured file size limit.</p> <p>URL = http://%%URL%%</p> </BODY></HTML>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg http "http-client-bannedword"--More-- set buffer "<HTML><BODY>The page you uploaded has been blocked because it contains a banned word. URL = http://%%URL%%</BODY></HTML>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg http "http-post-block"--More-- set buffer "<HTML><BODY>HTTP POST action is not allowed for policy reasons.</BODY></HTML>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg ftp "ftp-dl-infected"--More-- set buffer "Transfer failed. The file %%FILE%% is infected with the virus %%VIRUS%%. File quarantined as %%QUARFILENAME%%."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg ftp "ftp-dl-blocked"--More-- set buffer "Transfer failed. You are not permitted to transfer the file \"%%FILE%%\"."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg ftp "ftp-dl-filesize"--More-- set buffer "File size limit exceeded."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg ftp "ftp-dl-dlp"--More-- set buffer "Transfer failed. Data leak detected \"%%FILE%%\"."--More-- set header none--More-- set format text

Page 32: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config system replacemsg ftp "ftp-dl-dlp-ban"--More-- set buffer "Transfer failed. You are banned from transmitting due to a detected data leak. Contact your admin to be re-enabled."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg nntp "nntp-dl-infected"--More-- set buffer "Dangerous Attachment has been Removed. The file \"%%FILE%%\" has been removed because of a virus. It was infected with the \"%%VIRUS%%\" virus. File quarantined as: \"%%QUARFILENAME%%\"."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg nntp "nntp-dl-blocked"--More-- set buffer "The file %%FILE%% has been blocked. File quarantined as: %%QUARFILENAME%%"--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg nntp "nntp-dl-filesize"--More-- set buffer "This article has been blocked. The article is larger than the configured file size limit."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg nntp "nntp-dlp"--More-- set buffer "This article has been blocked. It appears to contain a data leak."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg nntp "nntp-dlp-subject"--More-- set buffer "Data leak detected!"--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg nntp "nntp-dlp-ban"--More-- set buffer "this article has been blocked. The user is banned for sending a data leak. Please contact your admin to be re-enabled."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg fortiguard-wf "ftgd-block"--More-- set buffer "<html><head><title>Web Filter Violation</title></head><body><font size=2><table width=\"100%\"><tr><td>%%FORTIGUARD_WF%%</td><td align=\"right\">%%FORTINET%%</td></tr><tr><td bgcolor=#ff6600 align=\"center\" colspan=2><font color=#ffffff><b>Web Page Blocked</b></font></td></tr></table><br><br>You have tried to access a web page which is in violation of your internet usage policy.<br><br>URL:&nbsp;%%URL%%<br>Category:&nbsp;%ÊTEGORY%%<br><br>To have the rating of this web page re-evaluated <u><a href=\"%%FTGD_RE_EVAL%%\">please click here</a></u>.<br>%%OVERRIDE%%<br><hr><br>Powered by %%SERVICE%%.</font></body></html>"--More-- set header http--More-- set format html--More-- end

Page 33: N_ FortiGate 200a Configuration.txt

--More-- config system replacemsg fortiguard-wf "http-err"--More-- set buffer "<html><head><title>%%HTTP_ERR_CODE%% %%HTTP_ERR_DESC%%</title></head><body><font size=2><table width=\"100%\"><tr><td>%%FORTIGUARD_WF%%</td><td align=\"right\">%%FORTINET%%</td></tr><tr><td bgcolor=#3300cc align=\"center\" colspan=2><font color=#ffffff><b>%%HTTP_ERR_CODE%% %%HTTP_ERR_DESC%%</b></font></td></tr></table><br><br>The webserver for %%URL%% reported that an error occurred while trying to access the website. Please click <u><a onclick=\"history.back()\">here</a></u> to return to the previous page.<br><br><hr><br>Powered by %%SERVICE%%.</font></body></html>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg fortiguard-wf "ftgd-ovrd"--More-- set buffer "<html><head><title>Web Filter Block Override</title></head><body><font size=2><table width=\"100%\"><tr><td>%%FORTIGUARD_WF%%</td><td align=\"right\">%%FORTINET%%</td></tr><tr><td bgcolor=#3300cc align=\"center\" colspan=2><font color=#ffffff><b>Web Filter Block Override</b></font></td></tr><tr><td colspan=2><br><br>If you have been granted override creation privileges by your administrator, you can enter your username and password here to gain immediate access to the blocked web-page. If you do not have these privileges, please contact your administrator to gain access to the web-page.<br><br></td></tr><tr><td align=\"center\" colspan=2>%%OVRD_FORM%%</td></tr></table><br><br><hr><br>Powered by %%SERVICE%%.</font></body></html>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg spam "ipblocklist"--More-- set buffer "Mail from this IP address is not allowed and has been blocked."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg spam "smtp-spam-dnsbl"--More-- set buffer "This message has been blocked because it is from a DNSBL/ORDBL IP address."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg spam "smtp-spam-feip"--More-- set buffer "This message has been blocked because it is from a FortiGuard - AntiSpam black IP address."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg spam "smtp-spam-helo"--More-- set buffer "This message has been blocked because the HELO/EHLO domain is invalid."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg spam "smtp-spam-emailblack"--More-- set buffer "Mail from this email address is not allowed and has been blocked."--More-- set header none--More-- set format text

Page 34: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config system replacemsg spam "smtp-spam-mimeheader"--More-- set buffer "This message has been blocked because it contains an invalid header."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg spam "reversedns"--More-- set buffer "This message has been blocked because the return email domain is invalid."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg spam "smtp-spam-bannedword"--More-- set buffer "This message has been blocked because it contains a banned word."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg spam "smtp-spam-ase"--More-- set buffer "This message has been blocked because ASE reports it as spam. "--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg spam "submit"--More-- set buffer "If this email is not spam, click here to submit the signatures to FortiGuard - AntiSpam Service."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg im "im-file-xfer-block"--More-- set buffer "Transfer failed. You are not permitted to transfer the file \"%%FILE%%\"."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg im "im-file-xfer-name"--More-- set buffer "Transfer %¬TION%%. The file name \"%%FILE%%\" matches the configured file name block list."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg im "im-file-xfer-infected"--More-- set buffer "Transfer %¬TION%%. The file \"%%FILE%%\" is infected with the virus %%VIRUS%%. File quarantined as %%QUARFILENAME%%."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg im "im-file-xfer-size"--More-- set buffer "Transfer %¬TION%%. The file \"%%FILE%%\" is larger than the configured limit."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg im "im-dlp"--More-- set buffer "Transfer %¬TION%%. The file \"%%FILE%%\" contains a data leak."

Page 35: N_ FortiGate 200a Configuration.txt

--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg im "im-dlp-ban"--More-- set buffer "Transfer %¬TION%%. The user is banned because of a detected data leak."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg im "im-voice-chat-block"--More-- set buffer "Connection failed. You are not permitted to use voice chat."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg im "im-photo-share-block"--More-- set buffer "Photo sharing failed. You are not permitted to share photo."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg im "im-long-chat-block"--More-- set buffer "Message blocked. The message is longer than the configured limit."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg alertmail "alertmail-virus"--More-- set buffer "Virus/Worm detected: %%VIRUS%% Protocol: %%PROTOCOL%% Source IP: %%SOURCE_IP%% Destination IP: %ÞST_IP%% Email Address From: %%EMAIL_FROM%% Email Address To: %%EMAIL_TO%% "--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg alertmail "alertmail-block"--More-- set buffer "File Block Detected: %%FILE%% Protocol: %%PROTOCOL%% Source IP: %%SOURCE_IP%% Destination IP: %ÞST_IP%% Email Address From: %%EMAIL_FROM%% Email Address To: %%EMAIL_TO%% "--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg alertmail "alertmail-nids-event"--More-- set buffer "The following intrusion was observed: %%NIDS_EVENT%%."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg alertmail "alertmail-crit-event"--More-- set buffer "The following critical firewall event was detected: %%CRITICAL_EVENT%%."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg alertmail "alertmail-disk-full"

Page 36: N_ FortiGate 200a Configuration.txt

--More-- set buffer "The log disk is Full."--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg admin "admin-disclaimer-text"--More-- set buffer "W A R N I N G W A R N I N G W A R N I N G W A R N I N G --More-- This is a private computer system. Unauthorized access or use --More-- is prohibited and subject to prosecution and/or disciplinary --More-- action. All use of this system constitutes consent to --More-- monitoring at all times and users are not entitled to any --More-- expectation of privacy. If monitoring reveals possible evidence--More-- of violation of criminal statutes, this evidence and any other --More-- related information, including identification information about --More-- the user, may be provided to law enforcement officials.--More-- If monitoring reveals violations of security regulations or--More-- unauthorized use, employees who violate security regulations or--More-- make unauthorized use of this system are subject to appropriate --More-- disciplinary action.--More-- W A R N I N G W A R N I N G W A R N I N G W A R N I N G--More-- "--More-- set header none--More-- set format text--More-- end--More-- config system replacemsg auth "auth-disclaimer-page-1"--More-- set buffer "<HTML><HEAD><TITLE>Firewall Disclaimer</TITLE></HEAD><BODY><FORM ACTION=\"/\" method=\"POST\"><INPUT TYPE=\"hidden\" NAME=\"%%MAGICID%%\" VALUE=\"%%MAGICVAL%%\"><INPUT TYPE=\"hidden\" NAME=\"%%ANSWERID%%\" VALUE=\"%ÞCLINEVAL%%\"><INPUT TYPE=\"hidden\" NAME=\"%%REDIRID%%\" VALUE=\"%%PROTURI%%\"><TABLE ALIGN=\"CENTER\" width=400 height=250 cellpadding=2 cellspacing=0 border=0 bgcolor=\"#008080\"><TR><TD><TABLE border=0 width=\"100%\" height=\"100%\" cellpadding=0 cellspacing=0 bgcolor=\"#9dc8c6\"><TR height=30 bgcolor=\"#008080\"><TD><b><font size=2 face=\"Verdana\" color=\"#ffffff\">Disclaimer Agreement</font></b></TD><TR><TR height=\"100%\"><TD><TABLE border=0 cellpadding=5 cellspacing=0 width=\"320\" align=center><TR><TD colspan=2><font size=2 face=\"Times New Roman\">You are about to access Internet content that is not under the control of the network access provider. The network access provider is therefore not responsible for any of these sites, their content or their privacy policies. The network access provider and its staff do not endorse nor make any representations about these sites, or any information, software or other products or materials found there, or any results that may be obtained from using them. If you decide to access any Internet content, you do this entirely at your own risk and you are responsible for ensuring that

Page 37: N_ FortiGate 200a Configuration.txt

any accessed material does not infringe the laws governing, but not exhaustively covering, copyright, trademarks, pornography, or any other material which is slanderous, defamatory or might cause offence in any other way.</font></TD></TR><TR><TD>Do you agree to the above terms?</TD></TR><TR><TD><INPUT CLASS=\"button\" TYPE=\"button\" VALUE=\"Yes, I agree\" ONCLICK=\"agree()\"><INPUT CLASS=\"button\" TYPE=\"button\" VALUE=\"No, I decline\" ONCLICK=\"decline()\"></TD></TR></TABLE></TD></TR></TABLE></TD></TR></TABLE></FORM><SCRIPT LANGUAGE=\"JavaScript\">function agree(){document.forms[0].%%ANSWERID%%.value=\"%%AGREEVAL%%\";document.forms[0].submit();}function decline(){document.forms[0].submit();}</SCRIPT></BODY></HTML>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg auth "auth-disclaimer-page-2"--More-- set buffer ''--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg auth "auth-disclaimer-page-3"--More-- set buffer ''--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg auth "auth-reject-page"--More-- set buffer "<HTML><HEAD><TITLE>Firewall Disclaimer Declined</TITLE></HEAD><BODY><FORM ACTION=\"/\" method=\"POST\"><INPUT TYPE=\"hidden\" NAME=\"%%MAGICID%%\" VALUE=\"%%MAGICVAL%%\"><INPUT TYPE=\"hidden\" NAME=\"%%REDIRID%%\" VALUE=\"%%PROTURI%%\"><TABLE ALIGN=\"CENTER\" width=400 height=250 cellpadding=2 cellspacing=0 border=0 bgcolor=\"#008080\"><TR><TD><TABLE border=0 width=\"100%\" height=\"100%\" cellpadding=0 cellspacing=0 bgcolor=\"#9dc8c6\"><TR height=30 bgcolor=\"#008080\"><TD><b><font size=2 face=\"Verdana\" color=\"#ffffff\">Disclaimer Declined</font></b></TD><TR><TR height=\"100%\"><TD><TABLE border=0 cellpadding=5 cellspacing=0 width=\"320\" align=center><TR><TD colspan=2><font size=2 face=\"Times New Roman\">Sorry, network access cannot be granted unless you agree to the disclaimer.</font></TD><TR><TR><TD></TD><TD><INPUT TYPE=\"submit\" VALUE=\"Return to Disclaimer\"></TD></TR></TABLE></TD></TR></TABLE></TD></TR></TABLE></FORM></BODY></HTML>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg auth "auth-login-page"--More-- set buffer "<HTML><HEAD><TITLE>Firewall Authentication</TITLE></HEAD><BODY><FORM ACTION=\"/\" method=\"POST\"><INPUT TYPE=\"hidden\" NAME=\"%%MAGICID%%\" VALUE=\"%%MAGICVAL%%\"><TABLE ALIGN=\"CENTER\" width=400 height=250 cellpadding=2 cellspacing=0 border=0 bgcolor=\"#008080\"><TR><TD><TABLE border=0 cellpadding=0 cellspacing=0 bgcolor=\"#9dc8c6\"><TR height=30 bgcolor=\"#008080\"><TD><b><font size=2 face=\"Verdana\" color=\"#ffffff\">Authentication Required</font></b></TD></TR><TR><TD><TABLE border=0 cellpadding=5 cellspacing=0 width=\"320\" align=center><TR><TD colspan=2><font

Page 38: N_ FortiGate 200a Configuration.txt

size=2 face=\"Times New Roman\">%%QUESTION%%</font></TD></TR><TR><TD><font size=2 face=\"Times New Roman\">Username:</font></TD><TD><INPUT TYPE=\"text\" NAME=\"%%USERNAMEID%%\" size=25></TD></TR><TR><TD><font size=2 face=\"Times New Roman\">Password:</font></TD><TD><INPUT TYPE=\"password\" NAME=\"%%PASSWORDID%%\" size=25></TD></TR><TR><TD><INPUT TYPE=\"hidden\" NAME=\"%%REDIRID%%\" VALUE=\"%%PROTURI%%\"><INPUT TYPE=\"submit\" VALUE=\"Continue\"></TD></TR></TABLE></TD></TR></TABLE></TD></TR></TABLE></FORM></BODY></HTML>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg auth "auth-login-failed-page"--More-- set buffer "<HTML><HEAD><TITLE>Firewall Authentication</TITLE></HEAD><BODY><FORM ACTION=\"/\" method=\"POST\"><INPUT TYPE=\"hidden\" NAME=\"%%MAGICID%%\" VALUE=\"%%MAGICVAL%%\"><TABLE ALIGN=\"CENTER\" width=400 height=250 cellpadding=2 cellspacing=0 border=0 bgcolor=\"#008080\"><TR><TD><TABLE border=0 cellpadding=0 cellspacing=0 bgcolor=\"#9dc8c6\"><TR height=30 bgcolor=\"#008080\"><TD><b><font size=2 face=\"Verdana\" color=\"#ffffff\">Authentication Failed</font></b></TD></TR><TR><TD><TABLE border=0 cellpadding=5 cellspacing=0 width=\"320\" align=center><TR><TD colspan=2><font size=2 face=\"Times New Roman\">%úILED_MESSAGE%%</font></TD></TR><TR><TD><font size=2 face=\"Times New Roman\">Username:</font></TD><TD><INPUT TYPE=\"text\" NAME=\"%%USERNAMEID%%\" size=25></TD></TR><TR><TD><font size=2 face=\"Times New Roman\">Password:</font></TD><TD><INPUT TYPE=\"password\" NAME=\"%%PASSWORDID%%\" size=25></TD></TR><TR><TD><INPUT TYPE=\"hidden\" NAME=\"%%REDIRID%%\" VALUE=\"%%PROTURI%%\"><INPUT TYPE=\"submit\" VALUE=\"Continue\"></TD></TR></TABLE></TD></TR></TABLE></TD></TR></TABLE></FORM></BODY></HTML>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg auth "auth-challenge-page"--More-- set buffer "<HTML><HEAD><TITLE>Firewall Authentication</TITLE></HEAD><BODY><FORM ACTION=\"/\" method=\"POST\"><INPUT TYPE=\"hidden\" NAME=\"%%MAGICID%%\" VALUE=\"%%MAGICVAL%%\"><TABLE ALIGN=\"CENTER\" width=400 height=250 cellpadding=2 cellspacing=0 border=0 bgcolor=\"#008080\"><TR><TD><TABLE border=0 cellpadding=0 cellspacing=0 bgcolor=\"#9dc8c6\"><TR height=30 bgcolor=\"#008080\"><TD><b><font size=2 face=\"Verdana\" color=\"#ffffff\">Authentication Required</font></b></TD></TR><TR><TD><TABLE border=0 cellpadding=5 cellspacing=0 width=\"320\" align=center><TR><TD colspan=2><font size=2 face=\"Times New Roman\">%%QUESTION%%</font></TD></TR><TR><TD><font size=2 face=\"Times New Roman\">Answer:</font></TD><TD><INPUT TYPE=\"password\" NAME=\"%%PASSWORDID%%\" size=25></TD></TR><TR><TD><INPUT TYPE=\"hidden\" NAME=\"%%USERNAMEID%%\" VALUE=\"%%USERNAMEVAL%%\"><INPUT TYPE=\"hidden\" NAME=\"%%REQUESTID%%\" VALUE=\"%%REQUESTVAL%%\"><INPUT TYPE=\"hidden\" NAME=\"%%REDIRID%%\" VALUE=\"%%PROTURI%%\"><INPUT TYPE=\"hidden\" NAME=\"%%USERGROUPID%%\" VALUE=\"%%USERGROUPVAL%%\"><INPUT TYPE=\"submit\"

