config system interface
edit "vsw.lan31"
set vdom "root"
set ip [Link] [Link]
set allowaccess ping
set alias "RedeVideoAnalytics"
set device-identification enable
set role lan
set interface "fortilink"
set vlanid 31
next
end
config system dhcp server
edit 0
set dns-service local
set wifi-ac-service local
set ntp-service local
set default-gateway [Link]
set netmask [Link]
set interface "vsw.lan31"
config ip-range
edit 1
set start-ip [Link]
set end-ip [Link]
next
end
next
end
config firewall address
edit "[Link]"
set type fqdn
set fqdn "[Link]"
next
edit "[Link]"
set type fqdn
set fqdn "[Link]"
next
edit "DNS GOOGLE"
set subnet [Link] [Link]
next
edit "DNS GOOGLE 2"
set subnet [Link] [Link]
next
edit "RedeVideoAnalytics"
set associated-interface "vsw.lan31"
set subnet [Link] [Link]
next
edit "addr-[Link]"
set subnet [Link] [Link]
next
edit "addr-[Link]"
set subnet [Link] [Link]
next
edit "addr-[Link]"
set subnet [Link] [Link]
next
edit "addr-[Link]"
set subnet [Link] [Link]
next
edit "addr-[Link]"
set subnet [Link] [Link]
next
edit "addr-[Link]"
set subnet [Link] [Link]
next
edit "addr-[Link]"
set subnet [Link] [Link]
next
edit "addr-[Link]"
set subnet [Link] [Link]
next
edit "addr-[Link]"
set subnet [Link] [Link]
next
edit "addr-[Link]"
set subnet [Link] [Link]
next
edit "addr-[Link]"
set subnet [Link] [Link]
next
edit "addr-[Link]"
set subnet [Link] [Link]
next
edit "addr-[Link]"
set subnet [Link] [Link]
next
edit "addr-[Link]"
set subnet [Link] [Link]
next
edit "addr-[Link]"
set subnet [Link] [Link]
next
edit "[Link]"
set type fqdn
set fqdn "[Link]"
next
edit "addr-[Link]"
set subnet [Link] [Link]
next
end
config firewall addrgrp
edit "G_VideoAnalytics"
set member "[Link]" "DNS GOOGLE" "DNS GOOGLE
2" "[Link]" "addr-[Link]" "addr-[Link]" "addr-
[Link]" "addr-[Link]" "addr-[Link]" "addr-[Link]" "addr-
[Link]" "addr-[Link]" "addr-[Link]" "addr-[Link]" "addr-
[Link]" "addr-[Link]" "addr-[Link]" "addr-[Link]" "addr-
[Link]" "[Link]" "addr-[Link]"
next
end
config firewall service category
edit "IoT"
set comment "Internet over things"
next
edit "Tunneling"
set comment "Tunneling - VPN"
next
end
config firewall service custom
edit "WireguardVPN"
set category "Tunneling"
set udp-portrange 51820
next
edit "SSH"
set category "Remote Access"
set tcp-portrange 22
next
end
config firewall service group
edit "G_VideoAnalytics"
set member "DNS" "HTTPS" "SSH" "SMTPS" "WireguardVPN"
next
end
config firewall policy
edit 0
set name "VideoAnalytics > WAN"
set srcintf "vsw.lan31"
set dstintf "virtual-wan-link"
set action accept
set srcaddr "RedeVideoAnalytics"
set dstaddr "G_VideoAnalytics"
set schedule "always"
set service "G_VideoAnalytics"
set utm-status enable
set ssl-ssh-profile "certificate-inspection"
set av-profile "default"
set logtraffic all
set nat enable
next
end