background image

FortiGate-5001FA2-LENC Security System Guide

01-30000-76602-20080606

Warnings and cautions

Only trained and qualified personnel should be allowed to install or maintain FortiGate-5000 series 
equipment. Read and comply with all warnings, cautions and notices in this document. 

• Turning off all power switches may not turn off all power to the FortiGate-5000 series equipment. 

Except where noted, disconnect the FortiGate-5000 series equipment from all power sources, 

telecommunications links and networks before installing, or removing FortiGate-5000 series 

components, or performing other maintenance tasks. Failure to do this can result in personal injury or 

equipment damage. Some circuitry in the FortiGate-5000 series equipment may continue to operate 

even though all power switches are off.

• An easily accessible disconnect device, such as a circuit breaker, should be incorporated into the data 

center wiring that connects power to the FortiGate-5000 series equipment.

• Install FortiGate-5000 series chassis at the lower positions of a rack to avoid making the rack top-heavy 

and unstable.

• Do not insert metal objects or tools into open chassis slots.
• Electrostatic discharge (ESD) can damage FortiGate-5000 series equipment. Only perform the 

procedures described in this document from an ESD workstation. If no such station is available, you 

can provide some ESD protection by wearing an anti-static wrist strap and attaching it to an ESD 

connector or to a metal part of a FortiGate chassis.

• Some FortiGate-5000 series components may overload your supply circuit and impact your overcurrent 

protection and supply wiring. Refer to nameplate ratings to address this concern. 

• Make sure all FortiGate-5000 series components have reliable grounding. Fortinet recommends direct 

connections to the branch circuit.

• If you install a FortiGate-5000 series component in a closed or multi-unit rack assembly, the operating 

ambient temperature of the rack environment may be greater than room ambient. Make sure the 

operating ambient temperature does not exceed the manufacturer's maximum rated ambient 

temperature.

• Installing FortiGate-5000 series equipment in a rack should be such that the amount of airflow required 

for safe operation of the equipment is not compromised. Refer to the ATCA specification for more 

information about cooling and airflow requirements.

• This equipment is for installation only in a Restricted Access Location (dedicated equipment room, 

service closet or the like), in accordance with the National Electrical Code.

• Per the National Electrical Code, sizing of a Listed circuit breaker or branch circuit fuse and the supply 

conductors to the equipment is based on the marked input current rating. A product with a marked input 

current rating of 25 A is required to be placed on a 40 A branch circuit. The supply conductors will also 

be sized according to the input current rating and also derated for the maximum rated operating 

ambient temperature, Tma, of the equipment.

• FortiGate-5000 series equipment shall be installed and connected to an electrical supply source in 

accordance with the applicable codes and regulations for the location in which it is installed. Particular 

attention shall be paid to use of correct wire type and size to comply with the applicable codes and 

regulations for the installation / location. Connection of the supply wiring to the terminal block on the 

equipment may be accomplished using Listed wire compression lugs, for example, Pressure Terminal 

Connector made by Ideal Industries Inc. or equivalent which is suitable for AWG 10. Particular attention 

shall be given to use of the appropriate compression tool specified by the compression lug 

manufacturer, if one is specified.

!

CAUTION: 

Risk of Explosion if Battery is replaced by an Incorrect Type. Dispose of Used Batteries According 

to the Instructions.

!

Caution: 

You should be aware of the following cautions and warnings before installing FortiGate-5000 series 

hardware

Содержание FortiGate 5001FA2-LENC

Страница 1: ...n a FortiGate 5000 series chassis how to configure the FortiGate 5001FA2 LENC security system for your network and contains troubleshooting information to help you diagnose and fix problems The most recent versions of this and all FortiGate 5000 series documents are available from the FortiGate 5000 page of the Fortinet Technical Documentation web site http docs forticare com Visit http support fo...

Страница 2: ...ack assembly the operating ambient temperature of the rack environment may be greater than room ambient Make sure the operating ambient temperature does not exceed the manufacturer s maximum rated ambient temperature Installing FortiGate 5000 series equipment in a rack should be such that the amount of airflow required for safe operation of the equipment is not compromised Refer to the ATCA specif...