Page 39: N_ FortiGate 200a Configuration.txt

VALUE=\"Continue\"></TD></TR></TABLE></TD></TR></TABLE></TD></TR></TABLE></FORM></BODY></HTML>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg auth "auth-keepalive-page"--More-- set buffer "<HTML>--More-- <HEAD>--More-- <TITLE>Firewall Authentication Keepalive Window</TITLE>--More-- </HEAD>--More-- <BODY>--More-- <SCRIPT LANGUAGE=\"JavaScript\">--More-- var countDownTime=%%TIMEOUT%% + 1;--More-- function countDown(){--More-- countDownTime--;--More-- if (countDownTime <= 0){--More-- location.href=\"%%KEEPALIVEURL%%\";--More-- return;--More-- }--More-- document.getElementById(\'countdown\').innerHTML = countDownTime;--More-- counter=setTimeout(\"countDown()\", 1000);--More-- }--More-- function startit(){--More-- countDown();--More-- }--More-- window.onload=startit--More-- </SCRIPT>--More-- <table width=\"100%\" height=\"100%\"><tr><td align=\"center\">--More-- <H3>This browser window is used to keep your authentication session active.</H3>--More-- <H3>Please leave it open in the background and open a <a href=\"%%AUTH_REDIR_URL%%\" target=\"_blank\">new window</a> to continue.</H3>--More-- <p>Authentication Refresh in <b id=countdown>%%TIMEOUT%%</b> seconds</p>--More-- <p><a href=\"%%AUTH_LOGOUT%%\">logout</a></p>--More-- </td></tr></table>--More-- </BODY>--More-- </HTML>--More-- "--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg sslvpn "sslvpn-login"--More-- set buffer "<html><head><title>login</title><meta http-equiv=\"Pragma\" content=\"no-cache\"><meta http-equiv=\"cache-control\" content=\"no-cache\"><meta http-equiv=\"cache-control\" content=\"must-revalidate\"><link href=\"/sslvpn/css/login.css\" rel=\"stylesheet\" type=\"text/css\"><script language=\"JavaScript\"><!--if (top && top.location != window.location) top.location = top.location;if (window.opener && window.opener.top) { window.opener.top.location = window.opener.top.location; self.close(); }//--></script></head><body class=\"main\"><center><table width=\"100%\" height=\"100%\" align=\"center\" class=\"container\" valign=\"middle\" cellpadding=\"0\" cellspacing=\"0\"><tr valign=middle><td><form action=\"%%SSL_ACT%%\" method=\"%%SSL_METHOD%%\" name=\"f\"><table class=\"list\" cellpadding=10 cellspacing=0 align=center width=400

Page 40: N_ FortiGate 200a Configuration.txt

height=180>%%SSL_LOGIN%%</table>%%SSL_HIDDEN%%</td></tr></table></form></center></body><script>document.forms[0].username.focus();</script></html>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg sslvpn "sslvpn-limit"--More-- set buffer "<html><head><title>Already Logged In</title><meta http-equiv=\"Pragma\" content=\"no-cache\"><meta http-equiv=\"cache-control\" content=\"no-cache\"><meta http-equiv=\"cache-control\" content=\"must-revalidate\"><link href=\"/sslvpn/css/login.css\" rel=\"stylesheet\" type=\"text/css\"><script type=\"text/javascript\">if (top && top.location != window.location) top.location = top.location;if (window.opener && window.opener.top) { window.opener.top.location = window.opener.top.location; self.close(); }</script></head><body class=\"main\"><center><table class=\"container\" height=\"100%\" cellspacing=\"0\" cellpadding=\"0\" align=\"center\" width=\"100%\" valign=\"middle\"><tbody><tr valign=\"middle\"><td><table class=\"list\" height=\"180\" cellspacing=\"0\" cellpadding=\"10\" align=\"center\" width=\"400\"><tbody><tr class=\"dark\"><td colspan=\"2\"> <b>Already Logged In</b></td></tr><tr><td colspan=\"2\"><p>You already have an open SSL VPN connection. Opening multiple connections is not permitted.</p><p>If you proceed, your other connection will be disconnected.</p><p>Please contact your administrator if you blevieve there is a problem.</p></td></tr><tr><td style=\"text-align:center\">%%SSL_LOGIN_ANYWAY%%</td><td style=\"text-align:center\">%%SSL_LOGIN_CANCEL%%</td></tr></tbody></table></td></tr></tbody></table></center></body></html>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg ec "endpt-download-portal"--More-- set buffer "<HTML><HEAD><TITLE>Endpoint Security Required</TITLE></HEAD><BODY><TABLE ALIGN=\"CENTER\" width=500 height=250 cellpadding=2 cellspacing=0 border=0 bgcolor=\"#008080\"><TR><TD><TABLE border=0 width=\"100%\" height=\"100%\" cellpadding=0 cellspacing=0 bgcolor=\"#9dc8c6\"><TR height=30 bgcolor=\"#008080\"><TD style=\"text-align: center\"><b><font size=2 face=\"Verdana\" color=\"#ffffff\">Endpoint Security Required</font></b></TD><TR><TR height=\"100%\"><TD><TABLE border=0 cellpadding=5 cellspacing=0 width=\"500\" align=center><TR><TD><font size=2 face=\"Times New Roman\">The security policy requires the latest FortiClient Endpoint Security software and antivirus signature package to be installed.<br><br>Installing FortiClient requires that you have administrator privileges on your computer. If you do not, please contact your network administrator to have FortiClient installed.<br><br>The installer may be downloaded using the following link:<br>%%LINK%%<br>Installation instructions:<br><ul><li><span style=\"font-style:italic\">For Internet Explorer:</span></li><ol><li>Click the above link to download the installer</li><li>When Internet Explorer asks what action you would like to take, click \"Run\"</li></ol><br><li><span style=\"font-style:italic\">For Firefox:</span></li><ol><li>Click the above link to download the installer</li><li>Save the installer and note the location it is saved to</li><li>Open the folder containing the installer and run it</li></ol></ul>FortiClient installation may take a few minutes. Thank you for your patience.<br><br></font></TD></TR><TR><TD></TD></TR></TABLE></TD></

Page 41: N_ FortiGate 200a Configuration.txt

TR></TABLE></TD></TR></TABLE></BODY></HTML>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg ec "endpt-recommendation-portal"--More-- set buffer "<HTML><HEAD><TITLE>Endpoint Security Required</TITLE></HEAD><BODY><TABLE ALIGN=\"CENTER\" width=500 height=250 cellpadding=2 cellspacing=0 border=0 bgcolor=\"#008080\"><TR><TD><TABLE border=0 width=\"100%\" height=\"100%\" cellpadding=0 cellspacing=0 bgcolor=\"#9dc8c6\"><TR height=30 bgcolor=\"#008080\"><TD style=\"text-align: center\"><b><font size=2 face=\"Verdana\" color=\"#ffffff\">Endpoint Security Required</font></b></TD><TR><TR height=\"100%\"><TD><TABLE border=0 cellpadding=5 cellspacing=0 width=\"500\" align=center><TR><TD><font size=2 face=\"Times New Roman\">The use of this security policy recommends that the latest FortiClient Endpoint Security software and antivirus signature package are installed.<br><br>Installing FortiClient requires that you have administrator privileges on your computer. If you do not, please contact your network administrator to have FortiClient installed.<br><br>The installer may be downloaded using the following link:<br>%%LINK%%<br>Installation instructions:<br><ul><li><span style=\"font-style:italic\">For Internet Explorer:</span></li><ol><li>Click the above link to download the installer</li><li>When Internet Explorer asks what action you would like to take, click \"Run\"</li></ol><br><li><span style=\"font-style:italic\">For Firefox:</span></li><ol><li>Click the above link to download the installer</li><li>Save the installer and note the location it is saved to</li><li>Open the folder containing the installer and run it</li></ol></ul>FortiClient installation may take a few minutes. Thank you for your patience.<br><br></font></TD></TR><TR><TD></TD></TR></TABLE><TR height=30 bgcolor=\"#9dc8c6\"><TD style=\"text-align: center\"><b><font size=2 face=\"Verdana\" color=\"#ffffff\"><a href=\"%%DST_ADDR_LINK%%\"> Continue to %%DST_ADDR_LABEL%% </a></font></b></TD><TR></TD></TR></TABLE></TD></TR></TABLE></BODY></HTML>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg nac-quar "nac-quar-virus"--More-- set buffer "<html><head><title>Virus Quarantine</title></head><body><font size=2><table width=\"100%\"><tr><td bgcolor=#3300cc align=\"center\" colspan=2><font color=#ffffff><b>Blocked because of virus</b></font></td></tr></table><br><br>A virus was detected, originating from your system. Please contact the system administrator.<br><br><hr></font></body></html>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg nac-quar "nac-quar-dos"--More-- set buffer "<html><head><title>Attack Detected</title></head><body><font size=2><table width=\"100%\"><tr><td bgcolor=#3300cc align=\"center\" colspan=2><font color=#ffffff><b>Blocked because of DoS Attack</b></font></td></tr></table><br><br>A DoS attack was detected, originating from your system. Please contact the system administrator.<br><br><hr></font></body></html>"--More-- set header http

Page 42: N_ FortiGate 200a Configuration.txt

--More-- set format html--More-- end--More-- config system replacemsg nac-quar "nac-quar-ips"--More-- set buffer "<html><head><title>Attack Detected</title></head><body><font size=2><table width=\"100%\"><tr><td bgcolor=#3300cc align=\"center\" colspan=2><font color=#ffffff><b>Blocked because of IPS attack</b></font></td></tr></table><br><br>An attack was detected, originating from your system. Please contact the system administrator.<br><br><hr></font></body></html>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg nac-quar "nac-quar-dlp"--More-- set buffer "<html><head><title>Data Leak Detected</title></head><body><font size=2><table width=\"100%\"><tr><td bgcolor=#3300cc align=\"center\" colspan=2><font color=#ffffff><b>Blocked because of data leak</b></font></td></tr></table><br><br>A data leak was detected, originating from your system. Please contact the system administrator.<br><br><hr></font></body></html>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg traffic-quota "per-ip-shaper-block"--More-- set buffer "<html><head><title>Traffic Quota Control</title></head><body><font size=2><table width=\"100%\"><tr><td bgcolor=#3300cc align=\"center\" colspan=2><font color=#ffffff><b>Traffic blocked because of exceed quota</b></font></td></tr></table><br><br>Traffic blocked because of exceed per IP traffic shaper quota. Please contact the system administrator.<br>%%QUOTA_INFO%%<br><br><hr></font></body></html>"--More-- set header http--More-- set format html--More-- end--More-- config system replacemsg traffic-quota "traffic-shaper-block"--More-- set buffer "<html><head><title>Traffic Quota Control</title></head><body><font size=2><table width=\"100%\"><tr><td bgcolor=#3300cc align=\"center\" colspan=2><font color=#ffffff><b>Traffic blocked because of exceed quota</b></font></td></tr></table><br><br>Traffic blocked because of exceed shared traffic shaper quota. Please contact the system administrator.<br>%%QUOTA_INFO%%<br><br><hr></font></body></html>"--More-- set header http--More-- set format html--More-- end--More-- config system snmp sysinfo--More-- set contact-info ''--More-- set description ''--More-- set engine-id ''--More-- set location ''--More-- set status disable--More-- set trap-high-cpu-threshold 80--More-- set trap-log-full-threshold 90--More-- set trap-low-memory-threshold 80--More-- end--More-- config system autoupdate override--More-- set address ''--More-- set fail-over enable

Page 43: N_ FortiGate 200a Configuration.txt

--More-- set status disable--More-- end--More-- config system autoupdate push-update--More-- set address 0.0.0.0--More-- set override disable--More-- set port 9443--More-- set status disable--More-- end--More-- config system autoupdate schedule--More-- set frequency every--More-- set status enable--More-- set time 03:60--More-- end--More-- config system autoupdate tunneling--More-- set address ''--More-- set password ''--More-- set port 0--More-- set status disable--More-- set username ''--More-- end--More-- config system autoupdate clientoverride--More-- set address ''--More-- set status disable--More-- end--More-- config system central-management--More-- set status enable--More-- set type fortimanager--More-- set auto-backup disable--More-- set schedule-config-restore enable--More-- set schedule-script-restore enable--More-- set allow-push-configuration enable--More-- set allow-pushd-firmware enable--More-- set allow-remote-firmware-upgrade enable--More-- set allow-monitor enable--More-- set fmg ''--More-- set vdom "root"--More-- set authorized-manager-only enable--More-- unset serial-number--More-- end--More-- config application name "AIM"--More-- end--More-- config application name "ICQ"--More-- end--More-- config application name "MSN"--More-- end--More-- config application name "Yahoo"--More-- end--More-- config application name "SIMPLE"--More-- end--More-- config application name "BitTorrent"--More-- end--More-- config application name "EDonkey"--More-- end--More-- config application name "Gnutella"--More-- end--More-- config application name "KaZaa"--More-- end--More-- config application name "Skype"--More-- end--More-- config application name "WinNY"--More-- end

Page 44: N_ FortiGate 200a Configuration.txt

--More-- config application name "SIP"--More-- end--More-- config application name "SCCP"--More-- end--More-- config application name "3PC"--More-- end--More-- config application name "A.N"--More-- end--More-- config application name "AH"--More-- end--More-- config application name "ARGUS"--More-- end--More-- config application name "ARIS"--More-- end--More-- config application name "AX.25"--More-- end--More-- config application name "BBN.RCC.MON"--More-- end--More-- config application name "BNA"--More-- end--More-- config application name "BR.SAT.MON"--More-- end--More-- config application name "CBT"--More-- end--More-- config application name "CFTP"--More-- end--More-- config application name "Chaos"--More-- end--More-- config application name "Compaq.Peer"--More-- end--More-- config application name "CPHB"--More-- end--More-- config application name "CPNX"--More-- end--More-- config application name "CRTP"--More-- end--More-- config application name "CRUDP"--More-- end--More-- config application name "DCCP"--More-- end--More-- config application name "DCN.MEAS"--More-- end--More-- config application name "DDP"--More-- end--More-- config application name "DDX"--More-- end--More-- config application name "DGP"--More-- end--More-- config application name "DSR"--More-- end--More-- config application name "EGP"--More-- end--More-- config application name "EIGRP"--More-- end--More-- config application name "EMCON"--More-- end--More-- config application name "ENCAP"--More-- end--More-- config application name "ESP"--More-- end--More-- config application name "ETHERIP"

