Fortinet 127 manual

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54

Go to page of

A good user manual

The rules should oblige the seller to give the purchaser an operating instrucion of Fortinet 127, along with an item. The lack of an instruction or false information given to customer shall constitute grounds to apply for a complaint because of nonconformity of goods with the contract. In accordance with the law, a customer can receive an instruction in non-paper form; lately graphic and electronic forms of the manuals, as well as instructional videos have been majorly used. A necessary precondition for this is the unmistakable, legible character of an instruction.

What is an instruction?

The term originates from the Latin word „instructio”, which means organizing. Therefore, in an instruction of Fortinet 127 one could find a process description. An instruction's purpose is to teach, to ease the start-up and an item's use or performance of certain activities. An instruction is a compilation of information about an item/a service, it is a clue.

Unfortunately, only a few customers devote their time to read an instruction of Fortinet 127. A good user manual introduces us to a number of additional functionalities of the purchased item, and also helps us to avoid the formation of most of the defects.

What should a perfect user manual contain?

First and foremost, an user manual of Fortinet 127 should contain:
- informations concerning technical data of Fortinet 127
- name of the manufacturer and a year of construction of the Fortinet 127 item
- rules of operation, control and maintenance of the Fortinet 127 item
- safety signs and mark certificates which confirm compatibility with appropriate standards

Why don't we read the manuals?

Usually it results from the lack of time and certainty about functionalities of purchased items. Unfortunately, networking and start-up of Fortinet 127 alone are not enough. An instruction contains a number of clues concerning respective functionalities, safety rules, maintenance methods (what means should be used), eventual defects of Fortinet 127, and methods of problem resolution. Eventually, when one still can't find the answer to his problems, he will be directed to the Fortinet service. Lately animated manuals and instructional videos are quite popular among customers. These kinds of user manuals are effective; they assure that a customer will familiarize himself with the whole material, and won't skip complicated, technical information of Fortinet 127.

Why one should read the manuals?

It is mostly in the manuals where we will find the details concerning construction and possibility of the Fortinet 127 item, and its use of respective accessory, as well as information concerning all the functions and facilities.

After a successful purchase of an item one should find a moment and get to know with every part of an instruction. Currently the manuals are carefully prearranged and translated, so they could be fully understood by its users. The manuals will serve as an informational aid.

Table of contents for the manual

  • Page 1

    FortiGate 500A Installation Guide Esc Ent er A CON SOLE 56 USB LAN 12 3 4 L1 L2 L3 L4 10/ 100 10/ 100/1 000 Ve r s i o n 2 . 8 0 M R 5 15 October 2004 01-28005-01 01-20041015[...]

  • Page 2

    © Copyright 2004 Fortine t Inc. All rights reserved . No part of this publication incl uding text, examples, di agrams or illustration s may be reproduced, transmitted, or translated in any form or by any means, electronic, m echanical, m anual, optical or otherwise, for any purpose, without prio r written pe rmission of F ortinet I nc. FortiGate-[...]

  • Page 3

    Contents FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 3 Table of Contents Introduction ............. .............................. ........................................................ ......... 5 Secure installation, configurat ion, and management ................ ................ ................... ....... 6 Web-based manager .[...]

  • Page 4

    Contents 4 01-28005-0101-2004101 5 Fortinet Inc. Transparent mode installation .... ............................................................... ......... 37 Preparing to configure Transparent mode ............ ................ .................... ................ ........ 37 Using the web-based manager ....................... ................ [...]

  • Page 5

    FortiGate-500A Inst allation Guide V ersion 2.80 MR5 FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 5 Introduction FortiGate A ntivirus Firew alls improve n etwork securit y , red uce networ k misuse and abuse, and help you use communication s resources more efficiently without compromising the performance of yo ur netw ork. FortiGate A[...]

