background image

www.fortinet.com

FortiGate-224B 
FortiOS 3.0 MR6

I N S T A L L   G U I D E

Summary of Contents for FortiGate 224B

Page 1: ...www fortinet com FortiGate 224B FortiOS 3 0 MR6 I N S T A L L G U I D E ...

Page 2: ...revention System DTPS APSecure FortiASIC FortiBIOS FortiBridge FortiClient FortiGate FortiGate Unified Threat Management System FortiGuard Antispam FortiGuard Antivirus FortiGuard Intrusion FortiGuard Web FortiLog FortiAnalyzer FortiManager FortiOS FortiPartner FortiProtect FortiReporter FortiResponse FortiShield and FortiVoIP are trademarks of Fortinet Inc in the United States and or other countr...

Page 3: ... Environmental specifications 11 Cautions and warnings 12 Grounding 12 Rack mount instructions 12 Mounting 12 Plugging in the FortiGate 14 Connecting to the network 14 Turning off the FortiGate unit 14 Configuring 15 NAT vs Transparent mode 15 NAT mode 15 Transparent mode 16 Connecting to the FortiGate unit 16 Connecting to the web based manager 16 Connecting to the CLI 17 Configuring NAT mode 18 ...

Page 4: ...ion 27 Backing up the configuration 27 Restoring a configuration 28 Additional configuration 28 Set the time and date 28 Set the Administrator password 28 Configure FortiGuard 29 Updating antivirus and IPS signatures 29 Advanced configuration 31 Protection profiles 31 Firewall policies 32 Configuring firewall policies 33 Antivirus options 33 AntiSpam options 34 Web filtering 35 Logging 36 FortiGat...

Page 5: ... 20080815 5 Installing firmware from a system reboot using the CLI 42 Restoring the previous configuration 44 Backup and Restore from a USB key 44 Using the USB Auto Install 45 Additional CLI Commands for a USB key 45 Testing new firmware before installing 46 Index 49 ...

Page 6: ...FortiGate 224B FortiOS 3 0 MR6 Install Guide 6 01 30006 0451 20080815 Contents ...

Page 7: ...t Management System uses Fortinet s Dynamic Threat Prevention System DTPS technology which leverages breakthroughs in chip design networking security and content analysis The unique ASIC based architecture analyzes content and behavior in real time enabling key applications to be deployed right at the network edge where they are most effective at protecting your networks Register your FortiGate un...

Page 8: ...ortiGate 224B About this document This document explains how to install and configure your FortiGate unit onto your network This document also includes how to install and upgrade new firmware versions on your FortiGate unit This document contains the following chapters Installing Describes setting up and powering on a FortiGate unit Configuring Provides an overview of the operating modes of the Fo...

Page 9: ...n web content filtering and spam filtering and how to configure a VPN FortiGate online help Provides a context sensitive and searchable version of the Administration Guide in HTML format You can access online help from the web based manager as you work FortiGate CLI Reference Describes how to use the FortiGate CLI and contains a reference to all FortiGate CLI commands Caution Warns you about comma...

Page 10: ...Guide Explains how to configure a PPTP VPN using the web based manager FortiGate Certificate Management User Guide Contains procedures for managing digital certificates including generating certificate requests installing signed certificates importing CA root certificates and certificate revocation lists and backing up and restoring installed certificates and private keys FortiGate VLANs and VDOMs...

Page 11: ...ure that the appliance has at least 1 5 in 3 75 cm of clearance on each side to allow for adequate air flow and cooling This device complies with part FCC Class A Part 15 UL CUL C Tick CE and VCCI Operation is subject to the following two conditions This device may not cause harmful interference and This device must accept any interference received including interference that may cause undesired o...

Page 12: ...erature of the rack environment may be greater than room ambient Therefore consideration should be given to installing the equipment in an environment compatible with the maximum ambient temperature Tma specified by the manufacturer Reduced Air Flow Installation of the equipment in a rack should be such that the amount of air flow required for safe operation of the equipment is not compromised Mec...