Page 45: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config application name "FC"--More-- end--More-- config application name "FIRE"--More-- end--More-- config application name "GGP"--More-- end--More-- config application name "GMTP"--More-- end--More-- config application name "GRE"--More-- end--More-- config application name "HIP"--More-- end--More-- config application name "HMP"--More-- end--More-- config application name "I.NLSP"--More-- end--More-- config application name "IATP"--More-- end--More-- config application name "ICMP"--More-- end--More-- config application name "IDPR"--More-- end--More-- config application name "IDPR.CMTP"--More-- end--More-- config application name "IDRP"--More-- end--More-- config application name "IFMP"--More-- end--More-- config application name "IGMP"--More-- end--More-- config application name "IGP"--More-- end--More-- config application name "IL"--More-- end--More-- config application name "IP.In.IP"--More-- end--More-- config application name "IP.Within.IP"--More-- end--More-- config application name "IPComp"--More-- end--More-- config application name "IPCV"--More-- end--More-- config application name "IPLT"--More-- end--More-- config application name "IPPC"--More-- end--More-- config application name "IPv6"--More-- end--More-- config application name "IPv6.Frag"--More-- end--More-- config application name "IPv6.ICMP"--More-- end--More-- config application name "IPv6.NoNxt"--More-- end--More-- config application name "IPv6.Opts"--More-- end--More-- config application name "IPv6.Route"--More-- end--More-- config application name "IPX.In.IP"--More-- end

Page 46: N_ FortiGate 200a Configuration.txt

--More-- config application name "IRTP"--More-- end--More-- config application name "ISIS.Over.IPv4"--More-- end--More-- config application name "ISO.IP"--More-- end--More-- config application name "ISO.TP4"--More-- end--More-- config application name "KRYPTOLAN"--More-- end--More-- config application name "L2TP"--More-- end--More-- config application name "LARP"--More-- end--More-- config application name "Leaf.1"--More-- end--More-- config application name "Leaf.2"--More-- end--More-- config application name "MANET"--More-- end--More-- config application name "MERIT.INP"--More-- end--More-- config application name "MFE.NSP"--More-- end--More-- config application name "MICP"--More-- end--More-- config application name "MOBILE"--More-- end--More-- config application name "Mobility.Header"--More-- end--More-- config application name "MPLS.In.IP"--More-- end--More-- config application name "MTP"--More-- end--More-- config application name "MUX"--More-- end--More-- config application name "NARP"--More-- end--More-- config application name "NETBLT"--More-- end--More-- config application name "NSFNET.IGP"--More-- end--More-- config application name "NVP.II"--More-- end--More-- config application name "OSPFIGP"--More-- end--More-- config application name "PGM"--More-- end--More-- config application name "PIM"--More-- end--More-- config application name "PIPE"--More-- end--More-- config application name "PNNI"--More-- end--More-- config application name "PRM"--More-- end--More-- config application name "PTP"--More-- end--More-- config application name "PUP"--More-- end--More-- config application name "PVP"

Page 47: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config application name "QNX"--More-- end--More-- config application name "RDP"--More-- end--More-- config application name "RSVP"--More-- end--More-- config application name "RSVP.E2E.IGNORE"--More-- end--More-- config application name "RVD"--More-- end--More-- config application name "SAT.EXPAK"--More-- end--More-- config application name "SAT.MON"--More-- end--More-- config application name "SCC.SP"--More-- end--More-- config application name "SCPS"--More-- end--More-- config application name "SCTP"--More-- end--More-- config application name "SDRP"--More-- end--More-- config application name "SECURE.VMTP"--More-- end--More-- config application name "SKIP"--More-- end--More-- config application name "SM"--More-- end--More-- config application name "SMP"--More-- end--More-- config application name "SNP"--More-- end--More-- config application name "Sprite.RPC"--More-- end--More-- config application name "SPS"--More-- end--More-- config application name "SRP"--More-- end--More-- config application name "SSCOPMCE"--More-- end--More-- config application name "ST"--More-- end--More-- config application name "STP"--More-- end--More-- config application name "SUN.ND"--More-- end--More-- config application name "SWIPE"--More-- end--More-- config application name "TCF"--More-- end--More-- config application name "TLSP"--More-- end--More-- config application name "TP++"--More-- end--More-- config application name "Trunk.1"--More-- end--More-- config application name "Trunk.2"--More-- end--More-- config application name "TTP"--More-- end

Page 48: N_ FortiGate 200a Configuration.txt

--More-- config application name "UDPLite"--More-- end--More-- config application name "UTI"--More-- end--More-- config application name "VINES"--More-- end--More-- config application name "VISA"--More-- end--More-- config application name "VMTP"--More-- end--More-- config application name "VRRP"--More-- end--More-- config application name "WB.EXPAK"--More-- end--More-- config application name "WB.MON"--More-- end--More-- config application name "WSN"--More-- end--More-- config application name "XNET"--More-- end--More-- config application name "XNS.IDP"--More-- end--More-- config application name "XTP"--More-- end--More-- config application name "DNS.Dynamic.Update"--More-- end--More-- config application name "Trin00"--More-- end--More-- config application name "Adobe.Update"--More-- end--More-- config application name "Bypass"--More-- end--More-- config application name "CA.MQ.Backup"--More-- end--More-- config application name "CrossLoop"--More-- end--More-- config application name "Download.Accelerator.Plus"--More-- end--More-- config application name "FastViewer"--More-- end--More-- config application name "Hamachi"--More-- end--More-- config application name "MS.Windows.Update"--More-- end--More-- config application name "Radmin"--More-- end--More-- config application name "Winmx"--More-- end--More-- config application name "Chikka"--More-- end--More-- config application name "Facebook.Chat"--More-- end--More-- config application name "Gadu.Gadu"--More-- end--More-- config application name "GOIM.SSL"--More-- end--More-- config application name "Google.Talk"--More-- end--More-- config application name "Jabber"--More-- end--More-- config application name "Mabber"

Page 49: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config application name "Meebo"--More-- end--More-- config application name "Meebo.File.Transfer"--More-- end--More-- config application name "MeeboMe"--More-- end--More-- config application name "MSN.Web.Messenger"--More-- end--More-- config application name "MSN2Go"--More-- end--More-- config application name "MySpace.IM"--More-- end--More-- config application name "Rediff.Messenger"--More-- end--More-- config application name "Yahoo.Mail.Messenger"--More-- end--More-- config application name "Yahoo.Web.Messenger"--More-- end--More-- config application name "IRC.Communication"--More-- end--More-- config application name "Ammyy.Admin"--More-- end--More-- config application name "AURP"--More-- end--More-- config application name "Back.Orifice"--More-- end--More-- config application name "BOOTP"--More-- end--More-- config application name "DHCP"--More-- end--More-- config application name "DNS"--More-- end--More-- config application name "Finger"--More-- end--More-- config application name "Google.Web.Talk"--More-- end--More-- config application name "Gopher"--More-- end--More-- config application name "H.323"--More-- end--More-- config application name "Helix.Community"--More-- end--More-- config application name "HSRP"--More-- end--More-- config application name "ICY.Radio.Streaming"--More-- end--More-- config application name "IPP"--More-- end--More-- config application name "JavaRMI.Call"--More-- end--More-- config application name "JavaRMI.Registry"--More-- end--More-- config application name "JavaRMI.Stream"--More-- end--More-- config application name "Kerberos"--More-- end--More-- config application name "LDP"--More-- end--More-- config application name "LMP"--More-- end

Page 50: N_ FortiGate 200a Configuration.txt

--More-- config application name "LPR"--More-- end--More-- config application name "Meevee"--More-- end--More-- config application name "Metacafe"--More-- end--More-- config application name "MMS"--More-- end--More-- config application name "MSDP"--More-- end--More-- config application name "Nagios"--More-- end--More-- config application name "NBSS"--More-- end--More-- config application name "Netbotz"--More-- end--More-- config application name "NFS"--More-- end--More-- config application name "NNTP"--More-- end--More-- config application name "NNTP.SSL"--More-- end--More-- config application name "Ntalk"--More-- end--More-- config application name "NTP"--More-- end--More-- config application name "Ooyala"--More-- end--More-- config application name "Photobucket"--More-- end--More-- config application name "Portmapper"--More-- end--More-- config application name "PPTP"--More-- end--More-- config application name "RAP"--More-- end--More-- config application name "RDT"--More-- end--More-- config application name "RIP"--More-- end--More-- config application name "RLP"--More-- end--More-- config application name "RPC"--More-- end--More-- config application name "RTMP"--More-- end--More-- config application name "SLP"--More-- end--More-- config application name "Soulseek"--More-- end--More-- config application name "Stream.Media"--More-- end--More-- config application name "SYSLOG"--More-- end--More-- config application name "SYSTAT"--More-- end--More-- config application name "TFN"--More-- end--More-- config application name "TFTP"--More-- end--More-- config application name "UUCP"

Page 51: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config application name "WHOIS"--More-- end--More-- config application name "MS.FRSAPI.Map"--More-- end--More-- config application name "Ares"--More-- end--More-- config application name "Applejuice"--More-- end--More-- config application name "CMP.HTTP"--More-- end--More-- config application name "iTunes.File.Sharing"--More-- end--More-- config application name "Kazaa.GET"--More-- end--More-- config application name "PP"--More-- end--More-- config application name "QQlive"--More-- end--More-- config application name "Share"--More-- end--More-- config application name "Sopcast"--More-- end--More-- config application name "Spotify"--More-- end--More-- config application name "Teamviewer"--More-- end--More-- config application name "Thunder"--More-- end--More-- config application name "TVUPlayer"--More-- end--More-- config application name "Xunlei.Kankan"--More-- end--More-- config application name "9PFS"--More-- end--More-- config application name "Atom.Publishing.Protocol"--More-- end--More-- config application name "Bing.Safe.Search.Off"--More-- end--More-- config application name "CMP.TCP"--More-- end--More-- config application name "COPS"--More-- end--More-- config application name "Google.Safe.Search.Off"--More-- end--More-- config application name "Google.Safe.Search.Moderate.Level"--More-- end--More-- config application name "Google.Web.Accelerator"--More-- end--More-- config application name "ISCSI"--More-- end--More-- config application name "MS.RDP.Request"--More-- end--More-- config application name "PacketiX"--More-- end--More-- config application name "SoftEther"--More-- end--More-- config application name "TACACS"--More-- end--More-- config application name "TACACS+"

Page 52: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config application name "Tor"--More-- end--More-- config application name "VNC"--More-- end--More-- config application name "Yahoo.Safe.Search.Moderate.Level"--More-- end--More-- config application name "Yahoo.Safe.Search.Off"--More-- end--More-- config application name "Rstatd.Information"--More-- end--More-- config application name "Rusers"--More-- end--More-- config application name "DNP3"--More-- end--More-- config application name "DNP3.Read"--More-- end--More-- config application name "DNP3.Write"--More-- end--More-- config application name "ICCP"--More-- end--More-- config application name "Modbus"--More-- end--More-- config application name "Snmp.Monitor"--More-- end--More-- config application name "Snmp.Trap"--More-- end--More-- config application name "MSN.Toolbar"--More-- end--More-- config application name "Rakuten.Toolbar"--More-- end--More-- config application name "Blackboard"--More-- end--More-- config application name "CDDB.Freedb.Search"--More-- end--More-- config application name "CDDB.Gracenote.Search"--More-- end--More-- config application name "CDDB.Musicbrainz.Search"--More-- end--More-- config application name "Filedropper"--More-- end--More-- config application name "Fona"--More-- end--More-- config application name "Gotomeeting"--More-- end--More-- config application name "Gotomypc"--More-- end--More-- config application name "Habbo"--More-- end--More-- config application name "Hotmail"--More-- end--More-- config application name "HTTP.Compress"--More-- end--More-- config application name "HTTP.Flash"--More-- end--More-- config application name "HTTP.MSOffice"--More-- end--More-- config application name "HTTP.NTLM"--More-- end--More-- config application name "HTTP.Stream"

Page 53: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config application name "HTTP.XML"--More-- end--More-- config application name "Mediamax"--More-- end--More-- config application name "Megaproxy"--More-- end--More-- config application name "Megaupload"--More-- end--More-- config application name "Messengerfx"--More-- end--More-- config application name "Moinmoin"--More-- end--More-- config application name "Morningstar"--More-- end--More-- config application name "Motleyfool"--More-- end--More-- config application name "Movenetworks"--More-- end--More-- config application name "MSN.Money"--More-- end--More-- config application name "Netspoke"--More-- end--More-- config application name "Noteworthy"--More-- end--More-- config application name "Octopz"--More-- end--More-- config application name "Omnidrive"--More-- end--More-- config application name "Openomy"--More-- end--More-- config application name "Optimum"--More-- end--More-- config application name "Orb"--More-- end--More-- config application name "Pandora"--More-- end--More-- config application name "Pbwiki"--More-- end--More-- config application name "Pogo"--More-- end--More-- config application name "Pokerstars"--More-- end--More-- config application name "Proxono"--More-- end--More-- config application name "Radiusim"--More-- end--More-- config application name "Ragingbull"--More-- end--More-- config application name "Sina.Webmail"--More-- end--More-- config application name "Sling"--More-- end--More-- config application name "Youtube.Video.Embedded"--More-- end--More-- config application name "Apache"--More-- end--More-- config application name "Citrix"--More-- end--More-- config application name "Apple.Store"--More-- end

Page 54: N_ FortiGate 200a Configuration.txt

--More-- config application name "DRDA"--More-- end--More-- config application name "Filemaker"--More-- end--More-- config application name "GDS.DB"--More-- end--More-- config application name "MaxDB"--More-- end--More-- config application name "MSSQL"--More-- end--More-- config application name "MySQL"--More-- end--More-- config application name "Postgres"--More-- end--More-- config application name "Facebook"--More-- end--More-- config application name "Gmail"--More-- end--More-- config application name "Hotmail.Attachment"--More-- end--More-- config application name "Mail.Com"--More-- end--More-- config application name "QQ.Mail"--More-- end--More-- config application name "Yahoo.Mail.Attachment"--More-- end--More-- config application name "Zoho.Mail"--More-- end--More-- config application name "Serv.U"--More-- end--More-- config application name "Vsftpd"--More-- end--More-- config application name "WS.FTP"--More-- end--More-- config application name "LogMeIn"--More-- end--More-- config application name "RemotelyAnywhere"--More-- end--More-- config application name "Telnet"--More-- end--More-- config application name "Unyte"--More-- end--More-- config application name "Webot"--More-- end--More-- config application name "X11"--More-- end--More-- config application name "XDMCP"--More-- end--More-- config application name "Yoics"--More-- end--More-- config application name "Gizmo"--More-- end--More-- config application name "HeadCall"--More-- end--More-- config application name "IAX2"--More-- end--More-- config application name "Jajah"--More-- end--More-- config application name "Sightspeed"--More-- end--More-- config application name "Teltel"

Page 55: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config application name "Voipstunt.Webphone"--More-- end--More-- config application name "126.Mail"--More-- end--More-- config application name "163.Alumni"--More-- end--More-- config application name "163.BBS"--More-- end--More-- config application name "18900.Com"--More-- end--More-- config application name "250.Eu"--More-- end--More-- config application name "2ch"--More-- end--More-- config application name "2ch.Posting"--More-- end--More-- config application name "360buy"--More-- end--More-- config application name "360quan"--More-- end--More-- config application name "4shared"--More-- end--More-- config application name "51.Com"--More-- end--More-- config application name "5460.Net"--More-- end--More-- config application name "6cn"--More-- end--More-- config application name "800buy"--More-- end--More-- config application name "Adobe.Connect"--More-- end--More-- config application name "AIM.Express"--More-- end--More-- config application name "AirAIM"--More-- end--More-- config application name "Alibaba"--More-- end--More-- config application name "Alitalk"--More-- end--More-- config application name "Amazon"--More-- end--More-- config application name "Anon.Me"--More-- end--More-- config application name "Anonr.Com"--More-- end--More-- config application name "AOL.Member.Search"--More-- end--More-- config application name "AOL.Messageboard.Posting"--More-- end--More-- config application name "AOL.Safe.Search.Off"--More-- end--More-- config application name "Armyproxy.Com"--More-- end--More-- config application name "Ask.Safe.Search.Off"--More-- end--More-- config application name "Asproxy"--More-- end--More-- config application name "Avoidr"--More-- end