  • Page 6

    6 01-28005-0101-2004101 5 Fortinet Inc. Web-based manage r Introduction Secure inst allation, configuration, and management The FortiGate unit default conf iguration includes default interface IP addr esses and is only a few steps away from protecting your netwo rk. There are several ways to configure basic FortiGate settings: • the web-based man[...]

  • Page 7

    Introduction Command line interface FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 7 Command line interface Y ou can access the FortiGate command lin e interface (CLI) by connecting a management compute r serial port to the Fo rtiGate RS-232 serial console connector . Y ou can also use T elnet or a secure SSH co nnection to connect to t[...]

  • Page 8

    8 01-28005-0101-2004101 5 Fortinet Inc. Setup wizard Introduction set opmode {nat | transparent} Y ou can en ter set opmode nat or set opmode transparent . • Square bracke ts [ ] to indica te that a keyword or variable is optional. For example: show system interface [<name_str>] T o show the settings for all interfaces, you can enter show s[...]

  • Page 9

    Introduction Comments on Fortine t technical documenta tion FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 9 Fortinet document ation Information about FortiGate produ cts is av ailable from the following FortiGate Gu ides: • FortiGate QuickS tart Guide Each QuickS tart Guide provides the basic information r equired to connect and inst[...]

  • Page 10

    10 01-28005-0101-2004101 5 Fortinet Inc. Comments on Fortinet technica l docume ntation Introduction Customer service and technical support For antiviru s and attack def inition up dates, firmware updates, updated product documentation , technical support informatio n , and other resources, please visit the Fortinet technical support we b site at h[...]

  • Page 11

    FortiGate-500A Inst allation Guide V ersion 2.80 MR5 FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 11 Getting st arted This section describes unp acking, setting up, and powering on a FortiGate Antivirus Firewall unit. This section includes: • Package content s • Mounting • T urning the FortiGate unit po wer on and o ff • Conne[...]

  • Page 12

    12 01-28005-0101-2004101 5 Fortinet Inc. Getting started Package content s The FortiGate-500A p ackage cont ains the following items: • FortiGate-500A Antivirus Firewall • one orange crossover ethe rnet cable (Fortinet p art number CC300248) • one gray regular ethern et cable (Fortinet part number CC300249) • one RJ-45 serial cable (Fortine[...]

  • Page 13

    Getting started FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 13 Power requirements • Power dissipation: 50 W (max) • AC input volt age: 100 to 2 40 V AC • AC input current: 1.6 A • Frequency: 50 to 60 H Environmental specifications • Operating temperature: 32 to 10 4°F (0 to 40°C) • S torage temperature: -13 to 158°F (-[...]

  • Page 14

    14 01-28005-0101-2004101 5 Fortinet Inc. Getting started T o power off the FortiGate unit Always shut down the FortiGate operatin g system properly bef ore turning off the power switch. 1 From the web-ba sed manage r , go to System > Maintenance > ShutDown , select Shut Down and select Apply , or from the CLI, enter: execute shutdown 2 T urn [...]

  • Page 15

    Getting started FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 15 3 S tart Internet Explorer and browse to the address http s://192.168.1.99. (r emember to include the “s” in https://). The FortiGate login is displayed. Figure 3: FortiG ate login 4 T ype admin in the Name field and select Login. Connecting to the command line interf[...]

  • Page 16

    16 01-28005-0101-2004101 5 Fortinet Inc. Getting started 5 Press Enter to connect to the FortiGate CLI. The following prompt is displayed: FortiGate-500A login: 6 Ty p e admin and press Enter twice. The following prompt is displayed: Welcome ! T ype ? to list available commands. For information about how to use the CLI, see the FortiGate C LI Refer[...]

  • Page 17

    Getting started Factory default NAT/Route mod e network configuration FortiGate-500A Installati on Guide 01-28005-0101-200 41015 17 Factory default NAT/Route m ode network configuration When the FortiGate unit is first p owered on , it is running in NA T/Rout e mode and has the basic ne twork config uration listed in Ta b l e 2 . This configura tio[...]

