Fortinet FortiGate 620B manual

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62

Ir a la página of

Buen manual de instrucciones

Las leyes obligan al vendedor a entregarle al comprador, junto con el producto, el manual de instrucciones Fortinet FortiGate 620B. La falta del manual o facilitar información incorrecta al consumidor constituyen una base de reclamación por no estar de acuerdo el producto con el contrato. Según la ley, está permitido adjuntar un manual de otra forma que no sea en papel, lo cual últimamente es bastante común y los fabricantes nos facilitan un manual gráfico, su versión electrónica Fortinet FortiGate 620B o vídeos de instrucciones para usuarios. La condición es que tenga una forma legible y entendible.

¿Qué es un manual de instrucciones?

El nombre proviene de la palabra latina “instructio”, es decir, ordenar. Por lo tanto, en un manual Fortinet FortiGate 620B se puede encontrar la descripción de las etapas de actuación. El propósito de un manual es enseñar, facilitar el encendido o el uso de un dispositivo o la realización de acciones concretas. Un manual de instrucciones también es una fuente de información acerca de un objeto o un servicio, es una pista.

Desafortunadamente pocos usuarios destinan su tiempo a leer manuales Fortinet FortiGate 620B, sin embargo, un buen manual nos permite, no solo conocer una cantidad de funcionalidades adicionales del dispositivo comprado, sino también evitar la mayoría de fallos.

Entonces, ¿qué debe contener el manual de instrucciones perfecto?

Sobre todo, un manual de instrucciones Fortinet FortiGate 620B debe contener:
- información acerca de las especificaciones técnicas del dispositivo Fortinet FortiGate 620B
- nombre de fabricante y año de fabricación del dispositivo Fortinet FortiGate 620B
- condiciones de uso, configuración y mantenimiento del dispositivo Fortinet FortiGate 620B
- marcas de seguridad y certificados que confirmen su concordancia con determinadas normativas

¿Por qué no leemos los manuales de instrucciones?

Normalmente es por la falta de tiempo y seguridad acerca de las funcionalidades determinadas de los dispositivos comprados. Desafortunadamente la conexión y el encendido de Fortinet FortiGate 620B no es suficiente. El manual de instrucciones siempre contiene una serie de indicaciones acerca de determinadas funcionalidades, normas de seguridad, consejos de mantenimiento (incluso qué productos usar), fallos eventuales de Fortinet FortiGate 620B y maneras de solucionar los problemas que puedan ocurrir durante su uso. Al final, en un manual se pueden encontrar los detalles de servicio técnico Fortinet en caso de que las soluciones propuestas no hayan funcionado. Actualmente gozan de éxito manuales de instrucciones en forma de animaciones interesantes o vídeo manuales que llegan al usuario mucho mejor que en forma de un folleto. Este tipo de manual ayuda a que el usuario vea el vídeo entero sin saltarse las especificaciones y las descripciones técnicas complicadas de Fortinet FortiGate 620B, como se suele hacer teniendo una versión en papel.

¿Por qué vale la pena leer los manuales de instrucciones?

Sobre todo es en ellos donde encontraremos las respuestas acerca de la construcción, las posibilidades del dispositivo Fortinet FortiGate 620B, el uso de determinados accesorios y una serie de informaciones que permiten aprovechar completamente sus funciones y comodidades.

Tras una compra exitosa de un equipo o un dispositivo, vale la pena dedicar un momento para familiarizarse con cada parte del manual Fortinet FortiGate 620B. Actualmente se preparan y traducen con dedicación, para que no solo sean comprensibles para los usuarios, sino que también cumplan su función básica de información y ayuda.

Índice de manuales de instrucciones

  • Página 1

    www.fortinet.com For tiGate-620B FortiO S 3 . 0 MR 6 INST ALL GUIDE[...]

  • Página 2

    FortiGate-620B Install Guide FortiOS 3.0 MR6 15 October 2008 01-30006-83 054-20081015 © Copyright 2008 Fortine t, Inc. All rights reserved. No part of this publication including text, examples , diagrams or illustrations may be reproduced, tra nsmitted, or translated in any form or by any means, electronic, mechanical, manual, op tical or otherwis[...]