Page 56: N_ FortiGate 200a Configuration.txt

--More-- config application name "Backpack"--More-- end--More-- config application name "Baidu.Hi"--More-- end--More-- config application name "Baidu.Tieba"--More-- end--More-- config application name "Barafranca.Webgame"--More-- end--More-- config application name "BBC.Iplayer"--More-- end--More-- config application name "Bearbuy"--More-- end--More-- config application name "Bebo"--More-- end--More-- config application name "Beinsync"--More-- end--More-- config application name "Blog.Posting"--More-- end--More-- config application name "Blogger.Blog.Posting"--More-- end--More-- config application name "Blokus"--More-- end--More-- config application name "Boratproxy.Com"--More-- end--More-- config application name "Boxnet"--More-- end--More-- config application name "Break"--More-- end--More-- config application name "Browse.Ms"--More-- end--More-- config application name "Bugzilla"--More-- end--More-- config application name "Bulfleet.Webgame"--More-- end--More-- config application name "Campfire"--More-- end--More-- config application name "Cantbustme.Com"--More-- end--More-- config application name "Carbonite"--More-- end--More-- config application name "Cat898.BBS"--More-- end--More-- config application name "Centric.CRM"--More-- end--More-- config application name "CGIProxy"--More-- end--More-- config application name "Chinaren"--More-- end--More-- config application name "Chinaren.Class"--More-- end--More-- config application name "Chosenspace.Webgame"--More-- end--More-- config application name "Circumventor"--More-- end--More-- config application name "Clarizen"--More-- end--More-- config application name "Classmates"--More-- end--More-- config application name "Clearspace"--More-- end--More-- config application name "Clubbox"

Page 57: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config application name "Cnxp.BBS"--More-- end--More-- config application name "Comcast.Webmail"--More-- end--More-- config application name "Coralcdn"--More-- end--More-- config application name "Cox.Webmail"--More-- end--More-- config application name "Criminal.Webgame"--More-- end--More-- config application name "Cuil.Safe.Search.Off"--More-- end--More-- config application name "Cyworld"--More-- end--More-- config application name "D1"--More-- end--More-- config application name "Dabble.DB"--More-- end--More-- config application name "Dailymotion"--More-- end--More-- config application name "Dangdang"--More-- end--More-- config application name "Deezer"--More-- end--More-- config application name "Depositfiles"--More-- end--More-- config application name "Desktoptwo"--More-- end--More-- config application name "Diino"--More-- end--More-- config application name "Docstoc"--More-- end--More-- config application name "Doodle"--More-- end--More-- config application name "Doof"--More-- end--More-- config application name "Doshow"--More-- end--More-- config application name "Drop.IO"--More-- end--More-- config application name "Dropboks"--More-- end--More-- config application name "Dynamic.Intranet"--More-- end--More-- config application name "Eachnet"--More-- end--More-- config application name "Earthcam"--More-- end--More-- config application name "Eatlime"--More-- end--More-- config application name "Ebay"--More-- end--More-- config application name "Ebuddy"--More-- end--More-- config application name "EditGrid"--More-- end--More-- config application name "Eiq.Sec.Analyzer"--More-- end--More-- config application name "Elluminate"--More-- end

Page 58: N_ FortiGate 200a Configuration.txt

--More-- config application name "Envy.Webgame"--More-- end--More-- config application name "ePeachtree"--More-- end--More-- config application name "Eroom.Net"--More-- end--More-- config application name "Esnips"--More-- end--More-- config application name "Excite.Webmail"--More-- end--More-- config application name "Eyejot"--More-- end--More-- config application name "Fastmail.FM"--More-- end--More-- config application name "FastTV"--More-- end--More-- config application name "Fc2.Blog"--More-- end--More-- config application name "Feidian"--More-- end--More-- config application name "Fenxijia"--More-- end--More-- config application name "FiveTV"--More-- end--More-- config application name "Flickr"--More-- end--More-- config application name "Flixster"--More-- end--More-- config application name "Foldershare"--More-- end--More-- config application name "Foonz"--More-- end--More-- config application name "Freecast"--More-- end--More-- config application name "Friendfeed"--More-- end--More-- config application name "Friendster"--More-- end--More-- config application name "Friendvox"--More-- end--More-- config application name "G.ho.st"--More-- end--More-- config application name "Glide"--More-- end--More-- config application name "Glype.Proxy"--More-- end--More-- config application name "Gogobox"--More-- end--More-- config application name "GOM.TV"--More-- end--More-- config application name "Goo.Webmail"--More-- end--More-- config application name "Google.Analytics"--More-- end--More-- config application name "Google.Calendar"--More-- end--More-- config application name "Google.Docs"--More-- end--More-- config application name "Google.Finance"--More-- end--More-- config application name "Google.Lively"

Page 59: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config application name "Google.Picasa.Update"--More-- end--More-- config application name "Google.Sites"--More-- end--More-- config application name "Gougou"--More-- end--More-- config application name "Hainei"--More-- end--More-- config application name "Hi5"--More-- end--More-- config application name "Hidemy.Info"--More-- end--More-- config application name "Hidemyass.Com"--More-- end--More-- config application name "Horde.Webmail"--More-- end--More-- config application name "Hotmail.Web.Messenger"--More-- end--More-- config application name "Howardforums"--More-- end--More-- config application name "HTTP.EXE"--More-- end--More-- config application name "HTTP.Script"--More-- end--More-- config application name "Hulu"--More-- end--More-- config application name "Hushmail"--More-- end--More-- config application name "Ibackup"--More-- end--More-- config application name "ICQ2go"--More-- end--More-- config application name "Ilohamail"--More-- end--More-- config application name "Iloveim"--More-- end--More-- config application name "Imeem"--More-- end--More-- config application name "Imhaha"--More-- end--More-- config application name "Infoseek.Webmail"--More-- end--More-- config application name "Invisiblesurfing.Com"--More-- end--More-- config application name "iTunes"--More-- end--More-- config application name "ITVPlayer"--More-- end--More-- config application name "Jaspersoft"--More-- end--More-- config application name "Jiayuan"--More-- end--More-- config application name "Jira"--More-- end--More-- config application name "Jubii"--More-- end--More-- config application name "JumpTV"--More-- end--More-- config application name "Justin.TV"--More-- end

Page 60: N_ FortiGate 200a Configuration.txt

--More-- config application name "Kaixin001"--More-- end--More-- config application name "Khanwars.Webgame"--More-- end--More-- config application name "Koolim"--More-- end--More-- config application name "Kproxy"--More-- end--More-- config application name "Kroxy.Net"--More-- end--More-- config application name "Ku6"--More-- end--More-- config application name "Land.of.Vikings.Webgame"--More-- end--More-- config application name "Last.FM"--More-- end--More-- config application name "Limelight"--More-- end--More-- config application name "Limitkiller.Com"--More-- end--More-- config application name "Linkedin"--More-- end--More-- config application name "Livedoor.Webmail"--More-- end--More-- config application name "Livejournal"--More-- end--More-- config application name "Mafia.Webgame"--More-- end--More-- config application name "Mail.Ru"--More-- end--More-- config application name "Mediafire"--More-- end--More-- config application name "Megavideo"--More-- end--More-- config application name "MeteorNetTV"--More-- end--More-- config application name "Mixi"--More-- end--More-- config application name "Mofile"--More-- end--More-- config application name "Mop.DZH"--More-- end--More-- config application name "Mozy"--More-- end--More-- config application name "MS.Live.Spaces"--More-- end--More-- config application name "Mysee"--More-- end--More-- config application name "Myspace"--More-- end--More-- config application name "Myspace.CN"--More-- end--More-- config application name "Netease.Webmail"--More-- end--More-- config application name "Netlog"--More-- end--More-- config application name "Newegg"--More-- end--More-- config application name "Newsstand"--More-- end--More-- config application name "Nico.Nico.Douga"

Page 61: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config application name "Niwota"--More-- end--More-- config application name "Nokia.PC.Suite.Update"--More-- end--More-- config application name "Nuip.Net"--More-- end--More-- config application name "Office.Live"--More-- end--More-- config application name "Olympicproxy.Com"--More-- end--More-- config application name "Optionsxpress"--More-- end--More-- config application name "Orkut"--More-- end--More-- config application name "Ourproxy.Com"--More-- end--More-- config application name "Paipai"--More-- end--More-- config application name "Pcpop.BBS"--More-- end--More-- config application name "Pdbox"--More-- end--More-- config application name "People.BBS"--More-- end--More-- config application name "Perfspot"--More-- end--More-- config application name "PHProxy"--More-- end--More-- config application name "Privax"--More-- end--More-- config application name "Proxybuddy.Com"--More-- end--More-- config application name "Proxymafia.Net"--More-- end--More-- config application name "Proxystart.Com"--More-- end--More-- config application name "Qianlong.BBS"--More-- end--More-- config application name "QQ.BBS"--More-- end--More-- config application name "QQ.City"--More-- end--More-- config application name "QQ.Jiaoyou"--More-- end--More-- config application name "QQ.TV"--More-- end--More-- config application name "QQ.Video"--More-- end--More-- config application name "Rednet.BBS"--More-- end--More-- config application name "Reunion"--More-- end--More-- config application name "Rutube"--More-- end--More-- config application name "Samuraioflegend.Webgame"--More-- end--More-- config application name "Schwab"--More-- end--More-- config application name "Scottrade"--More-- end

Page 62: N_ FortiGate 200a Configuration.txt

--More-- config application name "Sina.BBS"--More-- end--More-- config application name "Sina.Video"--More-- end--More-- config application name "Sina.WebTV"--More-- end--More-- config application name "SinaTV"--More-- end--More-- config application name "Sitesurf.Net"--More-- end--More-- config application name "Skyrock"--More-- end--More-- config application name "Sohu.Club"--More-- end--More-- config application name "Sohu.TV"--More-- end--More-- config application name "Sosbackup"--More-- end--More-- config application name "Stock.Zqzx"--More-- end--More-- config application name "Supei"--More-- end--More-- config application name "Symantec.AV.Update"--More-- end--More-- config application name "Tagoo"--More-- end--More-- config application name "Taobao"--More-- end--More-- config application name "Tdameritrade"--More-- end--More-- config application name "Techinline"--More-- end--More-- config application name "Texasproxy.Com"--More-- end--More-- config application name "Thinkorswim"--More-- end--More-- config application name "Tianya.BBS"--More-- end--More-- config application name "Tiexue.BBS"--More-- end--More-- config application name "Tom.BBS"--More-- end--More-- config application name "Totorosa"--More-- end--More-- config application name "Tudou"--More-- end--More-- config application name "Tvtonic"--More-- end--More-- config application name "Twig"--More-- end--More-- config application name "Tycoon.Webgame"--More-- end--More-- config application name "Unblock.Biz"--More-- end--More-- config application name "Unblocked.Org"--More-- end--More-- config application name "URL.Sc"--More-- end--More-- config application name "Usermin"--More-- end--More-- config application name "Veoh"

Page 63: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config application name "Verycd"--More-- end--More-- config application name "Viadeo"--More-- end--More-- config application name "Voc.BBS"--More-- end--More-- config application name "WebDAV"--More-- end--More-- config application name "WebQQ"--More-- end--More-- config application name "Webshots"--More-- end--More-- config application name "Wikidot"--More-- end--More-- config application name "Wikipedia.Editing"--More-- end--More-- config application name "WinMedia"--More-- end--More-- config application name "Wrestling.Webgame"--More-- end--More-- config application name "Xcar.BBS"--More-- end--More-- config application name "Xiaonei"--More-- end--More-- config application name "Xici.Net"--More-- end--More-- config application name "Xilu.BBS"--More-- end--More-- config application name "Xing"--More-- end--More-- config application name "Xinhuanet.Forum"--More-- end--More-- config application name "Yahoo.Douga"--More-- end--More-- config application name "Yahoo.Video"--More-- end--More-- config application name "Yahoo.Webmail"--More-- end--More-- config application name "Yeeyoo"--More-- end--More-- config application name "Youa"--More-- end--More-- config application name "Youku"--More-- end--More-- config application name "Youporn"--More-- end--More-- config application name "Zhanzuo"--More-- end--More-- config application name "Zhinanzhen" --More-- end--More-- config application name "Zimbra"--More-- end--More-- config application name "Facebook.Video"--More-- end--More-- config application name "Mogulus"--More-- end--More-- config application name "Ragnarok.Online"--More-- end--More-- config application name "WebEx"

Page 64: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config application name "100Bao"--More-- end--More-- config application name "360safe.Update"--More-- end--More-- config application name "55bbs"--More-- end--More-- config application name "ABC.Streaming"--More-- end--More-- config application name "Adobe.Flash.Proxy.Auto.Discovery"--More-- end--More-- config application name "Adobe.MediaPlayer"--More-- end--More-- config application name "AIM.Game"--More-- end--More-- config application name "AIM.Webmail"--More-- end--More-- config application name "AIRadio"--More-- end--More-- config application name "Alexa.Toolbar"--More-- end--More-- config application name "ALYac"--More-- end--More-- config application name "ALZip"--More-- end--More-- config application name "AOL.Toolbar"--More-- end--More-- config application name "APC.Powerchute"--More-- end--More-- config application name "Apple.MacOS.Update"--More-- end--More-- config application name "APT"--More-- end--More-- config application name "Ares.Chat.Join"--More-- end--More-- config application name "Audiogalaxy.Rhapsody"--More-- end--More-- config application name "Autobahn.Accelerator"--More-- end--More-- config application name "AVG.Update"--More-- end--More-- config application name "Babelgum"--More-- end--More-- config application name "Backup.Exec"--More-- end--More-- config application name "Baofeng"--More-- end--More-- config application name "BBSee"--More-- end--More-- config application name "BF.Game"--More-- end--More-- config application name "BGP"--More-- end--More-- config application name "Big.Brother"--More-- end--More-- config application name "BitDefender.Update"--More-- end--More-- config application name "Blinkx.Video.Search"--More-- end--More-- config application name "Blubster"

Page 65: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config application name "BnB"--More-- end--More-- config application name "Bnbpopo"--More-- end--More-- config application name "BOINC"--More-- end--More-- config application name "BomberClone"--More-- end--More-- config application name "Buddy.Buddy"--More-- end--More-- config application name "Camfrog.Login"--More-- end--More-- config application name "CBS.Stream"--More-- end--More-- config application name "CCTV.Box"--More-- end--More-- config application name "Chargen"--More-- end--More-- config application name "ChiBi"--More-- end--More-- config application name "Chikka.Web"--More-- end--More-- config application name "Chinagames"--More-- end--More-- config application name "Chrome.Update"--More-- end--More-- config application name "Conquer"--More-- end--More-- config application name "CORBA"--More-- end--More-- config application name "Craigspal"--More-- end--More-- config application name "Cups"--More-- end--More-- config application name "CVS"--More-- end--More-- config application name "Dark.Age.Of.Camelot"--More-- end--More-- config application name "Daum.Touch"--More-- end--More-- config application name "Daytime"--More-- end--More-- config application name "Dazhihui"--More-- end--More-- config application name "DB2"--More-- end--More-- config application name "Dealio.Toolbar"--More-- end--More-- config application name "Dhxy"--More-- end--More-- config application name "Dict.Cn"--More-- end--More-- config application name "Dimdim"--More-- end--More-- config application name "Discard"--More-- end--More-- config application name "Distcc"--More-- end--More-- config application name "DLS"--More-- end

Page 66: N_ FortiGate 200a Configuration.txt

--More-- config application name "DLS.RPN"--More-- end--More-- config application name "DLS.WPN"--More-- end--More-- config application name "Duba.Update"--More-- end--More-- config application name "DuDu.Download.Accelerator"--More-- end--More-- config application name "eBay.Desktop"--More-- end--More-- config application name "EBay.Toolbar"--More-- end--More-- config application name "Echo"--More-- end--More-- config application name "ESPN.Toolbar"--More-- end--More-- config application name "Everyzing.Video.Search"--More-- end--More-- config application name "Ezpeer"--More-- end--More-- config application name "Feedreader"--More-- end--More-- config application name "Fetion"--More-- end--More-- config application name "FileGuri"--More-- end--More-- config application name "Filemaker.Web.Publishing"--More-- end--More-- config application name "Firefox.Update"--More-- end--More-- config application name "Fluxiom"--More-- end--More-- config application name "Folding.At.Home"--More-- end--More-- config application name "Fsjoy"--More-- end--More-- config application name "FTP"--More-- end--More-- config application name "FTP.Data"--More-- end--More-- config application name "Funshion"--More-- end--More-- config application name "Furthurnet"--More-- end--More-- config application name "Gabbly"--More-- end--More-- config application name "Ghostsurf"--More-- end--More-- config application name "Gizmoz.Edit"--More-- end--More-- config application name "Gkrellm"--More-- end--More-- config application name "GMX.Webmail"--More-- end--More-- config application name "GNUnet"--More-- end--More-- config application name "Goboogy"--More-- end--More-- config application name "GOM.Player"--More-- end--More-- config application name "Google.Desktop"