Страница 3: ... FortiGate 5001FA2 LENC board from a chassis 17 Troubleshooting 18 FortiGate 5001FA2 LENC does not startup 18 FortiGate 5001FA2 LENC cannot display chassis information 20 Quick Configuration Guide 21 Registering your Fortinet product 21 Upgrading to High Encryption 21 Planning the configuration 22 NAT Route mode 22 Transparent mode 23 Choosing the configuration tool 23 Web based manager 23 Command...

Страница 4: ...ring off the FortiGate 5001FA2 LENC board 32 For more information 33 Fortinet documentation 33 Fortinet Tools and Documentation CD 33 Fortinet Knowledge Center 33 Comments on Fortinet technical documentation 33 Customer service and technical support 33 Register your Fortinet product 33 ...

Страница 5: ...et performance The FortiGate 5001FA2 LENC board also supports high end FortiGate features including 802 1Q VLANs multiple virtual domains 802 3ad aggregate interfaces and FortiGate 5000 chassis monitoring Figure 1 FortiGate 5001FA2 LENC front panel The FortiGate 5001FA2 LENC board includes the following features A total of eight front panel gigabit interfaces Two accelerated packet forwarding and ...

Страница 6: ...Guide LEDs Table 1 lists and describes the FortiGate 5001FA2 LENC board LEDs Table 1 FortiGate 5001FA2 LENC board LEDs LED State Description PWR Green The FortiGate 50012FA2 board is powered on ACC Off or Flashing red The ACC LED flashes red when the FortiGate 5001FA2 LENC board accesses the FortiOS flash disk The FortiOS flash disk stores the current FortiOS firmware build and configuration files...

Страница 7: ...e connected equipment has power Flashing Network activity at this interface Speed LED Green The interface is connected at 1000 Mbps Amber The interface is connected at 100 Mbps Unlit The interface is connected at 10 Mbps Table 1 FortiGate 5001FA2 LENC board LEDs Continued LED State Description Table 2 FortiGate 5001FA2 LENC connectors Connector Type Speed Protocol Description 1 and 2 LC SFP 1000Ba...

Страница 8: ...f the high CPU requirement for antivirus scanning FA2 interfaces and active active HA performance FortiOS v3 0 MR4 firmware can also use FA2 acceleration to improve active active HA load balancing performance See the FortiGate HA Overview or the FortiGate HA Guide for more information Base backplane gigabit communication The FortiGate 5001FA2 LENC port9 and port10 base backplane gigabit interfaces...

Страница 9: ...LENC board ships with two RAM DIMMs installed on the FortiGate 5001FA2 LENC circuit board You should confirm that the RAM DIMMs are installed correctly before inserting the FortiGate 5001FA2 LENC board into a chassis To install FortiGate 5001FA2 LENC RAM DIMMs To complete this procedure you need A FortiGate 5001FA2 LENC board Two RAM DIMMs to be installed into the FortiGate 5001FA2 LENC board RAM ...

Страница 10: ...ou cannot lock the locking levers the DIM is not aligned correctly or is in upside down Installing SFP transceivers The FortiGate 5001FA2 LENC board ships with four SFP transceivers that you must install for normal operation of the FortiGate 5001FA2 LENC board The SFP transceivers are inserted into cage sockets numbered 1 to 4 on the FortiGate 5001FA2 LENC front panel You can install the SFP trans...

Страница 11: ...umper settings The JP3 jumper on the FortiGate 5001FA2 LENC board is factory set by Fortinet into one of two positions see Figure 3 on page 12 For a FortiGate 5140 or FortiGate 5050 chassis the jumper connects pins 2 and 3 For a FortiGate 5020 chassis the jumper connects pins 1 and 2 The jumper must connect pins 2 and 3 if the chassis contains a shelf manager Both the FortiGate 5140 and the FortiG...

Страница 12: ...s Correct JP3 Jumper Setting Result of wrong jumper setting FortiGate 5140 pins 2 and 3 Shelf manager cannot find FortiGate 5001FA2 LENC board No chassis information available FortiGate 5050 pins 2 and 3 Shelf manager cannot find FortiGate 5001FA2 LENC board No chassis information available FortiGate 5020 pins 1 and 2 FortiGate 5001FA2 LENC board will not start up Note If the shelf manager in a Fo...