  • Página 3

    Contents FortiGate-620B FortiOS 3.0 MR6 Install Guide 01-30006-83054-200810 15 3 Content s Contents...................................................................... .............. .......... 3 Introduction ............... ................................. .............................. .......... 7 Register your FortiGate unit ................[...]

  • Página 4

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 4 01-30006-83054-200810 15 Contents Configure the interfaces ............................ .................... ................ ....... 23 Configure a DNS server ...... ................ ................... ................ .............. 24 Adding a default route and gateway . ......... .................[...]

  • Página 5

    Contents FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 5 Changing interfaces to operate in SGMII or SerDes mode . ................ . 42 Configure the speed ............................ ................ ................... .............. 43 FortiGate Firmware ............ ................................. ................. .[...]

  • Página 6

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 6 01-30006-83054-200810 15 Contents[...]

  • Página 7

    Introduction Register your FortiGate unit FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 7 Introduction Welcome an d thank you for selecting Fortinet product s for your real-time network protection. The FortiGate Unified Threat Man agement System improves network security , reduces network misuse and abuse, and help s you us[...]

  • Página 8

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 8 01-30006-83054-200810 15 About the FortiGate-620B Introduction About the FortiGate-620B The FortiGate-620B is designed to raise the expect ations of mid-range security devices. Incorporating FortiASIC ne twork pr ocessors for firewall/VPN acceleration and the FortiASIC Content Processor for content ins[...]

  • Página 9

    Introduction Further Reading FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 9 • AMC modules – Describes how to insta ll and configure Advanced Mezzanine Cards for use in the FortiGate unit. • FortiGate Fir mware – Describes how to install, u pdate, restore and test firmware for the For tiGate device. Document convent[...]

  • Página 10

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 10 01-30006-83054-200810 15 Further Reading Introduction • FortiGate Administration Guide Provides basic informati on about how to configure a F ortiGate unit, including how to define FortiGate pr otection profiles and firewall policies; h ow to apply intrusion prevention, antivirus protecti on, web co[...]

  • Página 11

    Introduction Customer service a nd technical su pport FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 11 Comments on Fortinet te chnical documentation Please send informa tion about any errors or omissions in this docume nt, or any Fortinet tech nical documen tation, to techdoc@fo rtinet.com. Customer service and technical su[...]

  • Página 12

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 12 01-30006-83054-200810 15 Customer service and technical support Introduction[...]

  • Página 13

    Installing Environmental specifications FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 13 Inst alling This chapter describes in stalling your FortiGate unit in your server room, environmental specifications and how to mount the FortiGate in a rack if applicable. This chapter contains the follow ing topics: • Environmenta l[...]

  • Página 14

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 14 01-30006-83054-200810 15 Cautions and warnings Installing • Connect the equipment into an outlet on a circuit differen t from that to which the receiver is connecte d. • Consult the dealer or an experien ced radio/TV technician for help. The equipm ent compliance with FCC radiation exposu re limit[...]

  • Página 15

    Installing Cautions and warni ngs FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 15 Mounting If required to fit into a rack unit, remove the rubber feet from the bottom of the FortiGate u nit. The FortiG ate unit can be placed o n any fl at surface, or mounted in a sta ndard 19- inch rack unit. When placing the For tiGate un[...]

  • Página 16

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 16 01-30006-83054-200810 15 Plugging in the FortiGa te Installing Figure 3: Mounting in a rack Plugging in the FortiGate Use the following steps to conne ct the power supply to the FortiGate unit. T o power on the FortiGate unit 1 Ensure the power switch, located at the ba ck of the FortiGate unit is in [...]

  • Página 17

    Configuring NA T vs. T ransparent mode FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 17 Configuring This section provides an overview of t he operating modes of the FortiGate unit, NA T/Route and T ransp arent, and how to configure the FortiGate unit for e ach mode. There are two ways you can configure the FortiGa te unit, [...]