Page 67: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config application name "Google.Earth"--More-- end--More-- config application name "Google.Groups"--More-- end--More-- config application name "Google.Picasa.Upload"--More-- end--More-- config application name "Google.Toolbar"--More-- end--More-- config application name "Google.Video.Search"--More-- end--More-- config application name "Guotaijunan.Dazhihui"--More-- end--More-- config application name "H.245"--More-- end--More-- config application name "H.323.Call.Setup"--More-- end--More-- config application name "Haofang"--More-- end--More-- config application name "Hexungudao"--More-- end--More-- config application name "Hobowars"--More-- end--More-- config application name "Hopster"--More-- end--More-- config application name "Hotline"--More-- end--More-- config application name "Hotspot"--More-- end--More-- config application name "HP.Storage.Mirroring.BroadCast"--More-- end--More-- config application name "HP.Storage.Mirroring.Control"--More-- end--More-- config application name "HTTP.Audio"--More-- end--More-- config application name "HTTP.BROWSER"--More-- end--More-- config application name "HTTP.HTML"--More-- end--More-- config application name "HTTP.Image"--More-- end--More-- config application name "HTTP.PDF"--More-- end--More-- config application name "HTTP.Resume.Download"--More-- end--More-- config application name "HTTP.Tunnel"--More-- end--More-- config application name "HTTP.Video"--More-- end--More-- config application name "Huaanzhengquan"--More-- end--More-- config application name "IBM.Lotus.Notes"--More-- end--More-- config application name "IBM.Tivoli.Storage.Manager"--More-- end--More-- config application name "Identd"--More-- end--More-- config application name "IMAP"

Page 68: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config application name "Imvu"--More-- end--More-- config application name "InstallAnywhere.Update"--More-- end--More-- config application name "Instan.T"--More-- end--More-- config application name "ISAKMP"--More-- end--More-- config application name "iTunes.BroadCast"--More-- end--More-- config application name "iTunes.iMix"--More-- end--More-- config application name "iTunes.mDNS"--More-- end--More-- config application name "iTunes.Podcast"--More-- end--More-- config application name "iTunes.Store"--More-- end--More-- config application name "iTunes.Update"--More-- end--More-- config application name "Jap"--More-- end--More-- config application name "Jianghaizhengquan"--More-- end--More-- config application name "JibJab"--More-- end--More-- config application name "JinWuTuan"--More-- end--More-- config application name "Joost"--More-- end--More-- config application name "JuRen"--More-- end--More-- config application name "JX.Web.Game"--More-- end--More-- config application name "Kadmin"--More-- end--More-- config application name "Kaillera.Server"--More-- end--More-- config application name "Kaspersky.Update"--More-- end--More-- config application name "KKBox"--More-- end--More-- config application name "Klogind"--More-- end--More-- config application name "KnightOnline"--More-- end--More-- config application name "Konspire2b"--More-- end--More-- config application name "Kpasswd"--More-- end--More-- config application name "Krlogin"--More-- end--More-- config application name "Kshd"--More-- end--More-- config application name "Kugoo"--More-- end--More-- config application name "Lava.Lava"--More-- end--More-- config application name "LDAP"--More-- end

Page 69: N_ FortiGate 200a Configuration.txt

--More-- config application name "LittleFighter"--More-- end--More-- config application name "Live.Search"--More-- end--More-- config application name "Live365"--More-- end--More-- config application name "LoginAny"--More-- end--More-- config application name "LPD"--More-- end--More-- config application name "Manolito"--More-- end--More-- config application name "Mcafee.SiteAdvisor"--More-- end--More-- config application name "Meabox"--More-- end--More-- config application name "MECA.Messenger"--More-- end--More-- config application name "MECA.Messenger.Recv.File"--More-- end--More-- config application name "MECA.Messenger.Recv.Message"--More-- end--More-- config application name "MECA.Messenger.Send.File"--More-- end--More-- config application name "MECA.Messenger.Send.Message"--More-- end--More-- config application name "Media.Player.Audio.HTTP"--More-- end--More-- config application name "Media.Player.RTP"--More-- end--More-- config application name "Media.Player.Video.HTTP"--More-- end--More-- config application name "Meebo.Repeater"--More-- end--More-- config application name "Meeting.Maker"--More-- end--More-- config application name "MGCP"--More-- end--More-- config application name "MIR2.Chuanqi"--More-- end--More-- config application name "Miro"--More-- end--More-- config application name "Mobile.IP"--More-- end--More-- config application name "Mount"--More-- end--More-- config application name "MoYu"--More-- end--More-- config application name "MS.ASF"--More-- end--More-- config application name "MS.DTC"--More-- end--More-- config application name "MS.IIS"--More-- end--More-- config application name "MS.NetSend"--More-- end--More-- config application name "MS.Scheduler"--More-- end--More-- config application name "MSN.Game"

Page 70: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config application name "MSN.Groups"--More-- end--More-- config application name "MSN.Messenger.Video"--More-- end--More-- config application name "MSN.Virtual.Earth.3D"--More-- end--More-- config application name "MSRPC"--More-- end--More-- config application name "Mute"--More-- end--More-- config application name "MySpace.Video"--More-- end--More-- config application name "NamiPan.Login"--More-- end--More-- config application name "Namipan.Upload.With.Web"--More-- end--More-- config application name "NamiRobot.Download"--More-- end--More-- config application name "NamiRobot.Upload"--More-- end--More-- config application name "NateOn"--More-- end--More-- config application name "NDMP"--More-- end--More-- config application name "Neokast"--More-- end--More-- config application name "Net2phone"--More-- end--More-- config application name "Net2Phone.Control"--More-- end--More-- config application name "Net2Phone.Data"--More-- end--More-- config application name "NetBIOS.Name.Service"--More-- end--More-- config application name "NetEase.POPO"--More-- end--More-- config application name "Netmeeting"--More-- end--More-- config application name "Netviewer"--More-- end--More-- config application name "NOD32.Update"--More-- end--More-- config application name "Norton.AV.Broadcast"--More-- end--More-- config application name "NPR.Radio"--More-- end--More-- config application name "Oovoo"--More-- end--More-- config application name "OpenVPN.Connect"--More-- end--More-- config application name "Opera.Update"--More-- end--More-- config application name "Oracle"--More-- end--More-- config application name "Ourgame"--More-- end--More-- config application name "Paltalk"--More-- end--More-- config application name "Pando"--More-- end

Page 71: N_ FortiGate 200a Configuration.txt

--More-- config application name "PCAnywhere"--More-- end--More-- config application name "Peercast"--More-- end--More-- config application name "Perforce"--More-- end--More-- config application name "Pichat"--More-- end--More-- config application name "Pingfu"--More-- end--More-- config application name "Pixsy.Image.Search"--More-- end--More-- config application name "Poco"--More-- end--More-- config application name "POP3"--More-- end--More-- config application name "PopKart"--More-- end--More-- config application name "Popogame"--More-- end--More-- config application name "PPLive"--More-- end--More-- config application name "PPMate"--More-- end--More-- config application name "PPStream"--More-- end--More-- config application name "Pruna"--More-- end--More-- config application name "Qianlong"--More-- end--More-- config application name "QQ.Download"--More-- end--More-- config application name "QQ.Games"--More-- end--More-- config application name "QQ.Speed"--More-- end--More-- config application name "Quake"--More-- end--More-- config application name "Quicktime"--More-- end--More-- config application name "QVoD"--More-- end--More-- config application name "R.Exec"--More-- end--More-- config application name "R.Services"--More-- end--More-- config application name "Radio.Netscape"--More-- end--More-- config application name "RADIUS"--More-- end--More-- config application name "RapidShare"--More-- end--More-- config application name "Rayfile"--More-- end--More-- config application name "Raysource"--More-- end--More-- config application name "Razor"--More-- end--More-- config application name "RC5DES"--More-- end--More-- config application name "Real.GameHall"

Page 72: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config application name "Real.RDT.TCP"--More-- end--More-- config application name "Real.RDT.UDP"--More-- end--More-- config application name "Real.RTP.TCP"--More-- end--More-- config application name "Real.RTP.UDP"--More-- end--More-- config application name "Real.Update"--More-- end--More-- config application name "RealLink.Login"--More-- end--More-- config application name "RealPlayer"--More-- end--More-- config application name "RealPlayer.Stream"--More-- end--More-- config application name "Revver"--More-- end--More-- config application name "Rising.Update"--More-- end--More-- config application name "Roundcube.Webmail"--More-- end--More-- config application name "Rss"--More-- end--More-- config application name "Rsync"--More-- end--More-- config application name "RTMPT"--More-- end--More-- config application name "RTSP"--More-- end--More-- config application name "Ruckus"--More-- end--More-- config application name "RuneScape"--More-- end--More-- config application name "Rwho"--More-- end--More-- config application name "Rxjh"--More-- end--More-- config application name "SageTV.Locator"--More-- end--More-- config application name "SageTV.Placeshifter"--More-- end--More-- config application name "SageTV.Stream"--More-- end--More-- config application name "Salesforce"--More-- end--More-- config application name "Scour.Search"--More-- end--More-- config application name "Second.Life"--More-- end--More-- config application name "Secureserver.Mail"--More-- end--More-- config application name "Sendspace"--More-- end--More-- config application name "Shanda.Gametea"--More-- end--More-- config application name "Sharepoint"--More-- end--More-- config application name "Sharepoint.Blog.Posting"--More-- end

Page 73: N_ FortiGate 200a Configuration.txt

--More-- config application name "Sharepoint.Calendar"--More-- end--More-- config application name "Sharepoint.Documents"--More-- end--More-- config application name "Sharepoint.Wiki"--More-- end--More-- config application name "Silverlight"--More-- end--More-- config application name "Sina.Game"--More-- end--More-- config application name "Sina.UC"--More-- end--More-- config application name "Sina.UT"--More-- end--More-- config application name "SIP.TCP"--More-- end--More-- config application name "SIP.UDP"--More-- end--More-- config application name "SMTP"--More-- end--More-- config application name "SOAP"--More-- end--More-- config application name "Socialtext.Editing"--More-- end--More-- config application name "Socialtv"--More-- end--More-- config application name "Sohu.Game"--More-- end--More-- config application name "Sohu.SOQ"--More-- end--More-- config application name "Sophos.Update"--More-- end--More-- config application name "Soribada"--More-- end--More-- config application name "Spark"--More-- end--More-- config application name "Special.Force"--More-- end--More-- config application name "SquirrelMail"--More-- end--More-- config application name "SSH"--More-- end--More-- config application name "SSL"--More-- end--More-- config application name "SSL.Shell"--More-- end--More-- config application name "Starcraft.Broodwar"--More-- end--More-- config application name "Steam"--More-- end--More-- config application name "Stickam"--More-- end--More-- config application name "Stream.Works"--More-- end--More-- config application name "Streamaudio"--More-- end--More-- config application name "Street.Basketball"--More-- end--More-- config application name "Stumbleupon.Toolbar"--More-- end--More-- config application name "STUN"

Page 74: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config application name "SubSpace"--More-- end--More-- config application name "Subversion"--More-- end--More-- config application name "SugarCRM"--More-- end--More-- config application name "Surrogafier"--More-- end--More-- config application name "Sybase"--More-- end--More-- config application name "Symantec.Syst.Center"--More-- end--More-- config application name "T.38.SIP.INVITE"--More-- end--More-- config application name "Taobao.Aliww"--More-- end--More-- config application name "TeamSpeak"--More-- end--More-- config application name "Teredo"--More-- end--More-- config application name "Thinkfree"--More-- end--More-- config application name "TianLongBaBu"--More-- end--More-- config application name "Tibia"--More-- end--More-- config application name "Tikiwiki.Editing"--More-- end--More-- config application name "Time"--More-- end--More-- config application name "Tokbox"--More-- end--More-- config application name "Tongdaxin"--More-- end--More-- config application name "Tonghuashun"endconfig application name "TortoiseSVN.Check.Update"endconfig application name "Totoexpress"endconfig application name "Totorasa"endconfig application name "Totorosa.JJAM"endconfig application name "TrendMicro.Update"endconfig application name "Tuotu"endconfig application name "TVants"endconfig application name "TVKing"endconfig application name "TVKoo"endconfig application name "Twitter"endconfig application name "UPnP"end--More-- config application name "Userplane"--More-- end

Page 75: N_ FortiGate 200a Configuration.txt

--More-- config application name "Ustream.Media"--More-- end--More-- config application name "Vakaka"--More-- end--More-- config application name "Valve.Games"--More-- end--More-- config application name "Veetle"--More-- end--More-- config application name "Ventrilo"--More-- end--More-- config application name "VeohTV"--More-- end--More-- config application name "Virtual.Tunnel"--More-- end--More-- config application name "Virustotal"--More-- end--More-- config application name "Virustotal.SSL"--More-- end--More-- config application name "VMware.Check.Update"--More-- end--More-- config application name "Vmware.Server"--More-- end--More-- config application name "VNC.HTTP"--More-- end--More-- config application name "VNN"--More-- end--More-- config application name "VSA"--More-- end--More-- config application name "Vsee"--More-- end--More-- config application name "Vtunnel.Web.Proxy"--More-- end--More-- config application name "Vyew"--More-- end--More-- config application name "Wakoopa.Toolbar"--More-- end--More-- config application name "Wallcooler.VPN"--More-- end--More-- config application name "WAP"--More-- end--More-- config application name "Warcraft"--More-- end--More-- config application name "WarRock"--More-- end--More-- config application name "WCCP.V1"--More-- end--More-- config application name "WCCP.V2"--More-- end--More-- config application name "Web.Pownce"--More-- end--More-- config application name "Webaim"--More-- end--More-- config application name "Webcrawler"--More-- end--More-- config application name "WebEx.Weboffice"--More-- end--More-- config application name "Weilaiqushi"--More-- end--More-- config application name "Wetpaint"--More-- end--More-- config application name "Wikipedia"

Page 76: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config application name "Wikispaces.Editing"--More-- end--More-- config application name "Willing.WebCam.Broadcast"--More-- end--More-- config application name "Winamp.Remote"--More-- end--More-- config application name "Winamp.Stream"--More-- end--More-- config application name "Winamp.Video.HTTP"--More-- end--More-- config application name "Windows.CRL.Request"--More-- end--More-- config application name "WinKawaks"--More-- end--More-- config application name "WinPcap.Rpcapd"--More-- end--More-- config application name "Wins"--More-- end--More-- config application name "Wmsj"--More-- end--More-- config application name "Wolfenstein"--More-- end--More-- config application name "Woool"--More-- end--More-- config application name "WorldofWarcraft"--More-- end--More-- config application name "Writeboard"--More-- end--More-- config application name "X.Font.Server"--More-- end--More-- config application name "Xfire"--More-- end--More-- config application name "Xm.Radio"--More-- end--More-- config application name "XML.RPC"--More-- end--More-- config application name "Xobni.LinkedIn"--More-- end--More-- config application name "XYQ"--More-- end--More-- config application name "Yacy"--More-- end--More-- config application name "Yahoo.Finance.Posting"--More-- end--More-- config application name "Yahoo.Games"--More-- end--More-- config application name "Yahoo.Groups"--More-- end--More-- config application name "Yahoo.Search"--More-- end--More-- config application name "Yahoo.Toolbar"--More-- end--More-- config application name "YHGame"--More-- end--More-- config application name "Ymail"--More-- end--More-- config application name "Yourfilehost"--More-- end--More-- config application name "Youseemore"--More-- end

Page 77: N_ FortiGate 200a Configuration.txt

--More-- config application name "YouSendIt"--More-- end--More-- config application name "YouTube.Download"--More-- end--More-- config application name "Ypserv"--More-- end--More-- config application name "Yugma"--More-- end--More-- config application name "Yum"--More-- end--More-- config application name "Zango"--More-- end--More-- config application name "Zelune"--More-- end--More-- config application name "Zenbe"--More-- end--More-- config application name "Zhengtu"--More-- end--More-- config application name "ZhuXian"--More-- end--More-- config application name "ZMAAP"--More-- end--More-- config application name "Zoho.Chat"--More-- end--More-- config application name "Zoho.Notebook"--More-- end--More-- config application name "Zoho.Sheet"--More-- end--More-- config application name "Zoho.Show"--More-- end--More-- config application name "Zoho.Wiki"--More-- end--More-- config application name "Zoho.Writer"--More-- end--More-- config application name "Zwiki"--More-- end--More-- config application name "Alibaba.TradeManager"--More-- end--More-- config application name "Baidu.Xiaba"--More-- end--More-- config application name "Bomgar.Jump.Client"--More-- end--More-- config application name "Digsby"--More-- end--More-- config application name "DNS2TCP"--More-- end--More-- config application name "Dropbox"--More-- end--More-- config application name "Facebook.APP"--More-- end--More-- config application name "FortiClient"--More-- end--More-- config application name "Gbridge"--More-- end--More-- config application name "Graboid.Video"--More-- end--More-- config application name "Guildwars"--More-- end--More-- config application name "Haiwangxing"--More-- end--More-- config application name "ISL.Light"