Страница 13: ...A2 LENC board into a chassis The following procedure describes how to correctly use the FortiGate 5001FA2 LENC mounting components shown in Figure 4 to insert a FortiGate 5001FA2 LENC board into a FortiGate 5000 series chassis slot The FortiGate 5001FA2 LENC board left handle contacts to a hidden power switch The board must be fully installed in a chassis slot and this handle must be closed and lo...

Страница 14: ...board into a FortiGate 5000 series chassis slot is the same whether or not the FortiGate 5000 series chassis is powered on To insert a FortiGate 5001FA2 LENC board into a FortiGate 5000 series chassis To complete this procedure you need A FortiGate 5001FA2 LENC board Closed Open Alignment Pin Retention Screw Lock Handle Alignment Pin Retention Screw Lock Handle Switch Contact Power Switch Lock Lef...

Страница 15: ...ails in the slot Insert the board by applying moderate force to the front faceplate not the handles to slide the board into the slot The board should glide smoothly into the chassis If you encounter any resistance while sliding the board in the board could be aligned incorrectly Pull the board back out and try inserting it again 6 Slide the board in until the alignment pins are inserted half way i...

Страница 16: ...osed they lock into place If the chassis is powered on as the board slides into place the IPM LED starts flashing blue 8 Fully tighten the left and right retention screws to lock the FortiGate 5001FA2 LENC board into position in the chassis slot If the chassis is powered on the PWR LED turns green and the STA LED turns red The ACC LED also starts flashing red After a few minutes if the board is op...

Страница 17: ... chassis or frame 2 Disconnect all cables from the FortiGate 5001FA2 LENC board including all network cables the console cable and any USB cables or keys 3 Fully loosen the retention screws on the left and right sides of the FortiGate 5001FA2 LENC front panel 4 Unlock the left and right handles by squeezing the handle locks Caution Do not carry the FortiGate 5001FA2 LENC board by holding the handl...

Страница 18: ... of the slot Troubleshooting This section describes the following troubleshooting topics FortiGate 5001FA2 LENC does not startup FortiGate 5001FA2 LENC cannot display chassis information FortiGate 5001FA2 LENC does not startup Positioning of FortiGate 5001FA2 LENC handles the presence or absence of a functioning shelf manager incorrect jumper settings and firmware problems may all prevent a FortiG...

Страница 19: ... FortiGate 5140 or 5050 chassis shelf manager not installed or not functioning If you are operating a FortiGate 5001FA2 LENC in a FortiGate 5140 or 5050 chassis the FortiGate 5001FA2 LENC board will not start up if the JP3 jumper connects pins 2 and 3 see Figure 3 on page 12 and a shelf manager is not installed or is not operating correctly If the shelf manager is not installed or not operating co...

Страница 20: ... the JP3 jumper is set between pins 2 and 3 the FortiGate 5001FA2 LENC board should be able to communicate with the chassis shelf manager If the FortiGate 5001FA2 LENC board can communicate with the shelf manager the FortiGate 5001FA2 LENC web based manager System Chassis pages should display information about the boards installed in the chassis If any one of the conditions listed above are not me...

Страница 21: ...ering your Fortinet product Register your Fortinet product to receive Fortinet customer services such as product updates and technical support You must also register your product for FortiGuard services such as FortiGuard Antivirus and Intrusion Prevention updates and for FortiGuard Web Filtering and AntiSpam Register your product by visiting http support fortinet com and selecting Product Registr...

Страница 22: ...ity system is deployed as a gateway between private and public networks In the default NAT Route mode configuration the FortiGate 5001FA2 LENC security system functions as a firewall Firewall policies control communications through the FortiGate 5001FA2 LENC security system No traffic can pass through the FortiGate 5001FA2 LENC security system until you add firewall policies In NAT Route mode fire...

Страница 23: ...LENC security system functions as a firewall No traffic can pass through the FortiGate 5001FA2 LENC security system until you add firewall policies Choosing the configuration tool You can use either the web based manager or the Command Line Interface CLI to configure the FortiGate board Web based manager The FortiGate 5001FA2 LENC web based manager is an easy to use management tool Use the web bas...