  • Página 18

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 18 01-30006-83054-200810 15 Connecting to the FortiGate unit Configuring Transparent mode In T ransparent m ode, the Fo rtiGate unit is invisible to the network . Similar to a network bridge, all FortiGate interfaces must be on the same subnet. Y ou only have to configure a mana gement IP address to make[...]

  • Página 19

    Configuring Connecting to the FortiGate unit FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 19 T o support a secure HTTPS authentication method, the For tiGate unit ships with a self-signed security certific ate, which is offered to remote clients whenever they initiate a HTTPS connecti on to the FortiGate unit. When you con[...]

  • Página 20

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 20 01-30006-83054-200810 15 Configuring NA T mode Configuring Configuring NA T mode Configuring NA T mode involves defining interface addresses and defa ult routes, and simple firewall policies. Y ou can use the web-based m anager or the CLI to configure the FortiGate unit in NA T/Route mode. Using the w[...]

  • Página 21

    Configuring Configuring NA T mode FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 21 4 Select OK. 5 Repeat this procedure for each interf ace as required. Configure a DNS server A DNS server is a service that conver ts symbolic node names to IP addresses. A domain name server (DNS server) impl ements the protoc ol. In simple [...]

  • Página 22

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 22 01-30006-83054-200810 15 Configuring NA T mode Configuring For an initial configuration, you must edit the factor y configured static d efault route to specify a different defau lt gateway for the FortiGat e unit. This will enable the flow of data th rough the FortiGate unit. For details on add ing ad[...]

  • Página 23

    Configuring Configuring NA T mode FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 23 3 Set the following and select OK. Firewall policy configurati on is the same in NA T/Route mode and T ransp arent mode. Note that these policies allo w all traffic throug h. No protection profiles have been applied. Ensure you create additio[...]

  • Página 24

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 24 01-30006-83054-200810 15 Configuring NA T mode Configuring T o set an interface to use PPPo E addressing config system interface edit external set mode pppoe set username <name_str> set password <psswrd> set ipunnumbered <ip_address> set disc-retry-timeout <integer_seconds> set[...]

  • Página 25

    Configuring Configuring NA T mode FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 25 In the factory default configuration, entr y number 1 in the S tatic Route list is associated with a destination address of 0.0.0.0/0.0.0.0, which means any/all destinations. This route is called the "sta tic default rout e". If no [...]

  • Página 26

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 26 01-30006-83054-200810 15 Configuring T ransparent mod e Configuring Configuring T ra nsp arent mode Configuring T ransparent mode in volves switchin g to T ransparent mode, configurin g the management IP ad dress, default routes, and simple firewa ll policies. Y ou can use the web-based man ager or th[...]

  • Página 27

    Configuring Configuring T r ansparent mode FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 27 For the initial installation, a single firewa ll policy that enables all traffic through will enable you to verify your configur ation is working. On lower-end unit s such a default firewall policy is already in plac e. For the highe[...]

  • Página 28

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 28 01-30006-83054-200810 15 Configuring T ransparent mod e Configuring T o switch to T ransparent mode config system settings set opmode transparent set manageip <address_ip> <netmask> set gateway <address_gateway> end Configure a DNS server A DNS server is a service that convert s symb[...]

  • Página 29

    Configuring V erify the conf iguration FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 29 Note that these policies allo w all traffic throug h. No protection profiles have been applied. Ensure you create additio nal firewall policies to accommodate you r network requirement s. V erify the configuration Y our FortiGate unit is[...]

  • Página 30

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 30 01-30006-83054-200810 15 Restoring a configuration Configuring Restoring a configuration Should you need to restore the config uration file, use the following steps. T o restore the FortiGat e configuration 1 Go to System > Maintenance > Backup & Restore . 2 Select to uplo ad the restor e f [...]

  • Página 31

    Configuring Addition al configurat ion FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 31 T o change the administrator p assword 1 Go to System > Admin > Administrators . 2 Select Change Password and enter a new p assword. 3 Select OK. Alternatively , you can also a dd new admini strator users by selecting Create New , [...]