Page 78: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config application name "Justvoip"--More-- end--More-- config application name "McAfee.Update"--More-- end--More-- config application name "MS.Office.Live"--More-- end--More-- config application name "MySpace.Webmail"--More-- end--More-- config application name "Paradial.RealTunnel"--More-- end--More-- config application name "PartyPoker"--More-- end--More-- config application name "Playstation.Network"--More-- end--More-- config application name "Reduh"--More-- end--More-- config application name "SOCKS4"--More-- end--More-- config application name "SOCKS5"--More-- end--More-- config application name "Spy.Agent"--More-- end--More-- config application name "XBBrowser"--More-- end--More-- config application name "Zoho.DB"--More-- end--More-- config application name "FTP.Command"--More-- end--More-- config application name "FTP.DELETE"--More-- end--More-- config application name "FTP.GET"--More-- end--More-- config application name "FTP.PUT"--More-- end--More-- config application name "HTTP.Method"--More-- end--More-- config application name "HTTP.Proxy"--More-- end--More-- config application name "QQ"--More-- end--More-- config application name "IMAP.Command"--More-- end--More-- config application name "Direct.Connect"--More-- end--More-- config application name "Ultrasurf"--More-- end--More-- config application name "POP3.Command"--More-- end--More-- config application name "SUN.RPC.Program.Number"--More-- end--More-- config application name "SMTP.Command"--More-- end--More-- config application name "SIP.Method"--More-- end--More-- config application name "MS.RPC.UUID"--More-- end--More-- config application name "NNTP.Command"--More-- end--More-- config application name "RTSP.Method"--More-- end

Page 79: N_ FortiGate 200a Configuration.txt

--More-- config vpn certificate ca--More-- edit "Fortinet_CA"--More-- set ca "-----BEGIN CERTIFICATE-------More-- MIIDzTCCArWgAwIBAgIBADANBgkqhkiG9w0BAQUFADCBoDELMAkGA1UEBhMCVVMx--More-- EzARBgNVBAgTCkNhbGlmb3JuaWExEjAQBgNVBAcTCVN1bm55dmFsZTERMA8GA1UE--More-- ChMIRm9ydGluZXQxHjAcBgNVBAsTFUNlcnRpZmljYXRlIEF1dGhvcml0eTEQMA4G--More-- A1UEAxMHc3VwcG9ydDEjMCEGCSqGSIb3DQEJARYUc3VwcG9ydEBmb3J0aW5ldC5j--More-- b20wHhcNMDAwNDA5MDEyNTQ5WhcNMjAwNTI0MDEyNTQ5WjCBoDELMAkGA1UEBhMC--More-- VVMxEzARBgNVBAgTCkNhbGlmb3JuaWExEjAQBgNVBAcTCVN1bm55dmFsZTERMA8G--More-- A1UEChMIRm9ydGluZXQxHjAcBgNVBAsTFUNlcnRpZmljYXRlIEF1dGhvcml0eTEQ--More-- MA4GA1UEAxMHc3VwcG9ydDEjMCEGCSqGSIb3DQEJARYUc3VwcG9ydEBmb3J0aW5l--More-- dC5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDUO1Fz0DUSEsjD--More-- TllBSNE7wbCm1Q+DISmLeL/rw0SdxmaCmu4EH6Cfq+DNeMVs0zTdujaybVLrWElJ--More-- g5l/5ua26NuCY7RncdRcyi+vt3Ayh1A1fMGQiNA0GS2poYGzSe379FXq4LLiV8af--More-- Lq8xSQNuaW6sR/V+rtZTrODagjOgkx71afiKpmRrnFZhUEzIfX4hNC9tCBWNCucH--More-- Pwt1z9T2tAs1y7urJo7a9Ka8F4rBkok5MYNPh00jtuLb9KuQAT4H8zliqV/W+oGj--More-- Lde694UouRoShJWwgxi7TG3SnJXW6MTQUGeZ8T0TRUtui3XuXbgfI6HOkcHYL/Xb--More-- MUktex1jAgMBAAGjEDAOMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEFBQADggEB--More-- AGl8fJvgJHQW7fYTSE1w4FEx/rQe57qcT4Fr9Z++xomCEyAr375C8Lb8RPwJNBWo--More-- MVcuDbubJWe3f7pDklBvRMkM4twNtyZi6B2hNu6/g5blqm2b2nRzvhHrUIO+34US--More-- 9YjWNTgj20Jvoco4n+q8wdf6OjmcUfyOKG8ylf7xKpcdsyjQXKfnrZAg5qNL/dek--More-- lrzEteqx00tZqslyt5P061lrgt54L//+xAri8W+Kwr8zrrsb4JH+A4unS048WHtQ--More-- 4YU27fQqjR1cFRZbLsLdxbgiB4+oAWxwurpFtaT1jyHHz5DaXuClGeazbGtMQtHA--More-- bg8XdijSGBoIUys9XYY5juc=--More-- -----END CERTIFICATE-----"--More-- set scep-url ''--More-- next--More-- edit "Fortinet_CA2"--More-- unset ca--More-- set scep-url ''--More-- next--More-- end--More-- config vpn certificate local--More-- edit "Fortinet_Factory"--More-- set password ENC s7zHNQnK6cTkJrV6pN6XAt1ABdSYxUAmNgskJhM8wsbA3n597vaqzKNZipYczsYbzehOccog6AyqqVPimuckuSGV7CTTSqjYNZ6VDtEq77iDZkno--More-- set private-key "-----BEGIN RSA PRIVATE KEY-------More-- Proc-Type: 4,ENCRYPTED--More-- DEK-Info: DES-EDE3-CBC,6BC40AB5D42693BD

Page 80: N_ FortiGate 200a Configuration.txt

--More-- --More-- KPKw/a9Oo/hVWYDQLFCPz2+7UcyH1kcJrjMDXBmzfyAmZE88h2Yv4Ik1jVtX86RW--More-- kKK2D+kF/OQkkn6ocw7zXhLRlhoAJyfR8ur0e7KUmaeza6KbvUB/9cfxWQm3LY+0--More-- 2pSh+4OSbURdTvq8v2OhEiZmoVeNwW+3ES6bGQ1PJSmUO8F7gc3kdDgdei8bFrbv--More-- zMDS0ynjjpweSoFEEMbztcNONXwVCyp/HqiyGfJHga7Sv48x91a6Kft4eK42sBMp--More-- BIND0qqn1NN12A7PsDzeSEUDE/dW6Ium4hrWOD6+rXyjRd+bSv0SZCsIUbCYTwFZ--More-- Gfs6ueu/1mpFfKDooNAktsbo5w+xwZZsFSZu6fopJPETpk0QTqGyc3hcNMY/68qT--More-- vO0rIHcr+5unujz1h4rGiv5Cw+oU6dTBfKD8XZkugxvit5UO0MiLVpGWn5m3x8fL--More-- khPFGlheABu0uJVARpDYLwoSaOMd7qJhLb2RE+PxsqwW18EZrxXt36OGG7hGWASn--More-- Nwjcs/ADsP90F9vjndeV1/sRIq8TR1v3ca/CbPiqsG0av5t5MB3zdKaxHMvzfMXp--More-- Dazdle+SJ0MO9lTrAz/b+sEfJ4VDBDhL9Dw+PkQduDpPsQrfQFXXD7csMhnbtoNY--More-- UclEj0b+eAY3yQDqltmx7U5GlOqLAW03JIt7NLY4CsVeqP7DjkgkUASwUOlywn/2--More-- DNuLwntWvOjs8Wu5YMd80PAjBLdQUd9yuPzdUtFWOiewTgZ73O45QQBg2NBNUloL--More-- fjVFHZoUy0IPKafPqtPcGGiPrhIlvTZOgwGOXOql8XSApLjyFU+D8g==--More-- -----END RSA PRIVATE KEY-----"--More-- set certificate "-----BEGIN CERTIFICATE-------More-- MIIDRTCCAi2gAwIBAgIDB9f2MA0GCSqGSIb3DQEBBQUAMIGgMQswCQYDVQQGEwJV--More-- UzETMBEGA1UECBMKQ2FsaWZvcm5pYTESMBAGA1UEBxMJU3Vubnl2YWxlMREwDwYD--More-- VQQKEwhGb3J0aW5ldDEeMBwGA1UECxMVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MRAw--More-- DgYDVQQDEwdzdXBwb3J0MSMwIQYJKoZIhvcNAQkBFhRzdXBwb3J0QGZvcnRpbmV0--More-- LmNvbTAeFw0wNzA3MzAxNjE5NDVaFw0yNzA5MTMxNjE5NDVaMIGdMQswCQYDVQQG--More-- EwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTESMBAGA1UEBxMJU3Vubnl2YWxlMREw--More-- DwYDVQQKEwhGb3J0aW5ldDESMBAGA1UECxMJRm9ydGlnYXRlMRkwFwYDVQQDExBG--More-- RzIwMEEzOTA3NTA5NjA0MSMwIQYJKoZIhvcNAQkBFhRzdXBwb3J0QGZvcnRpbmV0--More-- LmNvbTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA0T/IdnRGjEkXcnJaCu7k--More-- iHv82aodxMBDE5StNMgZvLhkvQI2LKbMU7myJ9l8RWuGBFF2RpQLSF7KcgHxLCyx--More-- l8EyzJKFzX3Y9sHakU9XUO4gL4QKtWsdO+qyzj+TN0kWVmzHEuYlO7QsDipxlahu--More-- LzkSMz0RFK5BzMrZiWy1xiECAwEAAaMNMAswCQYDVR0TBAIwADANBgkqhkiG9w0B--More-- AQUFAAOCAQEAPhvFCtaOz7SlEnv/lbUjLXUmIW1WeXYuo37YskG/B2+VgI5UuLwj--More-- sFi5NbdGjWHEPfAj7WBgLNmBHMB1XtXqUQXciq2rOnoYfd/YqrQIA+uO6gEyMh/B--More-- hPeBOzHhEtSIGVkuw5uzQ/p5p6O4wo+FtqoYWbColPICUBVTx0V8nF0yFR2CG2FL--More--

Page 81: N_ FortiGate 200a Configuration.txt

r8WHO1gVSoV5uMnS8wGgzEAjnDvyqJsI3ygbJlbRt2TlTg9kcK+Zda03noDlSqGs--More-- 5QioFG+6e+Iqx4J1gNT3DL4xUec3kdGfpXCpTEAmz2RXf6MvQNs1f2Fj2R9jZ+td--More-- XNkkyliLsDUrcfDcXGURfr1h1ifN+R/wVg==--More-- -----END CERTIFICATE-----"--More-- set scep-url ''--More-- next--More-- edit "Fortinet_Factory2"--More-- set scep-url ''--More-- next--More-- edit "Fortinet_Firmware"--More-- set password ENC al7aFRSKfMihTs4BkVB3CcHNN8syssCohsLk8TRbhSJCp3UHclblc+BV0jOxIDnAnLCNIZYkx9nKAE4CHoYb8ZL6kf6AY6nqtc0H1pX6N42HR4Fk--More-- set private-key "-----BEGIN RSA PRIVATE KEY-------More-- Proc-Type: 4,ENCRYPTED--More-- DEK-Info: DES-EDE3-CBC,2010E763D48793BD--More-- --More-- GCz2Lz+vKetFYDEIPaIzNVTZQlCPL/iETw4V86Mwt26ClHfjToAJPENJtUPLY7A8--More-- asxlSVkpi77w/FnWZXbWhPU6DW2V7uBMRkTiih7FA/0gltShm5j4w4Y4oTA2rjVV--More-- s6L4pabR/3EJnLNYa84la1CfoZQY99T/Qm7+BFhudGGJs0HPQE7EGZ/1t0HHVqOc--More-- mVo60k8m55tykpRUiuzp1bByS4k9e6E/ppQMwLQayccfN7RWAgjRNTeO3SJ9OUQH--More-- BhJVZHsjK9NtOa3PCMQhzVGdh46Vzi9LExAAyKcFhha1B0Z0EqIJ0VbdUqyyt7NX--More-- l4azu3cFc1jHujF7koTzi6/LR5M9Qa9DJSV9fgjzt9ktHev031x+9yUJoLoiy9Ky--More-- 2gzXCoPg+mqwn3x/+I5z5RNQLfqQqeyGzP7gYKSQXuXmUIeBL+32WdGRUB2FBWgb--More-- feApmyJ5a8hTY2lbBZ//AxM2UfYp5c//m7zrBAPkjs5pSIaTbTHmfaH0s2q+7J8E--More-- 7wark63uvGkv/lhF1yDKDc56sZ6xmYUL5C5gUHNH722DGY+eviOsMVCEfkdusM06--More-- b3NuIwWKpm2IfQytrvH3Rb8n5cb60AF7bKFwHZ6fHSXJ1DW2l7iKUBFNMb3h+/JH--More-- +qn34HFqES22m0zN4CtcV6nnjSl6C8krZdPUE43VZrfpPWqOs4qUPqll0gbgaIn2--More-- vNHBSWq/LsQCVGslDILIaQpAe319IzGb5hqxbGRUSaUpKdwKTTRTwM2tigQ+mgVy--More-- ee8EA5tw98zSTskWGnGY4I3wfI8NsN+DMi1mrf9WgJk7G5gxoPtOgMyYDzQIiWv6--More-- lgxy1WvJAd3A9T/0VnmaBPXbMO+174AeXuFoDR2wfNpTvknWoeXMw6WJbSSu0NkT--More-- xJCOJgzDwC/sZLtspujV7EmoBQMR/zrRF+ECaVCwtSzYwg8taBIc4iPUJFbfIakL--More-- 4TUtCvFBM3NDLUYkE6Bw+ckdvlT4DFJ+XL9vzDoplc7drO0W6u67HUenxpp7Ex0K--More-- AwM3D4kgJBCpXgSAGcGKzJdhpyphof8rgcfZzD3LgClHwYjcAv5G1Ii9CW7iNi5X--More-- QkbefyUn0I0dNR4NBFUBPbzcaGGI4suSaZH9+P1ltn5ejUK1wigm3nDpgD8GnZtT--More-- T8jQwwUZLQBhj++aHhfgsS46Vvw9WQaw8befR6agWA/wgMkb4o4xmhlK0OmwQOdM--More-- rBVpdviB9TIaOAPUnzQnWp2bScRdQV8caePYmZv5smLL3IT8epQGWs2RSjTvQlum--More-- BfWCmv2DPLOB9KTUdBvoMJuLW7S58TC5T2To11+wa6Xtt0p0M5Kb5L3Ad5s1FRde