Страница 24: ...figure the FortiGate 5001FA2 LENC board onto the network To configure the FortiGate 5001FA2 LENC board onto the network you add an administrator password change the network interface IP addresses add DNS server IP addresses and if required configure basic routing Table 5 FortiGate 5001FA2 LENC factory default settings Operation Mode NAT Route Administrator Account User Name admin Password none por...

Страница 25: ... Type admin in the Name field and select Login To change the admin administrator password 1 Go to System Admin Administrators 2 Select Change Password for the admin administrator and enter a new password To configure interfaces 1 Go to System Network Interface 2 Select the edit icon for each interface to configure Table 6 FortiGate 5001FA2 LENC board NAT Route mode settings Admin Administrator Pas...

Страница 26: ...evice that you recorded above 3 Set Gateway to the Default Gateway IP address that you added to Table 6 on page 25 4 Select OK Using the CLI to configure NAT Route mode 1 Use the serial cable supplied with your FortiGate 5001FA2 LENC board to connect the FortiGate Console port to the management computer serial port 2 Start a terminal emulation program HyperTerminal on the management computer Use t...

Страница 27: ... on the same subnet as the port1 interface of the FortiGate 5001FA2 LENC board To do this change the IP address of the management computer to 192 168 1 2 and the netmask to 255 255 255 0 3 To access the FortiGate web based manager start Internet Explorer and browse to https 192 168 1 99 remember to include the s in https 4 Type admin in the Name field and select Login Table 7 Transparent mode sett...

Страница 28: ...ver IP addresses 1 Go to System Network Options 2 Enter the Primary and Secondary DNS IP addresses that you added to Table 7 on page 27 as required and select Apply Using the CLI to configure Transparent mode 1 Use the serial cable supplied with your FortiGate 5001FA2 LENC board to connect the FortiGate Console port to the management computer serial port 2 Start a terminal emulation program HyperT...

Страница 29: ...t computer 2 Log into the web based manager as the admin administrator 3 Go to System Status 4 Under System Information Firmware Version select Update 5 Type the path and filename of the firmware image file or select Browse and locate the file 6 Select OK The FortiGate 5001FA2 LENC board uploads the firmware image file upgrades to the new firmware version restarts and displays the FortiGate login ...

Страница 30: ... You can configure the FortiGate 5001FA2 LENC boards for data communications using the two FortiGate 5140 FortiGate 5050 or FortiGate 5020 chassis base backplane interfaces By default the base backplane interfaces are used for HA heartbeat communication However using the information in this section you can configure the FortiGate 5001FA2 LENC to also use the base backplane interfaces for data comm...

Страница 31: ...on using the FortiSwitch 5003 board see the FortiGate 5000 Base Backplane Communication Guide To enable base backplane data communication from the FortiGate 5001FA2 LENC web based manager From the FortiGate 5001FA2 LENC web based manager use the following steps to enable base backplane data communication 1 Go to System Network Interface 2 Select Show backplane interfaces The port9 and port10 backp...

Страница 32: ...ate 5001FA2 LENC board from a chassis slot or before powering down the chassis To power off a FortiGate 5001FA2 LENC board 1 Shut down the FortiGate 5001FA2 LENC operating system From the web based manager go to System Status and from the Unit Operation widget select Shutdown and then select OK From the CLI enter execute shutdown 2 Remove the FortiGate 5001FA2 LENC board from the chassis slot Note...

Страница 33: ...ilable from the Fortinet Knowledge Center The knowledge center contains troubleshooting and how to articles FAQs technical notes and more Visit the Fortinet Knowledge Center at http kc forticare com Comments on Fortinet technical documentation Please send information about any errors or omissions in this document or any Fortinet technical documentation to techdoc fortinet com Customer service and ...

Страница 34: ...ate and FortiGuard are registered trademarks and Dynamic Threat Prevention System DTPS APSecure FortiASIC FortiBIOS FortiBridge FortiClient FortiGate FortiGate Unified Threat Management System FortiGuard Antispam FortiGuard Antivirus FortiGuard Intrusion FortiGuard Web FortiLog FortiAnalyzer FortiManager FortiOS FortiPartner FortiProtect FortiReporter FortiResponse FortiShield and FortiVoIP are tr...

Отзывы: