FortiGate-6000F System Guide
FortiGate-6000F Series
Страница 1: ...FortiGate 6000F System Guide FortiGate 6000F Series...
Страница 2: ...fortinet com FORTINET TRAINING CERTIFICATION PROGRAM https www fortinet com support and training training html NSE INSTITUTE https training fortinet com FORTIGUARD CENTER https fortiguard com END USE...
Страница 3: ...PSUs to low line AC power 19 AC PSU LED states 19 Connecting FortiGate 6000F PSUs to AC power 20 Hot swapping an AC PSU 20 Connecting the FortiGate 6000F to ground 20 FortiGate 6000F hardware assembl...
Страница 4: ...individual FPC 38 Installing firmware from the BIOS after a reboot 39 Synchronizing the FPCs with the management board 41 Cautions and warnings 43 Environmental specifications 43 Safety 44 Regulatory...
Страница 5: ...ecting generation 1 or 2 FortiGate 6000F PSUs to low line AC power on page 19 describes FortiGate 6000F generation 1 AC PSUs September 2 2020 More information about FPC failure with power loss added t...
Страница 6: ...ocessor Cards FPCs that contain NP6 and CP9 security processors The management board handles management tasks separating management tasks from data processing tasks that are handled by the FPCs The Fo...
Страница 7: ...P out of band management interface MGMT3 l One RJ 45 RS 232 serial console connection l One USB connector Interface groups and changing data interface speeds Depending on the networks that you want to...
Страница 8: ...arm One or more analog sensors excluding PSUs has surpassed a major or critical CR threshold Any sensor including sensors on PSUs has generated an alert Sensor alert criteria is defined per sensor For...
Страница 9: ...and the attached network device has power Flashing Green Network activity at the interface Off No link is established MGMT3 Right LED Not used HA1 HA2 Link Activity Green This interface is connected a...
Страница 10: ...nsceiver For out of band management or system administration HA1 HA2 SFP 1 10Gbps Ethernet 1 10GigE connection using SFP or SFP transceivers For HA heartbeat and synchronization 1GigE not recommended...
Страница 11: ...connect to the management board MBD CLI of the FortiGate 6000F You can also press Ctrl T to switch between the management board CLI and the CLIs of each of the FPCs in your FortiGate 6000F the new de...
Страница 12: ...hoot problems with your FortiGate 6000F you can use the front panel non maskable interrupt NMI switch to assist with troubleshooting Pressing this switch causes the software to dump management board r...
Страница 13: ...anagement functions such as administrator logins configuration and session synchronization SNMP and other monitoring HA heartbeat communication and remote and if supported local disk logging Separatin...
Страница 14: ...ace over the HA1 and HA2 interfaces Administrator logins SNMP monitoring remote logging to one or more FortiAnalyzers or syslog servers and other management functions use the MGMT1 MGMT2 and MGMT3 int...
Страница 15: ...J 45 Ethernet cable l Two FG TRAN SFP SR transceivers Optional accessories and replacement parts The following optional accessories can be ordered separately SKU Description FG 6000F FAN FortiGate 600...
Страница 16: ...When connected to high line AC power generation 2 FortiGate 6000F models provide 1 1 PSU redundancy When connected to high line AC power each PSU provides 2000W which is enough power to run the entir...
Страница 17: ...FortiGate 6000F AC power supply units PSUs The FortiGate 6000F back panel includes three hot swappable redundant AC PSUs PSU1 PSU2 and PSU3 Two generations of FortiGate 6000F models have been release...
Страница 18: ...power If you connect a generation 2 FortiGate 6000F to high line AC power each PSU provides 2000W AC which is all the power required by the FortiGate 6000F Only two PSUs PSU1 and PSU2 each connected t...
Страница 19: ...he FPC with the highest slot number until only four FPCs are running Usually this results in the FPCs in slots 1 to 4 running if there is only one PSU connected If one of the FPCs in slot 1 to 4 has p...
Страница 20: ...ng traffic as long as one PSU remains connected to power at all times 1 Attach an ESD wrist strap to your wrist and to an ESD socket or to a bare metal surface on the chassis or frame 2 Turn off the p...
Страница 21: ...1 Attach the ESD wrist strap to your wrist and to an ESD socket or to a bare metal surface on the FortiGate 6000F 2 Make sure that the FortiGate 6000F and ground wire are not energized 3 Connect the g...
Страница 22: ...ended that two or more people install the FortiGate 6000F into the rack Do not place heavy objects on the appliance Ensure there is enough room around the appliance to allow for sufficient air flow Co...
Страница 23: ...the rails and fully slid into the rack the FortiGate 6000F locks into place You can press the system release buttons that project out of the front of the rack to unlock the rails and slide the FortiGa...
Страница 24: ...For example on a lifting device in front of the rack that it will be installed into 2 Remove the right rail assembly from the packaging and begin sliding the right inner rail out of it 3 Unlock the ri...