Page 82: N_ FortiGate 200a Configuration.txt

--More-- HomkF3Z1BNbIJJT+s9GFeCviNfDldQaIHSP2XfgCXwGRIsxuyxuwxJdFP6wT+6nz--More-- HvpbJtC5ox7SQsrD/r/8p+JFHje6rH3ZQ8aYSge/gfxTnrFi2MD8CG/tRvFn1eh/--More-- PGHce+Z1113rvlZl4UsvWzfQDlE/Dtt11I4nG65Ac0k6Mj318Z0oV3ZVF1+TLjxi--More-- Aq+iKCvepomknvK0ODgXqwHqs3tqPfTOIKh8Nbu2/zD5YTctyziKbHjCCvAzmsQP--More-- -----END RSA PRIVATE KEY-----"--More-- set certificate "-----BEGIN CERTIFICATE-------More-- MIIDwjCCAqqgAwIBAgIDAePrMA0GCSqGSIb3DQEBBQUAMIGgMQswCQYDVQQGEwJV--More-- UzETMBEGA1UECBMKQ2FsaWZvcm5pYTESMBAGA1UEBxMJU3Vubnl2YWxlMREwDwYD--More-- VQQKEwhGb3J0aW5ldDEeMBwGA1UECxMVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MRAw--More-- DgYDVQQDEwdzdXBwb3J0MSMwIQYJKoZIhvcNAQkBFhRzdXBwb3J0QGZvcnRpbmV0--More-- LmNvbTAeFw0wNjAxMjcxOTQ0MTRaFw0yNjAzMTMxOTQ0MTRaMIGWMQswCQYDVQQG--More-- EwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTESMBAGA1UEBxMJU3Vubnl2YWxlMREw--More-- DwYDVQQKEwhGb3J0aW5ldDESMBAGA1UECxMJRm9ydGlnYXRlMRIwEAYDVQQDEwlG--More-- b3J0aWdhdGUxIzAhBgkqhkiG9w0BCQEWFHN1cHBvcnRAZm9ydGluZXQuY29tMIIB--More-- IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxMZu1/4w7kp/idCBrEiV8fZk--More-- xti4fZez1p8pMEtRENdgPHdNzXTwLU86GTNU1znG7sukRpDF4lD9jRKOBExJpUXn--More-- lo3bPSZQCYyS8RPaThtVSN2ygK2S0F2bGcRDoPiVMmBNlyzeP3hYIJYVHKVKTqDL--More-- xB682Smp17XuPXKWuq5SvRnmWl+DLzu/ZD75/UJhda+seiA7HxppsGwGO6LLzhXj--More-- Ki5f6ZJGVsq2YY+mEZwSC8/Gp9EB7EzG6JfTH627N8uOXWATAZBht+R/5BGWYsw4--More-- EME3zY3V5xmgBjjn26TaU9YF28kyzInl9vhnv6fXxrWfeaTHdMsr+QFJ5Y5h9QID--More-- AQABow0wCzAJBgNVHRMEAjAAMA0GCSqGSIb3DQEBBQUAA4IBAQAGsdqtZj8NCtQp--More-- bmattOb8DJle0bQrKd25dZkIjgELXp2W523jbejEZLqZ6DdHwuvEaUE+MqpnffJ3--More-- 2prIxsHkedJwDyexsmeUdQ62mQCkNi64nHbViQVGS3thLZInAPVIfCYRcTQVdLzd--More-- SYqzON/AAd9w6fK0hsbI6y/5Iym5iVP4D/J3YrCDr/ysxh1SYYoKgytheYHfbWNr--More-- E4u2VLMk8FetRqpG+wZmzea2rfXs5fgEgBdDUwniClp7spqCnLooTN4SmV6dSih8--More-- G2myTCMh4810eU5fxTnnWG9nvDK8/hpZ/iWu1+IdwkNcolxG4enLTpE8gS+O9d5a--More-- FGxImnS5--More-- -----END CERTIFICATE-----"--More-- set scep-url ''--More-- next--More-- edit "Fortinet_CA_SSLProxy"--More-- set password ENC Ybn7bmLYr7oTvAvvMZFbPfADNbxycW4K20YaUY8ANVM7MZssz8sMN6uKDmu1jKC8YK04YQbC02xe8T27FKwPQJ8xtnYSVwtF+A9ijtduBTO64/pA--More-- set comments "This certificate is embedded in the firmware and is the same on every unit (not unique). This is

Page 83: N_ FortiGate 200a Configuration.txt

the default CA certificate the SSL Inspection will use when generating new server certificates."--More-- set private-key "-----BEGIN RSA PRIVATE KEY-------More-- Proc-Type: 4,ENCRYPTED--More-- DEK-Info: DES-EDE3-CBC,ECC19EED38462779--More-- --More-- a2QGUGmiwH4wUJ88QUA8P9kZfi9zk+SuXsqeY2k0A23s8li05+Rmt89yXmqgXtl0--More-- s5KY3tXMj2gvqkBxhce1Ok016Socyj3BUm2WvBXJlqfRjV4waMkdwDj2GgfxHUrv--More-- xDEZVKpU5ZIKbMoQhyw1EDKc4T/3HGCqxUR9rbm5Ak6+iykuLyHBz5YdERnHnfXD--More-- 1zYMYXjYVt9WolKgDqYA7Nxs3kz7+V+7sP7VEt2lAGvduWuCZpcw7syRYe9k1YZ5--More-- vrE64/QpIMp7FioulbZy9AUC7SqVYAs3T87+s/DfpEsuT6rumKXWTRaHLvNoxNVv--More-- TV5SkM7bw/7/+Fn3hohaUzkSK8v9D7hz2fQRP2h7VE9OvOUHzgLj9V1zXJxd2CXS--More-- JP3AWPSYM+/aaDc2vxabjvKtyVyaNqSlrkW8fC3sGWjMCIaqrFHXsta4WxbRviYv--More-- TkjSBczSqXHq/07YwSHhWY3AcbSSPbn98jA0OLzCK55lELd7qawYUAapBfyNRZnK--More-- 7kB2UYZ6y2aOJsTRLGgqWNG5xkaKLSsy3LmTkPluEHLlpfOLqmKhG8Mahnp9gfGr--More-- CGjGQTUaNewwb+n0p44QfZvHyemc+j+dnBOF1InkQCYIpWQwRojPq8/1CyAmAIqK--More-- ab9P8lMN3vrZTfSh/xPI5MofKz4fU7TrS/gtmlKgG9ygdyPG634+Xa3nSGIT6Olj--More-- m3lhQZ0SBQFwGqYYSpQ2SaUV6tYcoS/xzIXXbQT1dtO7rSHtE25aYpgaoZXf2cMY--More-- BjfwqM4bPNYxZUs1XAHqwSFL4+1QCObRMNhtfF1xbTkw3ly/1KkMpqkjhhuv1PuB--More-- VqEeYZ6nJbZUA/cWwSTAKrx0TaA2lNAasSikpe/Dl/FCA8kdrAC+dZGCr0QgGDs7--More-- gl9zB9K0S9kZoRySReInY6bo7vEtjCUpXx7q1DDAaGjesIb8+qJPOjc6WChhncdT--More-- koZkNnJs6TDVxXM+4JiXmuibmIqETiYblURees/8v9OUwp0VF/jKhJZrjdNxImcU--More-- d4yf7cixaFwQVGqDb3Z8jTF+/bIHJP1wQ1DRDGOJc8fvQIDbDDToyUfr27FhUl7K--More-- +0q3MXfNxuQgccnJR3D6OoimKWP4Qeaki2Hyzd7/DaFG+vz4MJ2fG5KwQRpUnna0--More-- hH5vDP5MZEbQe+9smIBgG8p7q0BCVuwVzhlAWbrL6SEOnbtNHX+duOIOQijnqmoW--More-- UywjxVNGuGxtj1IsQ/QYZTP2l+cwMX047MrMC/f1LNdqR2howoPGZdADDb1ibB0y--More-- Fx5xcFWA9t/YpErJXHw6bTdTCCxXvEnoPgVC3YvNXw++FtjrF6jiEaVU0wz0bnGW--More-- w3Zx8SJYq6OeJbKY0+E4xmgySYPE709NCsLKQgTImbDa6kvQtGruPumTACfztEZn--More-- wc/vyg4M/d+/sUUbVg3TqhUvBYfstvDUah/jWi4yqKAoFUi6HvfRdNmeqr0k6Ou0--More-- rE8WBjtagvWCHhxuwEf9l9ha8EJBWn2Yys7fX1tIYCd7yWUemnZ4DZZ4AlV1rFMj--More-- eobWmQcXrOfE1bkQ7TSnXu4KytJnEJ70lgPH1Z7iJ2Zs9TyiZUlqxA==--More-- -----END RSA PRIVATE KEY-----"--More-- set certificate "-----BEGIN CERTIFICATE-------More--

Page 84: N_ FortiGate 200a Configuration.txt

MIID1zCCAr+gAwIBAgIBADANBgkqhkiG9w0BAQUFADCBpTELMAkGA1UEBhMCVVMx--More-- EzARBgNVBAgTCkNhbGlmb3JuaWExEjAQBgNVBAcTCVN1bm55dmFsZTERMA8GA1UE--More-- ChMIRm9ydGluZXQxHjAcBgNVBAsTFUNlcnRpZmljYXRlIEF1dGhvcml0eTEVMBMG--More-- A1UEAxMMRm9ydGlHYXRlIENBMSMwIQYJKoZIhvcNAQkBFhRzdXBwb3J0QGZvcnRp--More-- bmV0LmNvbTAeFw0wODEwMTgwMDQ2MzlaFw0yODEwMTMwMDQ2MzlaMIGlMQswCQYD--More-- VQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTESMBAGA1UEBxMJU3Vubnl2YWxl--More-- MREwDwYDVQQKEwhGb3J0aW5ldDEeMBwGA1UECxMVQ2VydGlmaWNhdGUgQXV0aG9y--More-- aXR5MRUwEwYDVQQDEwxGb3J0aUdhdGUgQ0ExIzAhBgkqhkiG9w0BCQEWFHN1cHBv--More-- cnRAZm9ydGluZXQuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA--More-- tveDq5vViSsRgHROaylt0qMdteLi1D/L0AWct+j5Y+N+HskBqsK5eGHrgytW6Jr3--More-- dtQ/53/usTI+8HHpPXj8gWune6ivjQcOAmGsB/gfwLPCa98+kLgo9wpu0NxLVbyU--More-- i5F9OjFtMpEGsYlnu6jtrsIR8EonAnaUtYKCqPLNSVc/U97ZX9m7zyjLYEGENt2M--More-- elnAeTDNy2VHdxvjCkHBZYuI8lygtQsFvAGdvHsoIGEKgnLHbycLCWUk1j9mTkYB--More-- 0QFKWdy45jsvrUEnaEuWBlIKNZEgy8uI1wW/Rtv1HHbofuWr/2gTIaggPjIWshak--More-- sPA5wXth1N5pBMrPOxNoHwIDAQABoxAwDjAMBgNVHRMEBTADAQH/MA0GCSqGSIb3--More-- DQEBBQUAA4IBAQBrAfI+ULwg3M+k4s3FB6//6sPG5TcrvPdrQ8gArEeYJJCzHnVY--More-- tknIPPx1K5V+QueAXRpLiuWphFP5w9OxWuDqHw8zwb24wJc7BD4CeFKUyYinbpDi--More-- Yg035SKYl4TSGMOTiYRoTxqgkfzcmTFfpfD1pOJQ08Kh+1yle35WqG9Ab1jrO0Y/--More-- vltGReZckwh9e95SPzNA43xGZPSIgxZ8007EUqYBekoSKGAQPqTalHBkzpB1Us3F--More-- 5yCZzxA4WYT9UGVwPhIVgMlZvm5NL29/5dFgts51U+P4OZ0Or+xQfWYIxTzCWtAC--More-- 1ikZ/6HeIvet27H4CPP1rolBTXw4z6olP32T--More-- -----END CERTIFICATE-----"--More-- set scep-url ''--More-- next--More-- end--More-- config webfilter fortiguard--More-- set cache-mode ttl--More-- set cache-prefix-match enable--More-- set cache-mem-percent 2--More-- set ovrd-auth-port-http 8008--More-- set ovrd-auth-port-https 8010--More-- set ovrd-auth-https enable--More-- set reports-status enable--More-- end--More-- config endpoint-control app-detect predefined-signature 1--More-- end--More-- config endpoint-control app-detect predefined-signature 2--More-- end--More-- config endpoint-control app-detect predefined-signature 3

Page 85: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config endpoint-control app-detect predefined-signature 4--More-- end--More-- config endpoint-control app-detect predefined-signature 5--More-- end--More-- config endpoint-control app-detect predefined-signature 6--More-- end--More-- config endpoint-control app-detect predefined-signature 7--More-- end--More-- config endpoint-control app-detect predefined-signature 8--More-- end--More-- config endpoint-control app-detect predefined-signature 9--More-- end--More-- config endpoint-control app-detect predefined-signature 10--More-- end--More-- config endpoint-control app-detect predefined-signature 11--More-- end--More-- config endpoint-control app-detect predefined-signature 12--More-- end--More-- config endpoint-control app-detect predefined-signature 13--More-- end--More-- config endpoint-control app-detect predefined-signature 14--More-- end--More-- config endpoint-control app-detect predefined-signature 15--More-- end--More-- config endpoint-control app-detect predefined-signature 16--More-- end--More-- config endpoint-control app-detect predefined-signature 17--More-- end--More-- config endpoint-control app-detect predefined-signature 18--More-- end--More-- config endpoint-control app-detect predefined-signature 19--More-- end--More-- config endpoint-control app-detect predefined-signature 20--More-- end--More-- config endpoint-control app-detect predefined-signature 21--More-- end--More-- config endpoint-control app-detect predefined-signature 22--More-- end--More-- config endpoint-control app-detect predefined-signature 23--More-- end

Page 86: N_ FortiGate 200a Configuration.txt

--More-- config endpoint-control app-detect predefined-signature 24--More-- end--More-- config endpoint-control app-detect predefined-signature 25--More-- end--More-- config endpoint-control app-detect predefined-signature 26--More-- end--More-- config endpoint-control app-detect predefined-signature 27--More-- end--More-- config endpoint-control app-detect predefined-signature 28--More-- end--More-- config endpoint-control app-detect predefined-signature 29--More-- end--More-- config endpoint-control app-detect predefined-signature 30--More-- end--More-- config endpoint-control app-detect predefined-signature 31--More-- end--More-- config endpoint-control app-detect predefined-signature 32--More-- end--More-- config endpoint-control app-detect predefined-signature 33--More-- end--More-- config endpoint-control app-detect predefined-signature 34--More-- end--More-- config endpoint-control app-detect predefined-signature 35--More-- end--More-- config endpoint-control app-detect predefined-signature 36--More-- end--More-- config endpoint-control app-detect predefined-signature 37--More-- end--More-- config endpoint-control app-detect predefined-signature 38--More-- end--More-- config endpoint-control app-detect predefined-signature 39--More-- end--More-- config endpoint-control app-detect predefined-signature 40--More-- end--More-- config endpoint-control app-detect predefined-signature 41--More-- end--More-- config endpoint-control app-detect predefined-signature 42--More-- end--More-- config endpoint-control app-detect predefined-signature 43--More-- end--More-- config endpoint-control app-detect predefined-

Page 87: N_ FortiGate 200a Configuration.txt

signature 44--More-- end--More-- config endpoint-control app-detect predefined-signature 45--More-- end--More-- config endpoint-control app-detect predefined-signature 46--More-- end--More-- config endpoint-control app-detect predefined-signature 47--More-- end--More-- config endpoint-control app-detect predefined-signature 48--More-- end--More-- config endpoint-control app-detect predefined-signature 49--More-- end--More-- config endpoint-control app-detect predefined-signature 50--More-- end--More-- config endpoint-control app-detect predefined-signature 51--More-- end--More-- config endpoint-control app-detect predefined-signature 52--More-- end--More-- config endpoint-control app-detect predefined-signature 53--More-- end--More-- config endpoint-control app-detect predefined-signature 54--More-- end--More-- config endpoint-control app-detect predefined-signature 55--More-- end--More-- config endpoint-control app-detect predefined-signature 56--More-- end--More-- config endpoint-control app-detect predefined-signature 57--More-- end--More-- config endpoint-control app-detect predefined-signature 58--More-- end--More-- config endpoint-control app-detect predefined-signature 59--More-- end--More-- config endpoint-control app-detect predefined-signature 60--More-- end--More-- config endpoint-control app-detect predefined-signature 61--More-- end--More-- config endpoint-control app-detect predefined-signature 62--More-- end--More-- config endpoint-control app-detect predefined-signature 63--More-- end--More-- config endpoint-control app-detect predefined-signature 64

Page 88: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config endpoint-control app-detect predefined-signature 65--More-- end--More-- config endpoint-control app-detect predefined-signature 66--More-- end--More-- config endpoint-control app-detect predefined-signature 67--More-- end--More-- config endpoint-control app-detect predefined-signature 68--More-- end--More-- config endpoint-control app-detect predefined-signature 69--More-- end--More-- config endpoint-control app-detect predefined-signature 70--More-- end--More-- config endpoint-control app-detect predefined-signature 71--More-- end--More-- config endpoint-control app-detect predefined-signature 72--More-- end--More-- config endpoint-control app-detect predefined-signature 73--More-- end--More-- config endpoint-control app-detect predefined-signature 74--More-- end--More-- config endpoint-control app-detect predefined-signature 75--More-- end--More-- config endpoint-control app-detect predefined-signature 76--More-- end--More-- config endpoint-control app-detect predefined-signature 77--More-- end--More-- config endpoint-control app-detect predefined-signature 78--More-- end--More-- config endpoint-control app-detect predefined-signature 79--More-- end--More-- config endpoint-control app-detect predefined-signature 80--More-- end--More-- config endpoint-control app-detect predefined-signature 81--More-- end--More-- config endpoint-control app-detect predefined-signature 82--More-- end--More-- config endpoint-control app-detect predefined-signature 83--More-- end--More-- config endpoint-control app-detect predefined-signature 84--More-- end