Page 13: ...trate how the brackets should be mounted Note that the screw configuration may vary depending on your FortiGate unit Figure 2 Installed mounting brackets 2 Position the FortiGate unit in the rack to allow for sufficient air flow 3 Line up the mounting bracket holes to the holes on the rack ensuring the FortiGate unit is level 4 Finger tighten the screws to attach the FortiGate unit to the rack 5 O...

Page 14: ... position indicated by the I Connecting to the network Using the supplied Ethernet cable connect one end of the cable to your router or modem whatever the connection is to the Internet Connect the other end to the FortiGate unit Connect to either the External WAN port or port 1 Connect additional cable to the Internal port or port 2 and your internal hub or switch Turning off the FortiGate unit Al...

Page 15: ...mode and Transparent mode Both include the same robust network security features such as antispam antivirus VPN and firewall policies NAT mode In NAT Route mode the FortiGate unit is visible to the network Like a router all its interfaces are on different subnets In NAT mode each port is on a different subnet enabling you to have a single IP address available to the public Internet The FortiGate u...

Page 16: ...s using the web based manger a GUI interface using a current web browser such as FireFox or Internet Explorer using the command line interface CLI a command line interface similar to DOS or UNIX commands using an SSH terminal or Telnet terminal Connecting to the web based manager To connect to the web based manager you require a computer with an Ethernet connection Microsoft Internet Explorer vers...

Page 17: ...the FortiGate unit redirects the connection This is an informational message Select OK to continue logging in 4 Type admin in the Name field and select Login Connecting to the CLI To connect to the FortiGate CLI you require a computer with an available communications port a serial cable either a RJ 45 to DB 9 or null modem cable whichever was included in your FortiGate package terminal emulation s...

Page 18: ...t gateway retrieved from the DHCP server The administrative distance specifies the relative priority of a route when there are multiple routes to the same destination A lower administrative distance indicates a more preferred route Retrieve default gateway from server Enable to retrieve a default gateway IP address from the DHCP server The default gateway is added to the static routing table Overr...

Page 19: ...route is called the static default route If no other routes are present in the routing table and a packet needs to be forwarded beyond the FortiGate unit the factory configured static default route causes the FortiGate unit to forward the packet to the default gateway Initial PADT Timeout Initial PPPoE Active Discovery Terminate PADT timeout in seconds Use this timeout to shut down the PPPoE sessi...

Page 20: ...rtiGate interfaces Firewall policies define how the FortiGate unit processes the packets in a communication session You can configure the firewall policies to allow only specific traffic users and specific times when traffic is allowed For the initial installation a single firewall policy that enables all traffic through will enable you to verify your configuration is working On lower end units su...

Page 21: ... Connecting to the CLI on page 17 before beginning Configure the interfaces When shipped the FortiGate unit has a default address of 192 168 1 99 and a netmask of 255 255 255 0 for either the Port 1 or Internal interface You need to configure this and other ports for use on your network To set an interface to use a static address config system interface edit interface_name set mode static set ip a...

Page 22: ...erver IP addresses are typically provided by your internet service provider To configure DNS server settings config system dns set autosvr enable disable set primary address_ip set secondary address_ip end Note if you set the autosvr to enable you do not have to configure the primary or secondary DNS server IP addresses Adding a default route and gateway A route provides the FortiGate unit with th...

Page 23: ...flow through the FortiGate interfaces Firewall policies to define the FortiGate unit process the packets in a communication session You can configure the firewall policies to allow only specific traffic users and specific times when traffic is allowed For the initial installation a single firewall policy that enables all traffic through will enable you to verify your configuration is working On lo...

Page 24: ... address and the Default Gateway address The default gateway IP address is required to tell the FortiGate unit where to send network traffic to other networks 5 Select Apply Configure a DNS server A DNS server is a service that converts symbolic node names to IP addresses A domain name server DNS server implements the protocol In simple terms it acts as a phone book for the Internet A DNS server m...

Page 25: ...rewall policy configuration is the same in NAT Route mode and Transparent mode Note that these policies allow all traffic through No protection profiles have been applied Ensure you create additional firewall policies to accommodate your network requirements Using the CLI After connecting to the CLI you can use the following procedures to complete the basic configuration of the FortiGate unit Ensu...

Page 26: ... DNS server IP addresses Adding firewall policies Firewall policies enable traffic to flow through the FortiGate interfaces Firewall policies define the FortiGate unit process the packets in a communication session You can configure the firewall policies to allow only specific traffic users and specific times when traffic is allowed For the initial installation a single firewall policy that enable...

Page 27: ...red and working correctly it is extremely important that you back up your configuration By backing up the configuration you ensure that if you need to reset the FortiGate unit for whatever reason you will be able to quickly return it to operation with minimal effort To back up the FortiGate configuration 1 Go to System Maintenance Backup Restore 2 Select to back up to your PC or to a USB key The U...

Page 28: ...le not mandatory they will help in ensuring better control with the firewall Set the time and date For effective scheduling and logging the FortiGate system date and time must be accurate You can either manually set the system date and time or configure the FortiGate unit to automatically keep its time correct by synchronizing with a Network Time Protocol NTP server To set the date and time 1 Go t...

Page 29: ...red your FortiGate unit you can update antivirus and IPS signatures The FortiGuard Center enables you to receive push updates allow push update to a specific IP address and schedule updates for daily weekly or hourly intervals To update antivirus definitions and IPS signatures 1 Go to System Maintenance FortiGuard 2 Select the blue arrow for AntiVirus and IPS Options to expand the options 3 Select...

Page 30: ...FortiGate 224B FortiOS 3 0 MR6 Install Guide 30 01 30006 0451 20080815 Additional configuration Configuring ...

Page 31: ...g spam filtering content archiving instant messaging filtering and access control P2P access and bandwidth control logging options for policies and configurations within the policies rate limiting for VoIP protocols Using protection profiles you can customize types and levels of protection for different firewall policies For example while traffic between internal and external addresses might need ...

Page 32: ...e firewall action for the connection The action can be to allow the connection deny the connection require authentication before the connection is allowed or process the packet as an IPSec VPN connection You can configure each firewall policy to route connections or apply network address translation NAT to translate source and destination IP addresses and ports You also add protection profiles to ...

Page 33: ...you can apply FortiGate features such as virus scanning and authentication to the communication session accepted by the policy Add DENY policies to deny communication sessions Add IPSec encryption policies to enable IPSec tunnel mode VPN traffic and SSL VPN encryption policies to enable SSL VPN traffic Firewall encryption policies determine which types of IP traffic will be permitted during an IPS...

Page 34: ... AntiVirus Config Grayware Antivirus settings are turned on in the protection profile In the protection profile you can enable antivirus options for specific services and which services will use the file patterns as a part of the antivirus process To configure antivirus protection profile settings go to Firewall Protection Profile Select edit for a profile and select the Anti Virus options For det...

Page 35: ...es the email address of the message s sender to the email address list in sequence If a match is found the action associated with the email address is taken If no match is found the message is passed to the next enabled antispam filter To configure black white lists go to AntiSpam Black White List You enable antispam options for each mail service POP3 IMAP and SMTP in the protection profile To con...

Page 36: ... You need to have a FortiGuard subscription to take advantage of FortiGuard web filtering The FortiGate unit also enables you to override the FortiGuard filtering designation and you can add your own To customize your FortiGuard web filtering go to Web Filter FortiGuard Web Filter For details and configuration options for the web filtering features and settings see the FortiGate Administration Gui...

Page 37: ...patch release before upgrading the firmware Follow the steps below download and review the release notes for the patch release download the patch release back up the current configuration install the patch release using the procedure Testing new firmware before installing on page 46 test the patch release until you are satisfied that it applies to your configuration Installing a patch release with...

Page 38: ...path and filename of the firmware image file or select Browse and locate the file 6 Select OK The FortiGate unit uploads the firmware image file upgrades to the new firmware version restarts and displays the FortiGate login This process takes a few minutes Reverting to a previous version The following procedures revert the FortiGate unit to its factory default configuration and deletes IPS custom ...