Страница 25: ...it to lock the pins in place 4 Pull out the bracket on the back of the right outer rail to adjust its position until it matches up with the back post of the rack 5 Verify that the rail is level then p...
Страница 26: ...l the lock out tabs on the inner rails click into the front of the middle rails Keep the rails aligned and apply even pressure to both sides of the FortiGate 6000F while doing this 6 Slide the release...
Страница 27: ...ed to it 2 Remove the four rack screws to allow the FortiGate 6000F to slide out of the rack 3 Squeeze the system release buttons on the front of both inner rails at the same time to release the Forti...
Страница 28: ...level Installing QSFP28 SFP28 SFP and SFP transceivers You must install QSFP28 or QSFP transceivers into the 25 to 28 interfaces before connecting them to 100Gbps or 40Gbps networks You must install S...
Страница 29: ...preventive wrist strap when handling FortiGate 6000Fs Handling the transceivers by holding the release latch can damage the connector Do not force transceivers into their cage slots If the transceiver...
Страница 30: ...necting MGMT1 or MGMT2 to your network and browsing to https 192 168 1 99 or https 192 168 2 99 l Log in to the management board CLI by connecting MGMT1 or MGMT2 to your network and using an SSH clien...
Страница 31: ...with in_sync 0 that FPC is not synchronized The following example just shows a few output lines diagnose sys confsync status grep in_sy FPC6KF3E17900200 Slave uptime 5385 45 priority 119 slot_id 2 1...
Страница 32: ...me set ip ip address netmask end Adding a password to the admin administrator account For security purposes one of the first things you should do is add a password to the admin account Depending on yo...
Страница 33: ...the FortiGate 6000 connect to the management board CLI and enter the execute reboot command After you enter this command the management board and all of the FPCs restart To restart an individual FPC...
Страница 34: ...agement port numbers you can set slbc mgmt intf to an interface that is not connected to a network does not have a valid IP address or has management or administrative access disabled For example if t...
Страница 35: ...e The System Information dashboard widget also shows the host name and serial number The CLI prompt also shows slot address in the format hostname slot address Logging in to different FPCs allows you...
Страница 36: ...For example from the management board CLI use the following command to log in to the console of the FPC in slot 3 execute system console server connect 3 Authenticate to log in to the console and use...
Страница 37: ...FPC slot numbers start at 1 When connected to the CLI of a FPC you can view information about the status or configuration of the FPC restart the FPC or perform other operations You should not change t...
Страница 38: ...stem Some firmware upgrades may take longer depending on factors such as the size of the configuration and whether an upgrade of the DP3 processor is included Before beginning a firmware upgrade Forti...
Страница 39: ...FortiGate 6301F devices The field in_sync 1 indicates that the configuration of the FPC is synchronized FPC6KFT018901327 Slave uptime 615368 33 priority 19 slot_id 1 1 idx 1 flag 0x4 in_sync 1 F6KF31...
Страница 40: ...management board CLI 6 To restart the management board enter the execute reboot command 7 When the management board starts up follow the boot process in the terminal session and press any key when pro...
Страница 41: ...ve uptime 57 40 priority 23 slot_id 1 5 idx 2 flag 0x4 in_sync 0 FPC6KFT018901346 Slave uptime 58 44 priority 21 slot_id 1 3 idx 3 flag 0x4 in_sync 0 FPC6KFT018901372 Slave uptime 58 48 priority 20 sl...
Страница 42: ...x4 in_sync 1 F6KF31T018900143 Master uptime 3837 25 priority 1 slot_id 1 0 idx 0 flag 0x0 in_sync 1 F6KF31T018900143 Master uptime 3837 25 priority 1 slot_id 1 0 idx 0 flag 0x0 in_sync 1 FPC6KFT018901...
Страница 43: ...ment M canique Montage de l quipement dans le rack doit tre telle qu une situation dangereuse n est pas li un chargement m canique in gal Circuit Overloading Consideration should be given to the conne...
Страница 44: ...ez pas les batteries au feu Ils peuvent exploser Jetez les piles usag es conform ment aux r glementations locales IMPORTANT Suisse l annexe 4 10 de SR814 013 s appliquent aux batteries CAUTION There i...
Страница 45: ...a terre de la prise This product has a separate protective earthing terminal provided on the back of the product in addition to the grounding terminal of the attachment plug This separate protective e...
Страница 46: ...ause harmful interference in which case the user will be required to correct the interference at his own expense WARNING Any changes or modifications to this product not expressly approved by the part...
Страница 47: ...fety Electrical Appliance Material PSE Japan PSE Bureau of Standards Metrology and Inspection BSMI Taiwan The presence conditions of the restricted substance BSMI RoHS table are available at the link...
Страница 48: ...inet enters a binding written contract signed by Fortinet s General Counsel with a purchaser that expressly warrants that the identified product will perform according to certain expressly identified...