Page 89: N_ FortiGate 200a Configuration.txt

--More-- config endpoint-control app-detect predefined-signature 85--More-- end--More-- config endpoint-control app-detect predefined-signature 86--More-- end--More-- config endpoint-control app-detect predefined-signature 87--More-- end--More-- config endpoint-control app-detect predefined-signature 88--More-- end--More-- config endpoint-control app-detect predefined-signature 89--More-- end--More-- config endpoint-control app-detect predefined-signature 90--More-- end--More-- config endpoint-control app-detect predefined-signature 91--More-- end--More-- config endpoint-control app-detect predefined-signature 92--More-- end--More-- config endpoint-control app-detect predefined-signature 93--More-- end--More-- config endpoint-control app-detect predefined-signature 94--More-- end--More-- config endpoint-control app-detect predefined-signature 95--More-- end--More-- config endpoint-control app-detect predefined-signature 96--More-- end--More-- config endpoint-control app-detect predefined-signature 97--More-- end--More-- config endpoint-control app-detect predefined-signature 98--More-- end--More-- config endpoint-control app-detect predefined-signature 99--More-- end--More-- config endpoint-control app-detect predefined-signature 100--More-- end--More-- config endpoint-control app-detect predefined-signature 101--More-- end--More-- config endpoint-control app-detect predefined-signature 102--More-- end--More-- config endpoint-control app-detect predefined-signature 103--More-- end--More-- config endpoint-control app-detect predefined-signature 104--More-- end--More-- config endpoint-control app-detect predefined-

Page 90: N_ FortiGate 200a Configuration.txt

signature 105--More-- end--More-- config endpoint-control app-detect predefined-signature 106--More-- end--More-- config endpoint-control app-detect predefined-signature 107--More-- end--More-- config endpoint-control app-detect predefined-signature 108--More-- end--More-- config endpoint-control app-detect predefined-signature 109--More-- end--More-- config endpoint-control app-detect predefined-signature 110--More-- end--More-- config endpoint-control app-detect predefined-signature 111--More-- end--More-- config endpoint-control app-detect predefined-signature 112--More-- end--More-- config endpoint-control app-detect predefined-signature 113--More-- end--More-- config endpoint-control app-detect predefined-signature 114--More-- end--More-- config endpoint-control app-detect predefined-signature 115--More-- end--More-- config endpoint-control app-detect predefined-signature 116--More-- end--More-- config endpoint-control app-detect predefined-signature 117--More-- end--More-- config endpoint-control app-detect predefined-signature 118--More-- end--More-- config endpoint-control app-detect predefined-signature 119--More-- end--More-- config endpoint-control app-detect predefined-signature 120--More-- end--More-- config endpoint-control app-detect predefined-signature 121--More-- end--More-- config endpoint-control app-detect predefined-signature 122--More-- end--More-- config endpoint-control app-detect predefined-signature 123--More-- end--More-- config endpoint-control app-detect predefined-signature 124--More-- end--More-- config endpoint-control app-detect predefined-signature 125

Page 91: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config endpoint-control app-detect predefined-signature 126--More-- end--More-- config endpoint-control app-detect predefined-signature 127--More-- end--More-- config endpoint-control app-detect predefined-signature 128--More-- end--More-- config endpoint-control app-detect predefined-signature 129--More-- end--More-- config endpoint-control app-detect predefined-signature 130--More-- end--More-- config endpoint-control app-detect predefined-signature 131--More-- end--More-- config endpoint-control app-detect predefined-signature 132--More-- end--More-- config endpoint-control app-detect predefined-signature 133--More-- end--More-- config endpoint-control app-detect predefined-signature 134--More-- end--More-- config endpoint-control app-detect predefined-signature 135--More-- end--More-- config endpoint-control app-detect predefined-signature 136--More-- end--More-- config endpoint-control app-detect predefined-signature 137--More-- end--More-- config endpoint-control app-detect predefined-signature 138--More-- end--More-- config endpoint-control app-detect predefined-signature 139--More-- end--More-- config endpoint-control app-detect predefined-signature 140--More-- end--More-- config endpoint-control app-detect predefined-signature 141--More-- end--More-- config endpoint-control app-detect predefined-signature 142--More-- end--More-- config endpoint-control app-detect predefined-signature 143--More-- end--More-- config endpoint-control app-detect predefined-signature 144--More-- end--More-- config endpoint-control app-detect predefined-signature 145--More-- end

Page 92: N_ FortiGate 200a Configuration.txt

--More-- config endpoint-control app-detect predefined-signature 146--More-- end--More-- config endpoint-control app-detect predefined-signature 147--More-- end--More-- config endpoint-control app-detect predefined-signature 148--More-- end--More-- config endpoint-control app-detect predefined-signature 149--More-- end--More-- config endpoint-control app-detect predefined-signature 150--More-- end--More-- config endpoint-control app-detect predefined-signature 151--More-- end--More-- config endpoint-control app-detect predefined-signature 152--More-- end--More-- config endpoint-control app-detect predefined-signature 153--More-- end--More-- config endpoint-control app-detect predefined-signature 154--More-- end--More-- config endpoint-control app-detect predefined-signature 155--More-- end--More-- config endpoint-control app-detect predefined-signature 156--More-- end--More-- config endpoint-control app-detect predefined-signature 157--More-- end--More-- config endpoint-control app-detect predefined-signature 158--More-- end--More-- config endpoint-control app-detect predefined-signature 159--More-- end--More-- config endpoint-control app-detect predefined-signature 160--More-- end--More-- config endpoint-control app-detect predefined-signature 161--More-- end--More-- config endpoint-control app-detect predefined-signature 162--More-- end--More-- config endpoint-control app-detect predefined-signature 164--More-- end--More-- config endpoint-control app-detect predefined-signature 165--More-- end--More-- config endpoint-control app-detect predefined-signature 166--More-- end--More-- config endpoint-control app-detect predefined-

Page 93: N_ FortiGate 200a Configuration.txt

signature 167--More-- end--More-- config endpoint-control app-detect predefined-signature 168--More-- end--More-- config endpoint-control app-detect predefined-signature 169--More-- end--More-- config endpoint-control app-detect predefined-signature 170--More-- end--More-- config endpoint-control app-detect predefined-signature 171--More-- end--More-- config endpoint-control app-detect predefined-signature 172--More-- end--More-- config endpoint-control app-detect predefined-signature 173--More-- end--More-- config endpoint-control app-detect predefined-signature 174--More-- end--More-- config endpoint-control app-detect predefined-signature 175--More-- end--More-- config endpoint-control app-detect predefined-signature 176--More-- end--More-- config endpoint-control app-detect predefined-signature 177--More-- end--More-- config endpoint-control app-detect predefined-signature 178--More-- end--More-- config endpoint-control app-detect predefined-signature 179--More-- end--More-- config endpoint-control app-detect predefined-signature 180--More-- end--More-- config endpoint-control app-detect predefined-signature 181--More-- end--More-- config endpoint-control app-detect predefined-signature 182--More-- end--More-- config endpoint-control app-detect predefined-signature 183--More-- end--More-- config endpoint-control app-detect predefined-signature 184--More-- end--More-- config endpoint-control app-detect predefined-signature 185--More-- end--More-- config endpoint-control app-detect predefined-signature 186--More-- end--More-- config endpoint-control app-detect predefined-signature 187

Page 94: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config endpoint-control app-detect predefined-signature 188--More-- end--More-- config endpoint-control app-detect predefined-signature 189--More-- end--More-- config endpoint-control app-detect predefined-signature 190--More-- end--More-- config endpoint-control app-detect predefined-signature 191--More-- end--More-- config endpoint-control app-detect predefined-signature 192--More-- end--More-- config endpoint-control app-detect predefined-signature 193--More-- end--More-- config endpoint-control app-detect predefined-signature 194--More-- end--More-- config endpoint-control app-detect predefined-signature 195--More-- end--More-- config endpoint-control app-detect predefined-signature 196--More-- end--More-- config endpoint-control app-detect predefined-signature 197--More-- end--More-- config endpoint-control app-detect predefined-signature 198--More-- end--More-- config endpoint-control app-detect predefined-signature 199--More-- end--More-- config endpoint-control app-detect predefined-signature 200--More-- end--More-- config endpoint-control app-detect predefined-signature 201--More-- end--More-- config endpoint-control app-detect predefined-signature 202--More-- end--More-- config endpoint-control app-detect predefined-signature 203--More-- end--More-- config endpoint-control app-detect predefined-signature 204--More-- end--More-- config endpoint-control app-detect predefined-signature 205--More-- end--More-- config endpoint-control app-detect predefined-signature 206--More-- end--More-- config endpoint-control app-detect predefined-signature 207--More-- end

Page 95: N_ FortiGate 200a Configuration.txt

--More-- config endpoint-control app-detect predefined-signature 208--More-- end--More-- config endpoint-control app-detect predefined-signature 209--More-- end--More-- config endpoint-control app-detect predefined-signature 210--More-- end--More-- config endpoint-control app-detect predefined-signature 211--More-- end--More-- config endpoint-control app-detect predefined-signature 212--More-- end--More-- config endpoint-control app-detect predefined-signature 213--More-- end--More-- config endpoint-control app-detect predefined-signature 214--More-- end--More-- config endpoint-control app-detect predefined-signature 215--More-- end--More-- config endpoint-control app-detect predefined-signature 216--More-- end--More-- config endpoint-control app-detect predefined-signature 217--More-- end--More-- config endpoint-control app-detect predefined-signature 218--More-- end--More-- config endpoint-control app-detect predefined-signature 219--More-- end--More-- config endpoint-control app-detect predefined-signature 220--More-- end--More-- config endpoint-control app-detect predefined-signature 221--More-- end--More-- config endpoint-control app-detect predefined-signature 222--More-- end--More-- config endpoint-control app-detect predefined-signature 223--More-- end--More-- config endpoint-control app-detect predefined-signature 224--More-- end--More-- config endpoint-control app-detect predefined-signature 225--More-- end--More-- config endpoint-control app-detect predefined-signature 226--More-- end--More-- config endpoint-control app-detect predefined-signature 227--More-- end--More-- config endpoint-control app-detect predefined-

Page 96: N_ FortiGate 200a Configuration.txt

signature 228--More-- end--More-- config endpoint-control app-detect predefined-signature 229--More-- end--More-- config endpoint-control app-detect predefined-signature 230--More-- end--More-- config endpoint-control app-detect predefined-signature 231--More-- end--More-- config endpoint-control app-detect predefined-signature 232--More-- end--More-- config endpoint-control app-detect predefined-signature 233--More-- end--More-- config endpoint-control app-detect predefined-signature 234--More-- end--More-- config endpoint-control app-detect predefined-signature 235--More-- end--More-- config endpoint-control app-detect predefined-signature 236--More-- end--More-- config endpoint-control app-detect predefined-signature 237--More-- end--More-- config endpoint-control app-detect predefined-signature 238--More-- end--More-- config endpoint-control app-detect predefined-signature 239--More-- end--More-- config endpoint-control app-detect predefined-signature 240--More-- end--More-- config endpoint-control app-detect predefined-signature 241--More-- end--More-- config endpoint-control app-detect predefined-signature 242--More-- end--More-- config endpoint-control app-detect predefined-signature 243--More-- end--More-- config endpoint-control app-detect predefined-signature 244--More-- end--More-- config endpoint-control app-detect predefined-signature 245--More-- end--More-- config endpoint-control app-detect predefined-signature 246--More-- end--More-- config endpoint-control app-detect predefined-signature 247--More-- end--More-- config endpoint-control app-detect predefined-signature 248

Page 97: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config endpoint-control app-detect predefined-signature 249--More-- end--More-- config endpoint-control app-detect predefined-signature 250--More-- end--More-- config endpoint-control app-detect predefined-signature 251--More-- end--More-- config endpoint-control app-detect predefined-signature 252--More-- end--More-- config endpoint-control app-detect predefined-signature 253--More-- end--More-- config endpoint-control app-detect predefined-signature 254--More-- end--More-- config endpoint-control app-detect predefined-signature 255--More-- end--More-- config endpoint-control app-detect predefined-signature 256--More-- end--More-- config endpoint-control app-detect predefined-signature 257--More-- end--More-- config endpoint-control app-detect predefined-signature 258--More-- end--More-- config endpoint-control app-detect predefined-signature 259--More-- end--More-- config endpoint-control app-detect predefined-signature 260--More-- end--More-- config endpoint-control app-detect predefined-signature 261--More-- end--More-- config endpoint-control app-detect predefined-signature 262--More-- end--More-- config endpoint-control app-detect predefined-signature 263--More-- end--More-- config endpoint-control app-detect predefined-signature 264--More-- end--More-- config endpoint-control app-detect predefined-signature 265--More-- end--More-- config endpoint-control app-detect predefined-signature 266--More-- end--More-- config endpoint-control app-detect predefined-signature 267--More-- end--More-- config endpoint-control app-detect predefined-signature 268--More-- end

Page 98: N_ FortiGate 200a Configuration.txt

--More-- config endpoint-control app-detect predefined-signature 269--More-- end--More-- config endpoint-control app-detect predefined-signature 270--More-- end--More-- config endpoint-control app-detect predefined-signature 271--More-- end--More-- config endpoint-control app-detect predefined-signature 272--More-- end--More-- config endpoint-control app-detect predefined-signature 273--More-- end--More-- config endpoint-control app-detect predefined-signature 274--More-- end--More-- config endpoint-control app-detect predefined-signature 275--More-- end--More-- config endpoint-control app-detect predefined-signature 276--More-- end--More-- config endpoint-control app-detect predefined-signature 277--More-- end--More-- config endpoint-control app-detect predefined-signature 278--More-- end--More-- config endpoint-control app-detect predefined-signature 279--More-- end--More-- config endpoint-control app-detect predefined-signature 280--More-- end--More-- config endpoint-control app-detect predefined-signature 281--More-- end--More-- config endpoint-control app-detect predefined-signature 282--More-- end--More-- config endpoint-control app-detect predefined-signature 283--More-- end--More-- config endpoint-control app-detect predefined-signature 284--More-- end--More-- config endpoint-control app-detect predefined-signature 285--More-- end--More-- config endpoint-control app-detect predefined-signature 286--More-- end--More-- config endpoint-control app-detect predefined-signature 287--More-- end--More-- config endpoint-control app-detect predefined-signature 288--More-- end--More-- config endpoint-control app-detect predefined-

Page 99: N_ FortiGate 200a Configuration.txt

signature 289--More-- end--More-- config endpoint-control app-detect predefined-signature 290--More-- end--More-- config endpoint-control app-detect predefined-signature 291--More-- end--More-- config endpoint-control app-detect predefined-signature 292--More-- end--More-- config endpoint-control app-detect predefined-signature 293--More-- end--More-- config endpoint-control app-detect predefined-signature 294--More-- end--More-- config endpoint-control app-detect predefined-signature 295--More-- end--More-- config endpoint-control app-detect predefined-signature 296--More-- end--More-- config endpoint-control app-detect predefined-signature 297--More-- end--More-- config endpoint-control app-detect predefined-signature 298--More-- end--More-- config endpoint-control app-detect predefined-signature 299--More-- end--More-- config endpoint-control app-detect predefined-signature 300--More-- end--More-- config endpoint-control app-detect predefined-signature 301--More-- end--More-- config endpoint-control app-detect predefined-signature 302--More-- end--More-- config endpoint-control app-detect predefined-signature 303--More-- end--More-- config endpoint-control app-detect predefined-signature 304--More-- end--More-- config endpoint-control app-detect predefined-signature 305--More-- end--More-- config endpoint-control app-detect predefined-signature 306--More-- end--More-- config endpoint-control app-detect predefined-signature 307--More-- end--More-- config endpoint-control app-detect predefined-signature 308--More-- end--More-- config endpoint-control app-detect predefined-signature 309

Page 100: N_ FortiGate 200a Configuration.txt

--More-- end--More-- config endpoint-control app-detect predefined-signature 310--More-- end--More-- config endpoint-control app-detect predefined-signature 311--More-- end--More-- config endpoint-control app-detect predefined-signature 312--More-- end--More-- config endpoint-control app-detect predefined-signature 313--More-- end--More-- config endpoint-control app-detect predefined-signature 314--More-- end--More-- config endpoint-control app-detect predefined-signature 315--More-- end--More-- config endpoint-control app-detect predefined-signature 316--More-- end--More-- config endpoint-control app-detect predefined-signature 317--More-- end--More-- config endpoint-control app-detect predefined-signature 318--More-- end--More-- config endpoint-control app-detect predefined-signature 319--More-- end--More-- config endpoint-control app-detect predefined-signature 320--More-- end--More-- config endpoint-control app-detect predefined-signature 321--More-- end--More-- config endpoint-control app-detect predefined-signature 322--More-- end--More-- config endpoint-control app-detect predefined-signature 323--More-- end--More-- config endpoint-control app-detect predefined-signature 324--More-- end--More-- config endpoint-control app-detect predefined-signature 325--More-- end--More-- config endpoint-control app-detect predefined-signature 326--More-- end--More--