Page 39: ...the FortiGate unit must recognize that the key is installed in its USB port To backup configuration 1 Go to System Maintenance Backup and Restore 2 Select USB Disk from the backup configuration to list 3 Enter a file name for the configuration file 4 Select Backup To restore configuration 1 Go to System Maintenance Backup and Restore 2 Select USB Disk from the restore configuration from list 3 Sel...

Page 40: ...s included with the firmware release you are installing After you install new firmware make sure that antivirus and attack definitions are up to date You can also use the CLI command execute update now to update the antivirus and attack definitions For details see the FortiGate Administration Guide Before you begin ensure you have a TFTP server running and accessible to the FortiGate unit To upgra...

Page 41: ... messages Before beginning this procedure it is recommended that you back up the FortiGate unit system configuration using the command execute backup config back up the IPS custom signatures using the command execute backup ipsuserdefsig back up web content and email filtering lists If you are reverting to a previous FortiOS version for example reverting from FortiOS v3 0 to FortiOS v2 80 you migh...

Page 42: ...age from tftp server OK Check image OK This operation will downgrade the current firmware version Do you want to continue y n 7 Type y The FortiGate unit reverts to the old firmware version resets the configuration to factory defaults and restarts This process takes a few minutes 8 Reconnect to the CLI 9 To restore your previous configuration if needed use the command execute restore config name_s...

Page 43: ...ng message This operation will reboot the system Do you want to continue y n 7 Type y As the FortiGate unit starts a series of system startup messages appears When the following messages appears Press any key to display configuration menu Immediately press any key to interrupt the system startup If you successfully interrupt the startup process the following messages appears G Get firmware image f...

Page 44: ...the previous configuration Change the internal interface address if required You can do this from the CLI using the following command config system interface edit interface set ip address_ip4mask set allowaccess ping https ssh telnet http end After changing the interface address you can access the FortiGate unit from the web based manager and restore the configuration Backup and Restore from a USB...

Page 45: ...onfig system auto install set default config file filename set auto intall config enable disable set default image file filename set auto install image enable disable end 3 Enter the following command to see the new firmware installation settings get system status Additional CLI Commands for a USB key Use the following CLI commands when you want to delete a file from the FortiUSB key list what fil...

Page 46: ... same subnet as the internal interface To test the new firmware image 1 Connect to the CLI using a RJ 45 to DB 9 or null modem cable 2 Make sure the TFTP server is running 3 Copy the new firmware image file to the root directory of the TFTP server 4 Make sure the internal interface is connected to the same integer as the TFTP server You can use the following command to ping the computer running th...

Page 47: ... make sure you do not use the IP address of another device on the network The following message appears Enter File Name image out 11 Enter the firmware image file name and press Enter The TFTP server uploads the firmware image file to the FortiGate unit and the following appears Save as Default firmware Backup firmware Run image without saving D B R 12 Type R The FortiGate image is installed to sy...

Page 48: ...FortiGate 224B FortiOS 3 0 MR6 Install Guide 48 01 30006 0451 20080815 Testing new firmware before installing FortiGate Firmware ...

Page 49: ... document conventions 8 documentation 9 domain name server configure 24 domain name server configure 19 22 downloading firmware 37 E earthing 12 execute shutdown 14 F firewall policies 20 23 32 firmware backup and restore from USB 44 download 37 from system reboot 42 installing 42 re installing current version 44 restore from CLI 44 restoring previous config 44 revert from CLI 41 reverting with we...

Page 50: ...y certificate 17 shielded twisted pair 12 shut down 14 signatures update 29 static route 19 23 system reboot installing 42 T technical support 10 TFTP server 42 time and date 28 time zone 28 Transparent mode 16 switching to 24 typographic conventions 9 U unnumbered IP 18 update signatures 29 updating antivirus and IPS web based manager 29 upgrading firmware using the CLI 40 USB 44 auto install 39 ...

Page 51: ...FortiGate 224B FortiOS 3 0 MR6 Install Guide 51 01 30006 0451 20080815 Index ...

Page 52: ...FortiGate 224B FortiOS 3 0 MR6 Install Guide 52 01 30006 0451 20080815 Index ...

Page 53: ...www fortinet com ...

Page 54: ...www fortinet com ...

Reviews: