Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To configure a firewall rule, define the traffic it should match—direction, interfaces or zones, source and destination, service or ports, and schedule—then choose an action and place the rule correctly in the policy order. FortiGate uses firewall policies; Cisco Firepower Threat Defense (FTD) uses access-control rules within an access-control policy. Treat NAT as a separate configuration decision, and use the guide for your installed software version and management interface.

How do FortiGate and Cisco Firepower rules differ?

Both products evaluate traffic against configured conditions, but their policy terms, ordering, and NAT workflows are not interchangeable. Fortinet’s FortiOS 7.6.6 Administration Guide puts the basic relationship plainly: “Any traffic going through a FortiGate unit has to be associated with a policy.” On FortiGate, that policy is a firewall policy. In Cisco FMC, the traffic decision is made through access-control rules grouped in an access-control policy; translation is configured separately in an FTD NAT policy.

Area FortiGate / FortiOS Cisco Firepower / Secure Firewall Threat Defense
Traffic decision Firewall policy matched using inputs such as interfaces, addresses, service, schedule, and action. Access-control rule in an access-control policy; rule conditions and action determine handling.
Ordering Policies are checked in sequence; FortiOS also offers an interface-pair view. FMC access-control rules are evaluated in configured order; normally the first matching rule determines handling.
NAT configuration Source NAT may be configured on an IPv4 policy or through Central SNAT, depending on device configuration. NAT is configured in a separate policy with an ordered table divided into sections.
Documented management/version scope Procedures cited here cover FortiOS 7.4.4, 7.6.1, and 7.6.6; labels and features can vary by release. Procedures cited here cover FMC and FDM documentation version 7.0, plus a Firepower 1100 FMC local-management quick-start guide updated March 20, 2026. Exact menus depend on manager and release.

An allow or accept action permits traffic at that policy stage; it does not necessarily mean that no further inspection applies. In Cisco FMC, an allow rule can still apply intrusion or file inspection before traffic reaches an asset or leaves the network.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should you check before creating a rule?

Write down one representative flow before changing the policy. A rule can be syntactically valid and still fail to match if, for example, the wrong interface, address object, protocol, port, or schedule is selected.

#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
  • Source host or network and destination host or network.
  • Ingress and egress interface or, where applicable, zone.
  • Protocol and destination service or port.
  • When the rule should apply, including the intended schedule.
  • Whether the traffic should be allowed, denied, monitored, trusted, or inspected under the product’s available actions.
  • Whether the flow needs source or destination translation, and which NAT configuration is already in use.

Confirm that the route exists before diagnosing policy matching. Fortinet’s policy lookup guidance explicitly requires a relevant route; a policy cannot compensate for missing routing.

How do you create a FortiGate firewall policy?

Create and scope the policy in the GUI

  1. In the FortiOS 7.4.4 GUI, open Policy & Objects > Firewall Policy, then select Create New.
  2. Enter a policy name and choose the applicable incoming and outgoing interfaces.
  3. Select the source and destination address objects, schedule, and service that describe the intended flow.
  4. Choose the action, such as Accept or deny, consistent with the required traffic decision.
  5. Review the policy’s position relative to other policies, then save it.

The guide’s example uses LAN (port1) to WAN (port2), Always, All, and Accept. These are example values, not safe defaults for every deployment. In particular, scope addresses and services to the traffic that actually needs access instead of copying broad example values into a production policy.

Rank #2
Sale
FortiGate-60F Firewall Appliance - 10 Gigabit Ethernet RJ45 Ports, Includes DMZ, WAN & Internal Ports (Appliance Only, No Subscription) (FG-60F)
  • Extensive Connectivity Options: The FortiGate 60F is designed with 10 GE RJ45 ports, including 2 WAN ports, 1 DMZ port, and 7 internal ports, offering broad flexibility and high-density connections for diverse enterprise networking needs.
  • Superior Performance for Secure Networks: Features powerful system-on-a-chip acceleration to deliver top-tier security with 1.4 Gbps IPS throughput and 700 Mbps threat protection throughput, ensuring effective defense against advanced threats.
  • Enhanced SSL Inspection and SD-WAN Capabilities: Utilizes purpose-built security processor technology to provide the industry's highest SSL inspection performance and robust SD-WAN functionality for secure, high-speed network operations.
  • Simple and Effective Management: Comes equipped with a user-friendly management console that supports comprehensive network automation and visibility, alongside Zero Touch Integration with Fortinet's Security Fabric for streamlined deployment.
  • Advanced Security Features: Leverages continuous threat intelligence from AI-powered FortiGuard Labs, identifying and mitigating both known and unknown threats, enhancing security across all network traffic, whether encrypted or not.

Check order and matching

FortiOS 7.6.1 provides a By Sequence view that shows policy check order; policies can be moved by policy ID. Review the order when a flow appears to hit the wrong rule or a more general policy appears before the intended one. FortiGate also provides an interface-pair policy view, so confirm which view you are using when interpreting policy placement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The policy lookup tool can help check a flow using its source interface, protocol, source and destination addresses, and ports. It requires the relevant route to exist and is unsupported in transparent mode. First confirm routing, then use the lookup and policy sequence to investigate the actual match.

Rank #3
FortiGate-40F Firewall Appliance plus 1 Year FortiCare Premium and FortiGuard Unified Threat Protection (UTP) (FG-40F-BDL-950-12)
  • INTEGRATED FIREWALL APPLIANCE AND SECURITY SERVICES: Comes with FortiGate-40F Firewall Appliance, 1 year of FortiCare Premium, and FortiGuard Unified Threat Protection.
  • UTP SECURITY FEATURES: Offers protection from advanced threats with DNS filtering, URL filtering, video filtering, and controls against botnets.
  • IDEAL FOR SMALLER SETTINGS: Best suited for small to mid-sized businesses needing reliable security without the complexity of larger systems.
  • CONTINUOUS SUPPORT AND MAINTENANCE: FortiCare Premium ensures that technical help is readily available to manage and troubleshoot issues.
  • COMPACT AND EFFECTIVE: Provides a powerful, yet compact security solution that effectively protects against a wide range of cyber threats.

Choose the correct source NAT path

Do not assume that creating an accepting firewall policy also creates the required translation. In a FortiGate configuration using per-policy NAT, the FortiOS 7.6.6 CLI example enables NAT with set nat enable in the firewall policy. Central SNAT is a different path: its SNAT map is evaluated top-down and applied after the security policy. When central NAT is enabled, the per-policy IPv4 NAT option is skipped, so SNAT must be configured through the central SNAT map. Check the device’s NAT mode and existing configuration before choosing a path or following release-specific steps.

Account for VIP-related deny matching

Virtual IP (VIP) objects can change how FortiGate policies match traffic. In the documented FortiOS 7.6.6 case, a deny policy intended to block traffic for a VIP-backed accept policy needs match-vip enabled and must be ordered to match before that accept policy. New deny policies enable this option by default in that documented case. If a VIP is involved, ordinary policy-order checks alone may not explain the result.

Rank #4
Fortinet FortiGate-30G Firewall for Small Offices with 4 Gigabit Ethernet RJ45 Ports (FG-30G)
  • Single appliance with integrated firewalling, SD-WAN and Wi-Fi controller reduces complexity of WLAN management. Its zero-touch deployment helps optimize your onboarding experience.
  • Built on a patented secure processor, this compact network firewall delivers the highest level of security and performance in its class – 800 Mbps IPS | 500 Mbps threat protection.
  • User-friendly management console gives you centralized visibility and simplifies policy enforcement across your network. Its zero-touch deployment helps you optimize your onboarding experience.
  • Compact and fanless design equipped with 4 GE RJ45 ports (1 WAN port and 3 internal ports) provide essential connectivity and flexibility for various network configurations in a small-scale environment.
  • Fortinet is the most deployed and trusted firewall from businesses worldwide with 99.98% security effectiveness, surpassing competition. Fortinet is the only vendor recognized as a firewall leader 13 consecutive years by Gartner.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How do you configure Cisco Firepower access-control rules?

In Cisco FMC, rules are grouped in an access-control policy and evaluated in the configured order. In most cases, the first rule whose conditions match determines handling. Build the rule around the intended traffic conditions and choose the appropriate action; Cisco FMC’s documented actions include Monitor, Trust, Block, and Allow. Review the order so a broader matching rule does not take precedence over the intended rule.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not treat Allow as a guarantee that traffic bypasses inspection. An allow rule can invoke intrusion or file inspection before traffic proceeds. The precise configuration screens vary by release and management plane; the rule behavior described here is from Cisco FMC documentation version 7.0, not a universal menu path for every FTD deployment.

Best Value
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

How do you configure Cisco FTD NAT separately?

FTD NAT has its own policy and ordered table. The table is evaluated through sections 1, 2, and 3 until a match is found. Manual NAT rules in section 1 are first-match in their configured order, so put more specific matching rules ahead of broader overlapping rules. Cisco recommends keeping NAT rules simple and planning their order carefully.

Scoped outbound interface PAT example

A Cisco Firepower 1100 FMC local-management quick-start guide updated March 20, 2026, illustrates an outbound dynamic Auto NAT setup. Its example creates a NAT policy, adds a dynamic Auto NAT rule, selects the outside zone, chooses an original source network object, and translates the source to the destination interface IP for interface PAT. This is a specific FMC/local-management example, not a universal sequence of menus for FDM or every FTD version.

  1. Create a NAT policy in the documented FMC local-management workflow.
  2. Add a dynamic Auto NAT rule.
  3. Select the outside zone and the original source network object appropriate to the intended traffic.
  4. Set the translated source to the destination interface IP for interface PAT.
  5. Review the NAT policy’s table section and order, especially if other rules could match the same traffic.

Keep the NAT decision separate from the access-control decision: verify that the traffic is permitted by the access-control policy and that the intended NAT rule matches it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do you troubleshoot a rule that does not work?

  1. Describe the flow precisely. Record source, destination, ingress and egress interfaces or zones, protocol, ports, and expected time window.
  2. Check routing. Confirm that the relevant route exists before attributing the failure to a policy.
  3. Inspect the traffic decision and order. On FortiGate, review the By Sequence order and use policy lookup where supported. In Cisco FMC, identify the first access-control rule whose conditions match.
  4. Inspect NAT independently. Confirm the correct FortiGate NAT mode or, on Cisco, the matching NAT table section and rule order. A correct access decision does not prove that translation is correct.
  5. Check product-specific exceptions and scope. For FortiGate traffic involving a VIP, verify the documented match-vip behavior. Confirm that your instructions match the installed release and manager rather than assuming menus are identical across versions.

Make changes through your organization’s change-control process. These steps describe vendor-documented configuration behavior; they do not establish that a particular rule has been deployed or tested on your device.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.