  • Page 18

    18 01-28005-0101-2004101 5 Fortinet Inc. Factory default Transpar ent mode network configuration Getting started Factory default Transparent mode network configuration In T ransparent mode, the FortiGate unit has the d efault network configuration listed in Ta b l e 3 . Factory default firewall configuration FortiGate firewall policies cont rol how[...]

  • Page 19

    Getting started Factory default protection profiles FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 19 Factory default protection profiles Use protection profiles to apply dif ferent protection settings for traf fic that is controlled by firewall po licies. Y ou can us e protection profiles to : • Configure antivirus protection for HT [...]

  • Page 20

    20 01-28005-0101-2004101 5 Fortinet Inc. NAT/Rout e mode Getting started Figure 4: We b protection profile settings Planning the FortiGate configuration Before you configure the FortiGate unit, you need to plan how to integrate the unit into the network. Amo ng other thing s, you must decide whet her you want th e unit to be visible to the network,[...]

  • Page 21

    Getting started NAT/Route mode with multiple external network conn ections FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 21 Y ou can add firewall policies to control w hether communications through the FortiGate unit operate in NA T or Route mode. Firewall policies control the flow of traf fic based on the sou rce addres s, destinatio [...]

  • Page 22

    22 01-28005-0101-2004101 5 Fortinet Inc. Transparent mode Getting started Figure 6: Example NA T/Route multipl e internet connection configu ration Transparent mode In T ransparent mode, the Fo rtiGate unit is invisible to the network. Similar to a network bridge, all FortiGate inte rfaces must be on the same subnet. Y ou only have to configure a m[...]

  • Page 23

    Getting started Configuration options FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 23 Web-based manager and setup wizard The FortiGate web-based ma nager is a full featured management to ol. Y ou can use the web-based manager to confi gure most FortiGate settings. The web-based manage r Setup Wizard guides you through the initia l con[...]

  • Page 24

    24 01-28005-0101-2004101 5 Fortinet Inc. Configuration opti ons Getting started[...]

  • Page 25

    FortiGate-500A Inst allation Guide V ersion 2.80 MR5 FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 25 NA T/Route mode inst allation This chapter describes ho w to install the FortiGate un it in NA T/Route mode. For information about installing a FortiGate unit in T r ansparent mode, see “T ransparent mode inst allation” on p age 37[...]

  • Page 26

    26 01-28005-0101-2004101 5 Fortinet Inc. DHCP or PPPoE confi guration NAT/Route mode installati on DHCP or PPPoE configuration Y ou can configure any FortiGate interface to acquire it s IP address from a DHCP or PPPoE server . Y our ISP may provide IP add resses using one of these protocols. T o use the FortiGate DHCP server , you need to configure[...]

  • Page 27

    NAT/Route mode installation Configuring basic settings FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 27 Using the web-based manager Y ou can use the web-based manager for the in itial configuration of the FortiGate unit. Y ou can also continue to use the web-based mana ger for all FortiGate unit settings. For information about co nnect[...]

  • Page 28

    28 01-28005-0101-2004101 5 Fortinet Inc. Configuring basic settin gs NAT/Route mode installati on T o add a default route Add a default route to configure wh ere the FortiGate unit sends traf fic destined for an external ne twork (usua lly the Interne t). A dding the default route also defines which interface is connected to an external ne twor k. [...]

  • Page 29

    NAT/Route mode installation Configuring the Fo rtiGate unit to oper ate in NAT/Route mode FortiGate-500A Installati on Guide 01-28005-0101-200 41015 29 T o add a default gateway to an interface The default gateway is usually configured for the interface connecte d to the Internet. Y ou can use the procedur e below to confi gure a de fault gateway f[...]

  • Page 30

    30 01-28005-0101-2004101 5 Fortinet Inc. Configur ing the FortiG ate unit to opera te in NAT/Ro ute mode NAT/Rout e mode instal lation Example T o set the IP address of the LAN interface to 192.16 8.2.99 and netmask to 255.255.255.0, enter: config system interface edit lan set ip 192.168.2.99 255.255.255.0 end 3 T o set the IP address and ne tmask [...]

  • Page 31

    NAT/Route mode installation Configuring the Fo rtiGate unit to oper ate in NAT/Route mode FortiGate-500A Installati on Guide 01-28005-0101-200 41015 31 6 Confirm that the addre sses are correct. Ente r: get system interface The CLI lists the IP address, netma sk, and other set tings for ea ch of the F ortiGate interfaces. T o configure DNS server s[...]

  • Page 32

    32 01-28005-0101-2004101 5 Fortinet Inc. Configur ing the FortiG ate unit to opera te in NAT/Ro ute mode NAT/Rout e mode instal lation Using the setup wizard From the web-based ma nager, you can use the setup wizard to complete the initial configuration of the FortiGate unit. For in formation about connecting to the web -based manager, see “C onn[...]

  • Page 33

    NAT/Route mode installati on Starting the setup wizard FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 33 Starting the setup wizard 1 In the web-based manager, sele ct Easy Setup Wizard. Figure 8: Select the Easy Setup W izard 2 Follow the instructions on th e wizard pages and use the in formation that you gathere d in T able 5 on page 2[...]

  • Page 34

    34 01-28005-0101-2004101 5 Fortinet Inc. Starting the setup wizard NAT/Route mode installati on Connecting the FortiGate unit to the network(s) After you co mplete the initial configuration, you ca n connect the Fo rtiGate unit between the internal ne twork and the Internet. There are 5 10/1 00 Base-T conn ectors on the FortiGate-500A: • LAN, a 4[...]

  • Page 35

    NAT/Route mode installati on Starting the setup wizard FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 35 3 Optionally connect Ports 3, 4, 5, and 6 to other networks. For example, you could conne ct port 3 to a DMZ network to provide access from the Internet to a web server or other server wit hout installing the serv ers on the internal[...]

  • Page 36

    36 01-28005-0101-2004101 5 Fortinet Inc. Starting the setup wizard NAT/Route mode installati on T o register the FortiGate unit After pur chasing and inst alling a new FortiGat e unit, you can register th e unit by goin g to the System Update Support page, or usin g a web browser to connect to http://support.fortinet .com and selecting Pr oduct Reg[...]

  • Page 37

    FortiGate-500A Inst allation Guide V ersion 2.80 MR5 FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 37 T ransp arent mode inst allation This chapter de scribes how to inst all a FortiGate unit in T ransp arent mode. If you want to install the FortiGate un it in NA T/Ro ute mode, see “NA T/Route mode installation” on pag e 25 . If yo[...]

  • Page 38

    38 01-28005-0101-2004101 5 Fortinet Inc. Transparen t mode install ation Using the web-based manager Y ou can use the web-based manager to complete the initial configuration of the FortiGate unit. Y ou can continue to use the web-based manager for all FortiGate unit settings. For information about co nnecting to the web-based manager, see “Connec[...]

  • Page 39

    Transparent mode installatio n Reco nnecting to the web-based manager FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 39 T o configure the default gateway 1 Go to System > Network > Management . 2 Set Default Gateway to the default gatewa y IP address that you recorded in T able 8 on page 38 . 3 Select Apply . Reconnecting to the w[...]

  • Page 40

    40 01-28005-0101-2004101 5 Fortinet Inc. Reconnecting to the web-based manager Transparent mode installation 4 After you set the last digit of the default gateway , press Enter . 5 Press Esc to return to the Main Menu. Y ou have now co mpleted the in itial configuration o f the FortiGate unit and you can proceed to “Next steps” on page 43 . Usi[...]

  • Page 41

    Transparent mode installatio n Reco nnecting to the web-based manager FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 41 Example config system manageip set ip 10.10.10.2 255.255.255.0 end 3 Confirm that the addre ss is correct. Enter: get system manageip The CLI lists the managemen t IP address and netmask. T o configure DNS server se tt[...]

  • Page 42

    42 01-28005-0101-2004101 5 Fortinet Inc. Reconnecting to the web-based manager Transparent mode installation Using the setup wizard From the web-based manager, you can use th e setup wizard to begin the initial configuration of the FortiGate unit. For in formation about connecting to the web -based manager, see “C onnecting to the web-based man a[...]

  • Page 43

    Transparent mode installatio n Reco nnecting to the web-based manager FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 43 For example, you can connect the Fort iGate-500A using the following ste ps: 1 Connect port 1 to the hub or switch connected to your internal network. 2 Connect port 2 to the network segment connected to the external f[...]

  • Page 44

    44 01-28005-0101-2004101 5 Fortinet Inc. Reconnecting to the web-based manager Transparent mode installation T o set the date and time For effective scheduling and logging, the FortiGate syst em date and time must be accurate. Y ou can either manually set the system date and time or configure the FortiGate unit to automatically keep its ti me corre[...]

  • Page 45

    FortiGate-500A Inst allation Guide V ersion 2.80 MR5 FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 45 High availability inst allation This chapter describes how to install two or more FortiGate units in an HA cluster . HA installation involves three basic steps: • Configuring FortiGate un its for HA operation • Connecting the clust[...]

  • Page 46

    46 01-28005-0101-2004101 5 Fortinet Inc. High availability configuration se ttings High availability installation T able 9: Hig h availability settings Mode Active-Active Load balancing and failo ve r HA. Each FortiGate unit in the HA cluster actively processes co nnections and monitors the statu s of the other Forti Gate unit s in the cluster . Th[...]

  • Page 47

    High availability installation Configuring Fort iGate units for HA usi ng the web-based manager FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 47 Configuring FortiGate units for HA using the web-based manager Use the followin g procedur e to configu re each For tiGate unit f or HA opera tion. T o change the FortiGate unit host name Chan[...]

  • Page 48

    48 01-28005-0101-2004101 5 Fortinet Inc. Configuring FortiGate units for HA usin g the CLI High availability installati on T o configure a FortiGate unit for HA operation 1 Go to System > Config > HA . 2 Select High Availability . 3 Select the mode. 4 Select a Group ID for the HA cluster . 5 If required, change the Unit Priority . 6 If requir[...]

  • Page 49

    High availability installation Configuring FortiGate units for HA using the CLI FortiGate-500A Installati on Guide 01-28005-0101-200 41015 49 T o configure the FortiGate unit for HA operation 1 Configure HA settings. Use the following command to: • Set the HA mode • Set the Group ID • Change the unit priority • Enable ov erride master • E[...]

  • Page 50

    50 01-28005-0101-2004101 5 Fortinet Inc. Configuring FortiGate units for HA usin g the CLI High availability installati on Inserting an HA cluster into your networ k temporarily interrupt s communications on the network because ne w physical conn ections are being made to route traf fic through the cluster . Also, starting th e cluster inte rrupts [...]

  • Page 51

    High availability installation Configuring FortiGate units for HA using the CLI FortiGate-500A Installati on Guide 01-28005-0101-200 41015 51 2 Power on all the FortiGat e units in the cluster . As the units st art, they negotiate to choose the primary cluste r unit and the subordinat e units. This negotiation occurs with no user interventio n and [...]

  • Page 52

    52 01-28005-0101-2004101 5 Fortinet Inc. Configuring FortiGate units for HA usin g the CLI High availability installati on[...]

  • Page 53

    FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 53 FortiGate-500A Inst allation Guide V ersion 2.80 MR5 Index C CLI 7 configuring IP addresses 40 configuring NAT/Route mode 29 connecting to 15 cluster connecting 49, 51 command line interface 7 connect cluster 49, 51 connecting to network 34 , 42 web-based manager 14 customer service 10 D[...]

  • Page 54

    54 01-28005-0101-2004101 5 Fortinet Inc. Index[...]