  • Página 32

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 32 01-30006-83054-200810 15 Additional confi guration Configuring[...]

  • Página 33

    Advanced configuration Protection profiles FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 33 Advanced configuration The FortiGate unit and the FortiOS o perating system provide a wide range of features that enable you to control netwo rk and internet traffic and pr otect your network. This chapter describes some of these opt[...]

  • Página 34

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 34 01-30006-83054-200810 15 Firewall p olicies Advanced configuration The best way to begin creating your own protection pr ofile is to open a predefined profile. This way you can see how a profile is set up, an d then modify it suit your requirement s. Y ou access Protecti on profile options by going to[...]

  • Página 35

    Advanced configuration Antivirus options FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 35 Configuring firewall policies T o add or edit a firewall policy go to Firewall > Policy and select Edit on an existing policy , or select Create New to add a policy . The source and des tination Interface/Zone match the firewall pol[...]

  • Página 36

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 36 01-30006-83054-200810 15 AntiSpam options Advanced configuration • Graywar e - These are unsolicited commercial software programs that are installed on computer s, often without the user's consent or knowledge. Grayware progr ams are generally consider ed an annoyance, b ut these programs can c[...]

  • Página 37

    Advanced configuration Web fi ltering FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 37 Banned word lists are specific wor ds that may be typically found in email. The FortiGate u nit searches f or words or patter ns in email me ssages. If m atches are found, values assigned to the words are to ta lled. If the defined thresh[...]

  • Página 38

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 38 01-30006-83054-200810 15 Logging Advanced configuration T o configure content blocking, go to W eb Filter > Content Block . URL filter enables you to control additional web sites that you can block or allow . This enables you greater con trol over ce rtain URLs or sub-URLs. The FortiGate unit allow[...]

  • Página 39

    AMC modules Installing AMC filler units FortiGate-620B FortiOS 3.0 MR6 Install Guide 01-30006-83054-200810 15 39 AMC modules FortiGate AMC module s enable you to ex pand your FortiGate unit and ne twork environment. These module s enable you to provide small p acket performance though optica l or copper t ransceivers. A h ard disk modu le enables y[...]

  • Página 40

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 40 01-30006-83054-200810 15 Removing modules AMC modules T o insert a module into a FortiGa te chassis 1 Ensure the FortiGate unit is powered off before proceeding. 2 Remove the panel block on the FortiGate unit using the hot swa p latch. 3 Pull the latch on the module to the extend ed position. 4 Insert[...]

  • Página 41

    AMC modules Using the AMC modules FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 41 Formatting the hard disk When you first inst all the ASM-S08 in the F ortiGate unit, the hard disk may not be formatted. This will result in an error in the console wh en starting up the FortiGate unit, indicating that the hard drive could no[...]

  • Página 42

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 42 01-30006-83054-200810 15 Using the AMC modul es AMC modules Log configuration using the CLI Configure the FortiGate unit to log to the ASM-S08 using the CLI within the FortiAnalyzer command config log disk setting enable . For details on log configuration, see the FortiGate CLI Reference . Viewing log[...]

  • Página 43

    AMC modules Using the AMC modules FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 43 For these mu lti-mode SFP inte rfaces, SerD es is the defa ult mode. Y ou can use a CLI command to change the inte rface to operate in SGMII mode. Depending on th e type of transceivers you inst all, you need to configur e the FortiGate unit [...]

  • Página 44

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 44 01-30006-83054-200810 15 Using the AMC modul es AMC modules[...]

  • Página 45

    FortiGate Firmware Downloading firmware FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 45 FortiGate Firmware Fortinet periodically updates the For tiGat e firmware to include new featur es and address issues. After yo u have registered yo ur FortiGate unit, you can download FortiGate firmware updates is available for downloa[...]

  • Página 46

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 46 01-30006-83054-200810 15 Using the web-based manage r FortiGate Firmware T o download firmware 1 Log into the site using your user n ame and password. 2 Go to Firmware Images > FortiGate . 3 Select the most recent FortiOS version, and MR release and p atch release. 4 Locate the firmware for your Fo[...]

  • Página 47

    FortiGate Firmware Using the web-based manager FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 47 T o revert to a previous firmwar e version 1 Copy the firmware image file to the managem ent computer . 2 Log into the FortiGate web- based manager . 3 Go to System > St atus . 4 Under System Information > Firmware V ersion[...]

  • Página 48

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 48 01-30006-83054-200810 15 Using the CLI FortiGate Firmware T o configure the USB Au to-Inst all 1 Go to System > Maintenance > Backup and Restore . 2 Select the blue arrow to expa nd the Advanced options. 3 Select the following: • On system restart, auto matically update FortiGate configuration[...]

  • Página 49

    FortiGate Firmware Using the CLI FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 49 5 Enter the fo llowing command to copy the firmwar e image from the TFTP se rver to the FortiGate unit: execute restore image <name_str> <tftp_ip4> Where <name_str> is the nam e of the firmware image file an d <tftp_ip4>[...]

  • Página 50

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 50 01-30006-83054-200810 15 Installing firmware from a system reboot using the CLI FortiGate Firmware 4 Make sure the FortiGate unit can connect to th e TFTP server . Y ou can use the following comm and to pin g the comput er running th e TFTP server . For example, if the TFTP serv er ’s IP address is [...]

  • Página 51

    FortiGate Firmware Installing firmware from a system reboot using the CLI FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 51 If you are revert ing to a previou s FortiOS version, you might not be able to restore the previous configuration from the backup configuration file . T o inst all firmware from a syste m reboot 1 Conne[...]

  • Página 52

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 52 01-30006-83054-200810 15 Installing firmware from a system reboot using the CLI FortiGate Firmware 9 T ype the address of the TFTP server and press Enter : The following message appears: Enter Local Address [192.168.1.188]: 10 T ype an IP address the FortiGate unit can use to connect to the TFTP serve[...]

  • Página 53

    FortiGate Firmware Installing firmware from a system reboot using the CLI FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 53 T o restore configuration us ing the CLI 1 Log into the CLI. 2 Enter the following command to re store the configuration files: exec restore image usb <filename> The FortiGate unit responds with t[...]

  • Página 54

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 54 01-30006-83054-200810 15 T esting new firmware before installing FortiGate Firmware T esting new firmware before inst alling Y ou can test a new fi rmware image by installing the firmware image from a system reboot and saving it to system memory . After completing this procedu re, the FortiGate unit o[...]

  • Página 55

    FortiGate Firmware T esting new firmware before installing FortiGate-620B Forti OS 3.0 MR6 Install Guide 01-30006-83054-2008 1015 55 8 T ype G to get t he new firm ware image from the TF TP server . The following m essage appears: Enter TFTP server address [192.168.1.168]: 9 T ype the address of the TFTP ser ver and press Enter: The following m ess[...]

  • Página 56

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 56 01-30006-83054-200810 15 T esting new firmware before installing FortiGate Firmware[...]

  • Página 57

    Index FortiGate-620B FortiOS 3.0 MR6 Install Guide 01-30006-83054-200810 15 57 Index A adding a defa ult route 21, 24 additional resources 9 admin password 30 air flow 13 ambient te mperature 13 antispam options 36 antivirus options 35 auto-install 47 auto-install from CLI 53 B backing up 29 C certificate, security 19 CLI 19 upgrading the firmware [...]

  • Página 58

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 58 01-30006-83054-200810 15 Index P PADT timeout 21 password, changing 30 power off 16 PPPoE 24 protection profiles 33 R registering 7 restore 30 restoring previous firmware configuration 52 reverting firmware 46 S security certificate 19 shielded twisted pair 14 shut down 16 signatures, update 31 static[...]

  • Página 59

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 59 01-30006-83054-200810 15 Index[...]

  • Página 60

    FortiGate-620B FortiOS 3.0 MR6 Install Guide 60 01-30006-83054-200810 15 Index[...]

  • Página 61

    www.fortinet.com[...]

  • Página 62

    www.fortinet.com[...]